Advisories
GoogleExploitedCISA KEV listedMEDIUM2022-02-09
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attr...
CVEs:CVE-2022-24682
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| zimbra_collaboration_suite |
affected |
synacor |
— |
— |
GoogleExploitedCISA KEV listedMEDIUM2022-02-09
CVEs:CVE-2022-24682
Project ZeroExploitedCISA KEV listed2022-02-09
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
CVEs:CVE-2022-24682
Open SourceExploitedCISA KEV listedCRITICAL2022-02-17
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
Open SourceExploitedCISA KEV listed2022-02-17
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
Project ZeroExploitedCISA KEV listed2022-02-15
Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0609
GoogleExploitedCISA KEV listedCRITICAL2022-02-15
Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0609
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleExploitedCISA KEV listedHIGH2022-02-15
Use after free in Animation
CVEs:CVE-2022-0609
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CefSharp.Common |
affected |
NuGet |
CefSharp.Common |
— |
| CefSharp.Common.NETCore |
affected |
NuGet |
CefSharp.Common.NETCore |
— |
| CefSharp.OffScreen |
affected |
NuGet |
CefSharp.OffScreen |
— |
| CefSharp.OffScreen.NETCore |
affected |
NuGet |
CefSharp.OffScreen.NETCore |
— |
| CefSharp.WinForms |
affected |
NuGet |
CefSharp.WinForms |
— |
| CefSharp.WinForms.NETCore |
affected |
NuGet |
CefSharp.WinForms.NETCore |
— |
| CefSharp.Wpf |
affected |
NuGet |
CefSharp.Wpf |
— |
| CefSharp.Wpf.HwndHost |
affected |
NuGet |
CefSharp.Wpf.HwndHost |
— |
| CefSharp.Wpf.NETCore |
affected |
NuGet |
CefSharp.Wpf.NETCore |
— |
Project ZeroExploitedCISA KEV listed2022-02-11
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
CVEs:CVE-2022-22620
GoogleExploitedCISA KEV listedHIGH2022-02-11
CVEs:CVE-2022-22620
GoogleExploitedCISA KEV listedCRITICAL2022-02-11
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to a...
CVEs:CVE-2022-22620
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
Open SourceExploitedCISA KEV listedCRITICAL2022-02-11
DEBIAN-CVE-2021-4102
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceExploitedVulnCheck KEV listedCRITICAL2022-02-07
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
Open SourceExploitedVulnCheck KEV listed2022-02-07
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleExploitedVulnCheck KEV listedCRITICAL2022-02-02
Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via profile destruction.
CVEs:CVE-2022-0456
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleExploitedVulnCheck KEV listedHIGH2022-02-02
CVEs:CVE-2022-0456
Open SourceWeaponized exploitCRITICAL2022-02-15
Privilege Escalation in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourceWeaponized exploitCRITICAL2022-02-15
Privilege Escalation in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-02-02
Updated chromium-browser-stable packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:8 |
chromium-browser-stable |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-02-15
Authorization bypass in Istio
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-02-15
Authorization bypass in Istio
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-02-12
DEBIAN-CVE-2022-0293
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2022-02-12
DEBIAN-CVE-2022-0295
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2022-02-12
DEBIAN-CVE-2022-0296
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-02-12
DEBIAN-CVE-2022-0297
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-02-12
DEBIAN-CVE-2022-0298
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2022-02-12
DEBIAN-CVE-2022-0307
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2022-02-12
DEBIAN-CVE-2022-0308
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-02-12
DEBIAN-CVE-2022-0291
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-02-12
DEBIAN-CVE-2022-0294
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-02-12
DEBIAN-CVE-2022-0305
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-02-15
Kubernetes Unsafe Cacheing
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| client-go |
affected |
k8s.io |
k8s.io/client-go |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-02-15
Kubernetes Unsafe Cacheing
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| client-go |
affected |
k8s.io |
k8s.io/client-go |
— |
GoogleActive exploitation (sightings)HIGH2022-02-26
Command injection in github.com/google/fscrypt
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/fscrypt |
affected |
github.com |
github.com/google/fscrypt |
— |
GoogleActive exploitation (sightings)HIGH2022-02-26
Command injection in github.com/google/fscrypt
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/fscrypt |
affected |
github.com |
github.com/google/fscrypt |
— |
GoogleActive exploitation (sightings)MEDIUM2022-02-25
Command injection in github.com/google/fscrypt
CVEs:CVE-2022-25328
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/fscrypt |
affected |
github.com |
github.com/google/fscrypt |
— |
GoogleActive exploitation (sightings)HIGH2022-02-25
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their p...
CVEs:CVE-2022-25328
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fscrypt |
affected |
google |
— |
— |
Open SourcePoC exploitMEDIUM2022-02-15
Symlink Attack in kubectl cp
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitMEDIUM2022-02-15
Symlink Attack in kubectl cp
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitHIGH2022-02-08
Unverified Ownership in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitHIGH2022-02-08
Unverified Ownership in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes-1.21 |
affected |
chainguard |
kubernetes-1.21 |
— |
| kubernetes-1.22 |
affected |
chainguard |
kubernetes-1.22 |
— |
| kubernetes-1.23 |
affected |
chainguard |
kubernetes-1.23 |
— |
| kubernetes-1.24 |
affected |
chainguard |
kubernetes-1.24 |
— |
| kubernetes-1.24 |
affected |
wolfi |
kubernetes-1.24 |
— |
| kubernetes-1.26 |
affected |
chainguard |
kubernetes-1.26 |
— |
| kubernetes-1.26 |
affected |
wolfi |
kubernetes-1.26 |
— |
| kubernetes-1.27 |
affected |
chainguard |
kubernetes-1.27 |
— |
| kubernetes-1.27 |
affected |
wolfi |
kubernetes-1.27 |
— |
| kubernetes-1.28 |
affected |
wolfi |
kubernetes-1.28 |
— |
| kubernetes-1.28 |
affected |
chainguard |
kubernetes-1.28 |
— |
| kubernetes-1.29 |
affected |
chainguard |
kubernetes-1.29 |
— |
| kubernetes-1.29 |
affected |
wolfi |
kubernetes-1.29 |
— |
| kubernetes-1.30 |
affected |
chainguard |
kubernetes-1.30 |
— |
| kubernetes-1.30 |
affected |
wolfi |
kubernetes-1.30 |
— |
| kubernetes-1.31 |
affected |
wolfi |
kubernetes-1.31 |
— |
| kubernetes-1.31 |
affected |
chainguard |
kubernetes-1.31 |
— |
| kubernetes-1.32 |
affected |
chainguard |
kubernetes-1.32 |
— |
| kubernetes-1.32 |
affected |
wolfi |
kubernetes-1.32 |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
| nodetaint |
affected |
wolfi |
nodetaint |
— |
| nodetaint |
affected |
chainguard |
nodetaint |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
Open SourcePoC exploitHIGH2022-02-17
Infinite loop when parsing inputs in golang.org/x/net/html
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpcurl |
affected |
wolfi |
grpcurl |
— |
| grpcurl |
affected |
chainguard |
grpcurl |
— |
| hey |
affected |
chainguard |
hey |
— |
| hey |
affected |
wolfi |
hey |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourcePoC exploit2022-02-17
Panic on certain certificates in crypto/tls
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploit2022-02-11
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:20.03-LTS-SP1 |
golang |
— |
| golang |
affected |
openEuler:20.03-LTS-SP2 |
golang |
— |
| golang |
affected |
openEuler:20.03-LTS-SP3 |
golang |
— |
Open SourcePoC exploitHIGH2022-02-16
Uncontrolled Resource Consumption in promhttp
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dynamic-localpv-provisioner |
affected |
wolfi |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner |
affected |
chainguard |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| prometheus/client_golang |
affected |
github.com |
github.com/prometheus/client_golang |
— |
| prometheus-postgres-exporter-0.10 |
affected |
chainguard |
prometheus-postgres-exporter-0.10 |
— |
Open SourcePoC exploitHIGH2022-02-16
Uncontrolled Resource Consumption in promhttp
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| prometheus/client_golang |
affected |
github.com |
github.com/prometheus/client_golang |
— |
Open SourcePoC exploitHIGH2022-02-15
CVE-2022-21698 affecting package application-gateway-kubernetes-ingress for versions less than 1.4.0-17
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| application-gateway-kubernetes-ingress |
affected |
Azure Linux:2 |
application-gateway-kubernetes-ingress |
— |
Open SourcePoC exploitHIGH2022-02-15
CVE-2022-21698 affecting package application-gateway-kubernetes-ingress for versions less than 1.7.2-2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| application-gateway-kubernetes-ingress |
affected |
Azure Linux:3 |
application-gateway-kubernetes-ingress |
— |
Open SourcePoC exploitHIGH2022-02-15
DEBIAN-CVE-2022-21698
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-prometheus-client-golang |
affected |
Debian:14 |
golang-github-prometheus-client-golang |
— |
| golang-github-prometheus-client-golang |
affected |
Debian:11 |
golang-github-prometheus-client-golang |
— |
| golang-github-prometheus-client-golang |
affected |
Debian:12 |
golang-github-prometheus-client-golang |
— |
| golang-github-prometheus-client-golang |
affected |
Debian:13 |
golang-github-prometheus-client-golang |
— |
Open SourcePoC exploitHIGH2022-02-15
Uncontrolled Resource Consumption in promhttp
CVEs:CVE-2022-21698
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| prometheus/client_golang |
affected |
github.com |
github.com/prometheus/client_golang |
— |
Open SourcePoC exploitHIGH2022-02-15
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial...
CVEs:CVE-2022-21698
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| client_golang |
affected |
prometheus |
— |
— |
| extra_packages_for_enterprise_linux |
affected |
fedoraproject |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| rdo |
affected |
rdo_project |
— |
— |
Open SourcePoC exploitHIGH2022-02-15
Server Side Request Forgery (SSRF) in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
Open SourcePoC exploitHIGH2022-02-15
Server Side Request Forgery (SSRF) in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitHIGH2022-02-15
Improper Authentication in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
Open SourcePoC exploitHIGH2022-02-15
Improper Authentication in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploit2022-02-17
Panic when reading certain archives in archive/zip
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploit2022-02-17
Panic on crafted authentication request message in golang.org/x/crypto/ssh
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| x/crypto |
affected |
golang.org |
golang.org/x/crypto |
— |
Open SourcePoC exploit2022-02-17
Improper sanitization when resolving values from DNS in net
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploit2022-02-17
Panic in ReverseProxy in net/http/httputil
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploitCRITICAL2022-02-11
CVE-2022-23806 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2022-02-11
CVE-2022-23806 affecting package golang for versions less than 1.18.8-3
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
GooglePoC exploitCRITICAL2022-02-11
CVEs:CVE-2022-23806
Open SourcePoC exploitCRITICAL2022-02-11
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
CVEs:CVE-2022-23806
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| beegfs_csi_driver |
affected |
netapp |
— |
— |
| cloud_insights_telegraf_agent |
affected |
netapp |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| go |
affected |
golang |
— |
— |
| kubernetes_monitoring_operator |
affected |
netapp |
— |
— |
| storagegrid |
affected |
netapp |
— |
— |
Open SourcePoC exploitCRITICAL2022-02-11
DEBIAN-CVE-2022-23806
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
Open SourcePoC exploitHIGH2022-02-11
CVE-2022-23772 affecting package golang for versions less than 1.17.8-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
GooglePoC exploitHIGH2022-02-11
CVEs:CVE-2022-23772
Open SourcePoC exploitHIGH2022-02-11
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
CVEs:CVE-2022-23772
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| beegfs_csi_driver |
affected |
netapp |
— |
— |
| cloud_insights_telegraf_agent |
affected |
netapp |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| go |
affected |
golang |
— |
— |
| kubernetes_monitoring_operator |
affected |
netapp |
— |
— |
| storagegrid |
affected |
netapp |
— |
— |
Open SourcePoC exploitHIGH2022-02-11
DEBIAN-CVE-2022-23772
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
Open SourcePoC exploit2022-02-17
Incorrect operations on the P-224 curve in crypto/elliptic
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploitHIGH2022-02-11
CVE-2022-23773 affecting package golang for versions less than 1.17.8-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
GooglePoC exploitHIGH2022-02-11
CVEs:CVE-2022-23773
Open SourcePoC exploitHIGH2022-02-11
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.
CVEs:CVE-2022-23773
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| beegfs_csi_driver |
affected |
netapp |
— |
— |
| cloud_insights_telegraf_agent |
affected |
netapp |
— |
— |
| go |
affected |
golang |
— |
— |
| kubernetes_monitoring_operator |
affected |
netapp |
— |
— |
| storagegrid |
affected |
netapp |
— |
— |
Open SourcePoC exploitHIGH2022-02-11
DEBIAN-CVE-2022-23773
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
Open SourcePoC exploitHIGH2022-02-15
Kubernetes API Server DoS Via API Requests
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apiserver |
affected |
k8s.io |
k8s.io/apiserver |
— |
Open SourcePoC exploitHIGH2022-02-15
Kubernetes API Server DoS Via API Requests
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apiserver |
affected |
k8s.io |
k8s.io/apiserver |
— |
| argo-cd-2.7 |
affected |
wolfi |
argo-cd-2.7 |
— |
| argo-cd-2.7 |
affected |
chainguard |
argo-cd-2.7 |
— |
| argo-cd-2.8 |
affected |
chainguard |
argo-cd-2.8 |
— |
| argo-cd-2.8 |
affected |
wolfi |
argo-cd-2.8 |
— |
| aws-ebs-csi-driver |
affected |
chainguard |
aws-ebs-csi-driver |
— |
| aws-ebs-csi-driver |
affected |
wolfi |
aws-ebs-csi-driver |
— |
| aws-ebs-csi-driver-1.18 |
affected |
chainguard |
aws-ebs-csi-driver-1.18 |
— |
| aws-ebs-csi-driver-1.19 |
affected |
chainguard |
aws-ebs-csi-driver-1.19 |
— |
| calico |
affected |
chainguard |
calico |
— |
| calico |
affected |
wolfi |
calico |
— |
| cert-manager-1.11 |
affected |
chainguard |
cert-manager-1.11 |
— |
| cert-manager-1.11 |
affected |
wolfi |
cert-manager-1.11 |
— |
| cert-manager-1.12 |
affected |
chainguard |
cert-manager-1.12 |
— |
| cert-manager-1.12 |
affected |
wolfi |
cert-manager-1.12 |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller-0 |
affected |
chainguard |
flux-helm-controller-0 |
— |
| flux-helm-controller-0.37 |
affected |
chainguard |
flux-helm-controller-0.37 |
— |
| gatekeeper-3.12 |
affected |
chainguard |
gatekeeper-3.12 |
— |
| gatekeeper-3.12 |
affected |
wolfi |
gatekeeper-3.12 |
— |
| gatekeeper-3.13 |
affected |
wolfi |
gatekeeper-3.13 |
— |
| gatekeeper-3.13 |
affected |
chainguard |
gatekeeper-3.13 |
— |
| haproxy-ingress |
affected |
chainguard |
haproxy-ingress |
— |
| haproxy-ingress |
affected |
wolfi |
haproxy-ingress |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm-3 |
affected |
wolfi |
helm-3 |
— |
| helm-3 |
affected |
chainguard |
helm-3 |
— |
| helm-4 |
affected |
chainguard |
helm-4 |
— |
| helm-4 |
affected |
wolfi |
helm-4 |
— |
| istio-pilot-agent-1.18 |
affected |
wolfi |
istio-pilot-agent-1.18 |
— |
| istio-pilot-agent-1.18 |
affected |
chainguard |
istio-pilot-agent-1.18 |
— |
| istio-pilot-agent-fips-1.19 |
affected |
chainguard |
istio-pilot-agent-fips-1.19 |
— |
| istio-pilot-discovery-1.19 |
affected |
wolfi |
istio-pilot-discovery-1.19 |
— |
| istio-pilot-discovery-1.19 |
affected |
chainguard |
istio-pilot-discovery-1.19 |
— |
| istio-pilot-discovery-fips-1.19 |
affected |
chainguard |
istio-pilot-discovery-fips-1.19 |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| kargo |
affected |
chainguard |
kargo |
— |
| kargo |
affected |
wolfi |
kargo |
— |
| keda |
affected |
wolfi |
keda |
— |
| keda |
affected |
chainguard |
keda |
— |
| keda-2.10 |
affected |
wolfi |
keda-2.10 |
— |
| keda-2.10 |
affected |
chainguard |
keda-2.10 |
— |
| keda-2.8 |
affected |
chainguard |
keda-2.8 |
— |
| keda-2.9 |
affected |
chainguard |
keda-2.9 |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kube-oidc-proxy |
affected |
chainguard |
kube-oidc-proxy |
— |
| kubernetes-csi-external-provisioner |
affected |
chainguard |
kubernetes-csi-external-provisioner |
— |
| kubernetes-csi-external-provisioner |
affected |
wolfi |
kubernetes-csi-external-provisioner |
— |
| kubernetes-csi-external-resizer |
affected |
chainguard |
kubernetes-csi-external-resizer |
— |
| kubernetes-csi-external-resizer |
affected |
wolfi |
kubernetes-csi-external-resizer |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
Open SourcePoC exploit2022-02-17
Attacker can drop certain headers in net/http/httputil
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploitCRITICAL2022-02-15
NULL Pointer Dereference in Kubernetes CSI snapshot-controller
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes-csi/external-snapshotter/v2 |
affected |
github.com |
github.com/kubernetes-csi/external-snapshotter/v2 |
— |
| kubernetes-csi/external-snapshotter/v3 |
affected |
github.com |
github.com/kubernetes-csi/external-snapshotter/v3 |
— |
Open SourcePoC exploitCRITICAL2022-02-15
NULL Pointer Dereference in Kubernetes CSI snapshot-controller
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes-csi/external-snapshotter/v2 |
affected |
github.com |
github.com/kubernetes-csi/external-snapshotter/v2 |
— |
| kubernetes-csi/external-snapshotter/v3 |
affected |
github.com |
github.com/kubernetes-csi/external-snapshotter/v3 |
— |
Open SourcePoC exploitMEDIUM2022-02-26
Improper Locking in JetBrains Kotlin
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jetbrains.kotlin:kotlin-stdlib |
affected |
Maven |
org.jetbrains.kotlin:kotlin-stdlib |
— |
Open SourcePoC exploitMEDIUM2022-02-26
Improper Locking in JetBrains Kotlin
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jetbrains.kotlin:kotlin-stdlib |
affected |
Maven |
org.jetbrains.kotlin:kotlin-stdlib |
— |
| thingsboard |
affected |
wolfi |
thingsboard |
— |
| thingsboard |
affected |
chainguard |
thingsboard |
— |
GooglePoC exploitMEDIUM2022-02-25
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
CVEs:CVE-2022-24329
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| communications_cloud_native_core_binding_support_function |
affected |
oracle |
— |
— |
| communications_pricing_design_center |
affected |
oracle |
— |
— |
| kotlin |
affected |
jetbrains |
— |
— |
Open SourcePoC exploitMEDIUM2022-02-25
Improper Locking in JetBrains Kotlin
CVEs:CVE-2022-24329
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jetbrains.kotlin:kotlin-stdlib |
affected |
Maven |
org.jetbrains.kotlin:kotlin-stdlib |
— |
Open SourcePoC exploitHIGH2022-02-15
Access Restriction Bypass in kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourcePoC exploitHIGH2022-02-15
Access Restriction Bypass in kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes-1.19 |
affected |
chainguard |
kubernetes-1.19 |
— |
| kubernetes-1.20 |
affected |
chainguard |
kubernetes-1.20 |
— |
| kubernetes-1.21 |
affected |
chainguard |
kubernetes-1.21 |
— |
| kubernetes-1.22 |
affected |
chainguard |
kubernetes-1.22 |
— |
| kubernetes-1.23 |
affected |
chainguard |
kubernetes-1.23 |
— |
| kubernetes-1.24 |
affected |
wolfi |
kubernetes-1.24 |
— |
| kubernetes-1.24 |
affected |
chainguard |
kubernetes-1.24 |
— |
| kubernetes-1.25 |
affected |
chainguard |
kubernetes-1.25 |
— |
| kubernetes-1.25 |
affected |
wolfi |
kubernetes-1.25 |
— |
| kubernetes-1.26 |
affected |
chainguard |
kubernetes-1.26 |
— |
| kubernetes-1.26 |
affected |
wolfi |
kubernetes-1.26 |
— |
| kubernetes-1.27 |
affected |
wolfi |
kubernetes-1.27 |
— |
| kubernetes-1.27 |
affected |
chainguard |
kubernetes-1.27 |
— |
| kubernetes-1.28 |
affected |
chainguard |
kubernetes-1.28 |
— |
| kubernetes-1.28 |
affected |
wolfi |
kubernetes-1.28 |
— |
| kubernetes-1.29 |
affected |
chainguard |
kubernetes-1.29 |
— |
| kubernetes-1.29 |
affected |
wolfi |
kubernetes-1.29 |
— |
| kubernetes-1.30 |
affected |
wolfi |
kubernetes-1.30 |
— |
| kubernetes-1.30 |
affected |
chainguard |
kubernetes-1.30 |
— |
| kubernetes-1.31 |
affected |
chainguard |
kubernetes-1.31 |
— |
| kubernetes-1.31 |
affected |
wolfi |
kubernetes-1.31 |
— |
| kubernetes-1.32 |
affected |
wolfi |
kubernetes-1.32 |
— |
| kubernetes-1.32 |
affected |
chainguard |
kubernetes-1.32 |
— |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourcePoC exploitHIGH2022-02-15
Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
Open SourcePoC exploitHIGH2022-02-15
Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitMEDIUM2022-02-12
DEBIAN-CVE-2022-0108
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| webkit2gtk |
affected |
Debian:11 |
webkit2gtk |
— |
| webkit2gtk |
affected |
Debian:12 |
webkit2gtk |
— |
| webkit2gtk |
affected |
Debian:13 |
webkit2gtk |
— |
| webkit2gtk |
affected |
Debian:14 |
webkit2gtk |
— |
| wpewebkit |
affected |
Debian:11 |
wpewebkit |
— |
| wpewebkit |
affected |
Debian:12 |
wpewebkit |
— |
| wpewebkit |
affected |
Debian:13 |
wpewebkit |
— |
| wpewebkit |
affected |
Debian:14 |
wpewebkit |
— |
Open SourcePoC exploitHIGH2022-02-09
Out of bounds read in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitHIGH2022-02-09
Out of bounds read in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitCRITICAL2022-02-03
PYSEC-2022-107
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitCRITICAL2022-02-03
PYSEC-2022-52
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourcePoC exploitCRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ReverseSequence` does not fully validate the value of `batch_dim` and can result in a heap OOB read. There is a check to make sure the value of `batch_d...
CVEs:CVE-2022-21728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2022-02-03
Out of bounds read in Tensorflow
CVEs:CVE-2022-21728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitHIGH2022-02-03
PYSEC-2022-52
CVEs:CVE-2022-21728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitLOW2022-02-02
Potential proxy IP restriction bypass in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitLOW2022-02-02
Potential proxy IP restriction bypass in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
Open SourcePoC exploitLOW2022-02-01
DEBIAN-CVE-2020-8562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourcePoC exploitLOW2022-02-01
Potential proxy IP restriction bypass in Kubernetes
CVEs:CVE-2020-8562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitLOW2022-02-01
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. ...
CVEs:CVE-2020-8562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
| kubernetes |
affected |
kubernetes |
— |
— |
| Kubernetes |
affected |
Kubernetes |
— |
— |
Open SourcePoC exploitHIGH2022-02-09
Read and Write outside of bounds in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitHIGH2022-02-09
Read and Write outside of bounds in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitCRITICAL2022-02-04
PYSEC-2022-124
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitCRITICAL2022-02-04
PYSEC-2022-69
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourcePoC exploitHIGH2022-02-04
Read and Write outside of bounds in TensorFlow
CVEs:CVE-2022-23560
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitHIGH2022-02-04
PYSEC-2022-69
CVEs:CVE-2022-23560
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourcePoC exploitCRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would allow limited reads and writes outside of arrays in TFLite. This exploits missing validation in the conversion from sparse tensors to dense tensors...
CVEs:CVE-2022-23560
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2022-02-08
CVEs:CVE-2021-39635
Open SourcePoC exploitHIGH2022-02-08
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidV...
CVEs:CVE-2021-39635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2022-02-01
ASB-A-206492634
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitCRITICAL2022-02-11
CBC padding oracle issue in AWS S3 Crypto SDK for golang
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| amazon-cloudwatch-agent |
affected |
chainguard |
amazon-cloudwatch-agent |
— |
| amazon-cloudwatch-agent |
affected |
wolfi |
amazon-cloudwatch-agent |
— |
| amazon-cloudwatch-agent-fips |
affected |
chainguard |
amazon-cloudwatch-agent-fips |
— |
| amazon-ecs-agent |
affected |
chainguard |
amazon-ecs-agent |
— |
| amazon-ecs-agent-fips |
affected |
chainguard |
amazon-ecs-agent-fips |
— |
| apply-cve-bump |
affected |
chainguard |
apply-cve-bump |
— |
| argo-cd-3.0 |
affected |
wolfi |
argo-cd-3.0 |
— |
| argo-cd-3.0 |
affected |
chainguard |
argo-cd-3.0 |
— |
| argo-cd-3.1 |
affected |
wolfi |
argo-cd-3.1 |
— |
| argo-cd-3.1 |
affected |
chainguard |
argo-cd-3.1 |
— |
| argo-cd-3.2 |
affected |
wolfi |
argo-cd-3.2 |
— |
| argo-cd-3.2 |
affected |
chainguard |
argo-cd-3.2 |
— |
| argo-cd-3.3 |
affected |
chainguard |
argo-cd-3.3 |
— |
| argo-cd-3.3 |
affected |
wolfi |
argo-cd-3.3 |
— |
| argo-cd-fips-3.0 |
affected |
chainguard |
argo-cd-fips-3.0 |
— |
| argo-cd-fips-3.1 |
affected |
chainguard |
argo-cd-fips-3.1 |
— |
| argo-cd-fips-3.2 |
affected |
chainguard |
argo-cd-fips-3.2 |
— |
| argo-cd-fips-3.3 |
affected |
chainguard |
argo-cd-fips-3.3 |
— |
| argo-events |
affected |
wolfi |
argo-events |
— |
| argo-events |
affected |
chainguard |
argo-events |
— |
| argo-events-fips |
affected |
chainguard |
argo-events-fips |
— |
| argo-rollouts |
affected |
wolfi |
argo-rollouts |
— |
| argo-rollouts |
affected |
chainguard |
argo-rollouts |
— |
| argo-rollouts-fips |
affected |
chainguard |
argo-rollouts-fips |
— |
| atlas-1.0 |
affected |
chainguard |
atlas-1.0 |
— |
| atlas-1.0-fips |
affected |
chainguard |
atlas-1.0-fips |
— |
| atlas-1.1 |
affected |
chainguard |
atlas-1.1 |
— |
| atlas-1.1-fips |
affected |
chainguard |
atlas-1.1-fips |
— |
| atlas-1.2 |
affected |
chainguard |
atlas-1.2 |
— |
| aws/aws-sdk-go |
affected |
github.com |
github.com/aws/aws-sdk-go |
— |
| aws-flb-cloudwatch |
affected |
chainguard |
aws-flb-cloudwatch |
— |
| aws-flb-cloudwatch |
affected |
wolfi |
aws-flb-cloudwatch |
— |
| aws-flb-cloudwatch-fips |
affected |
chainguard |
aws-flb-cloudwatch-fips |
— |
| aws-flb-firehose |
affected |
chainguard |
aws-flb-firehose |
— |
| aws-flb-firehose |
affected |
wolfi |
aws-flb-firehose |
— |
| aws-flb-firehose-fips |
affected |
chainguard |
aws-flb-firehose-fips |
— |
| aws-flb-kinesis |
affected |
wolfi |
aws-flb-kinesis |
— |
| aws-flb-kinesis |
affected |
chainguard |
aws-flb-kinesis |
— |
| aws-flb-kinesis-fips |
affected |
chainguard |
aws-flb-kinesis-fips |
— |
| aws-node-termination-handler |
affected |
wolfi |
aws-node-termination-handler |
— |
| aws-node-termination-handler |
affected |
chainguard |
aws-node-termination-handler |
— |
| aws-node-termination-handler-fips |
affected |
chainguard |
aws-node-termination-handler-fips |
— |
| aws-nuke |
affected |
wolfi |
aws-nuke |
— |
| aws-nuke |
affected |
chainguard |
aws-nuke |
— |
| aws-nuke-fips |
affected |
chainguard |
aws-nuke-fips |
— |
| aws-otel-collector |
affected |
chainguard |
aws-otel-collector |
— |
| aws-otel-collector |
affected |
wolfi |
aws-otel-collector |
— |
| aws-otel-collector-fips |
affected |
chainguard |
aws-otel-collector-fips |
— |
| aws-s3-controller |
affected |
chainguard |
aws-s3-controller |
— |
| aws-s3-controller |
affected |
wolfi |
aws-s3-controller |
— |
| aws-sigv4-proxy |
affected |
wolfi |
aws-sigv4-proxy |
— |
| aws-sigv4-proxy |
affected |
chainguard |
aws-sigv4-proxy |
— |
| aws-sigv4-proxy-fips |
affected |
chainguard |
aws-sigv4-proxy-fips |
— |
| bank-vaults |
affected |
chainguard |
bank-vaults |
— |
| bank-vaults |
affected |
wolfi |
bank-vaults |
— |
| bank-vaults-fips |
affected |
chainguard |
bank-vaults-fips |
— |
| bank-vaults-vault-operator |
affected |
chainguard |
bank-vaults-vault-operator |
— |
| bank-vaults-vault-operator-fips |
affected |
chainguard |
bank-vaults-vault-operator-fips |
— |
| cadence |
affected |
chainguard |
cadence |
— |
| cadence-fips |
affected |
chainguard |
cadence-fips |
— |
| cephcsi |
affected |
chainguard |
cephcsi |
— |
| cephcsi-fips |
affected |
chainguard |
cephcsi-fips |
— |
| cert-exporter |
affected |
chainguard |
cert-exporter |
— |
| cert-exporter |
affected |
wolfi |
cert-exporter |
— |
| cert-exporter-fips |
affected |
chainguard |
cert-exporter-fips |
— |
| certificate-transparency |
affected |
wolfi |
certificate-transparency |
— |
| certificate-transparency |
affected |
chainguard |
certificate-transparency |
— |
| certificate-transparency-fips |
affected |
chainguard |
certificate-transparency-fips |
— |
| cg |
affected |
chainguard |
cg |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| chartmuseum-fips |
affected |
chainguard |
chartmuseum-fips |
— |
| cloudbeat-9.0 |
affected |
chainguard |
cloudbeat-9.0 |
— |
| cloudbeat-fips-8.17 |
affected |
chainguard |
cloudbeat-fips-8.17 |
— |
| cloudbeat-fips-9.0 |
affected |
chainguard |
cloudbeat-fips-9.0 |
— |
| cloud-sql-proxy-2.16 |
affected |
chainguard |
cloud-sql-proxy-2.16 |
— |
| cloud-sql-proxy-2.16 |
affected |
wolfi |
cloud-sql-proxy-2.16 |
— |
| cloud-sql-proxy-2.17 |
affected |
wolfi |
cloud-sql-proxy-2.17 |
— |
| cloud-sql-proxy-2.17 |
affected |
chainguard |
cloud-sql-proxy-2.17 |
— |
| cloud-sql-proxy-2.18 |
affected |
chainguard |
cloud-sql-proxy-2.18 |
— |
| cloud-sql-proxy-2.18 |
affected |
wolfi |
cloud-sql-proxy-2.18 |
— |
| cloud-sql-proxy-2.21 |
affected |
wolfi |
cloud-sql-proxy-2.21 |
— |
| cloud-sql-proxy-2.21 |
affected |
chainguard |
cloud-sql-proxy-2.21 |
— |
| cloud-sql-proxy-2.22 |
affected |
chainguard |
cloud-sql-proxy-2.22 |
— |
| cloud-sql-proxy-2.22 |
affected |
wolfi |
cloud-sql-proxy-2.22 |
— |
| cloud-sql-proxy-fips |
affected |
chainguard |
cloud-sql-proxy-fips |
— |
| cluster-autoscaler-1.32 |
affected |
chainguard |
cluster-autoscaler-1.32 |
— |
| cluster-autoscaler-1.32 |
affected |
wolfi |
cluster-autoscaler-1.32 |
— |
| cluster-autoscaler-1.33 |
affected |
chainguard |
cluster-autoscaler-1.33 |
— |
| cluster-autoscaler-1.33 |
affected |
wolfi |
cluster-autoscaler-1.33 |
— |
| cluster-autoscaler-1.34 |
affected |
wolfi |
cluster-autoscaler-1.34 |
— |
| cluster-autoscaler-1.34 |
affected |
chainguard |
cluster-autoscaler-1.34 |
— |
| cluster-autoscaler-fips-1.32 |
affected |
chainguard |
cluster-autoscaler-fips-1.32 |
— |
| cluster-autoscaler-fips-1.33 |
affected |
chainguard |
cluster-autoscaler-fips-1.33 |
— |
| cluster-autoscaler-fips-1.34 |
affected |
chainguard |
cluster-autoscaler-fips-1.34 |
— |
| commercial-grafana-11.6 |
affected |
chainguard |
commercial-grafana-11.6 |
— |
| commercial-grafana-12.1 |
affected |
chainguard |
commercial-grafana-12.1 |
— |
| commercial-grafana-12.2 |
affected |
chainguard |
commercial-grafana-12.2 |
— |
| commercial-grafana-12.3 |
affected |
chainguard |
commercial-grafana-12.3 |
— |
| commercial-grafana-12.4 |
affected |
chainguard |
commercial-grafana-12.4 |
— |
| commercial-grafana-13.0 |
affected |
chainguard |
commercial-grafana-13.0 |
— |
| consul-1.18 |
affected |
chainguard |
consul-1.18 |
— |
| consul-1.19 |
affected |
chainguard |
consul-1.19 |
— |
| consul-1.20 |
affected |
chainguard |
consul-1.20 |
— |
| consul-1.21 |
affected |
chainguard |
consul-1.21 |
— |
| consul-fips-1.20 |
affected |
chainguard |
consul-fips-1.20 |
— |
| consul-fips-1.21 |
affected |
chainguard |
consul-fips-1.21 |
— |
| consul-k8s-1.1 |
affected |
chainguard |
consul-k8s-1.1 |
— |
| consul-k8s-1.3 |
affected |
chainguard |
consul-k8s-1.3 |
— |
| consul-k8s-1.4 |
affected |
chainguard |
consul-k8s-1.4 |
— |
| consul-k8s-1.5 |
affected |
chainguard |
consul-k8s-1.5 |
— |
| consul-k8s-1.6 |
affected |
wolfi |
consul-k8s-1.6 |
— |
| consul-k8s-1.6 |
affected |
chainguard |
consul-k8s-1.6 |
— |
| consul-k8s-fips-1.1 |
affected |
chainguard |
consul-k8s-fips-1.1 |
— |
| consul-k8s-fips-1.3 |
affected |
chainguard |
consul-k8s-fips-1.3 |
— |
| consul-k8s-fips-1.4 |
affected |
chainguard |
consul-k8s-fips-1.4 |
— |
| consul-k8s-fips-1.5 |
affected |
chainguard |
consul-k8s-fips-1.5 |
— |
| consul-k8s-fips-1.6 |
affected |
chainguard |
consul-k8s-fips-1.6 |
— |
| crossplane-aws-provider |
affected |
chainguard |
crossplane-aws-provider |
— |
| crossplane-aws-provider-fips |
affected |
chainguard |
crossplane-aws-provider-fips |
— |
| dapr-1.14 |
affected |
chainguard |
dapr-1.14 |
— |
| dapr-1.15 |
affected |
chainguard |
dapr-1.15 |
— |
| dapr-1.15 |
affected |
wolfi |
dapr-1.15 |
— |
| dapr-1.16 |
affected |
wolfi |
dapr-1.16 |
— |
| dapr-1.16 |
affected |
chainguard |
dapr-1.16 |
— |
| dapr-fips-1.14 |
affected |
chainguard |
dapr-fips-1.14 |
— |
| dapr-fips-1.15 |
affected |
chainguard |
dapr-fips-1.15 |
— |
| dapr-fips-1.16 |
affected |
chainguard |
dapr-fips-1.16 |
— |
| datadog-agent-7.71 |
affected |
chainguard |
datadog-agent-7.71 |
— |
| datadog-agent-7.77 |
affected |
wolfi |
datadog-agent-7.77 |
— |
| datadog-agent-7.77 |
affected |
chainguard |
datadog-agent-7.77 |
— |
| datadog-agent-7.78 |
affected |
chainguard |
datadog-agent-7.78 |
— |
| datadog-agent-7.78 |
affected |
wolfi |
datadog-agent-7.78 |
— |
| datadog-agent-7.79 |
affected |
chainguard |
datadog-agent-7.79 |
— |
| datadog-agent-7.79 |
affected |
wolfi |
datadog-agent-7.79 |
— |
| datadog-agent-fips-7.71 |
affected |
chainguard |
datadog-agent-fips-7.71 |
— |
| datadog-agent-fips-7.77 |
affected |
chainguard |
datadog-agent-fips-7.77 |
— |
| datadog-agent-fips-7.78 |
affected |
chainguard |
datadog-agent-fips-7.78 |
— |
| datadog-agent-fips-7.79 |
affected |
chainguard |
datadog-agent-fips-7.79 |
— |
| distribution |
affected |
chainguard |
distribution |
— |
| distribution |
affected |
wolfi |
distribution |
— |
| distribution-fips |
affected |
chainguard |
distribution-fips |
— |
| drone |
affected |
chainguard |
drone |
— |
| drone-fips |
affected |
chainguard |
drone-fips |
— |
| elastic-agent-8.19 |
affected |
chainguard |
elastic-agent-8.19 |
— |
| elastic-agent-9.1 |
affected |
chainguard |
elastic-agent-9.1 |
— |
| elastic-agent-9.2 |
affected |
chainguard |
elastic-agent-9.2 |
— |
| elastic-agent-9.3 |
affected |
chainguard |
elastic-agent-9.3 |
— |
| elastic-agent-9.4 |
affected |
chainguard |
elastic-agent-9.4 |
— |
| elastic-agent-fips-8.19 |
affected |
chainguard |
elastic-agent-fips-8.19 |
— |
| elastic-agent-fips-9.1 |
affected |
chainguard |
elastic-agent-fips-9.1 |
— |
| elastic-agent-fips-9.2 |
affected |
chainguard |
elastic-agent-fips-9.2 |
— |
| elastic-agent-fips-9.3 |
affected |
chainguard |
elastic-agent-fips-9.3 |
— |
| elastic-agent-fips-9.4 |
affected |
chainguard |
elastic-agent-fips-9.4 |
— |
| external-secrets-fips |
affected |
chainguard |
external-secrets-fips |
— |
| external-secrets-operator-1.2 |
affected |
wolfi |
external-secrets-operator-1.2 |
— |
| external-secrets-operator-1.2 |
affected |
chainguard |
external-secrets-operator-1.2 |
— |
| external-secrets-operator-1.3 |
affected |
chainguard |
external-secrets-operator-1.3 |
— |
| external-secrets-operator-1.3 |
affected |
wolfi |
external-secrets-operator-1.3 |
— |
| external-secrets-operator-2.0 |
affected |
wolfi |
external-secrets-operator-2.0 |
— |
| external-secrets-operator-2.0 |
affected |
chainguard |
external-secrets-operator-2.0 |
— |
| external-secrets-operator-2.1 |
affected |
chainguard |
external-secrets-operator-2.1 |
— |
| external-secrets-operator-2.1 |
affected |
wolfi |
external-secrets-operator-2.1 |
— |
| external-secrets-operator-2.2 |
affected |
chainguard |
external-secrets-operator-2.2 |
— |
| external-secrets-operator-2.2 |
affected |
wolfi |
external-secrets-operator-2.2 |
— |
| external-secrets-operator-2.3 |
affected |
chainguard |
external-secrets-operator-2.3 |
— |
| external-secrets-operator-2.3 |
affected |
wolfi |
external-secrets-operator-2.3 |
— |
| external-secrets-operator-2.4 |
affected |
chainguard |
external-secrets-operator-2.4 |
— |
| external-secrets-operator-2.4 |
affected |
wolfi |
external-secrets-operator-2.4 |
— |
| external-secrets-operator-2.5 |
affected |
wolfi |
external-secrets-operator-2.5 |
— |
| external-secrets-operator-2.5 |
affected |
chainguard |
external-secrets-operator-2.5 |
— |
| external-secrets-operator-2.6 |
affected |
chainguard |
external-secrets-operator-2.6 |
— |
| external-secrets-operator-2.6 |
affected |
wolfi |
external-secrets-operator-2.6 |
— |
| external-secrets-operator-2.7 |
affected |
chainguard |
external-secrets-operator-2.7 |
— |
| external-secrets-operator-fips-1.2 |
affected |
chainguard |
external-secrets-operator-fips-1.2 |
— |
| external-secrets-operator-fips-1.3 |
affected |
chainguard |
external-secrets-operator-fips-1.3 |
— |
| external-secrets-operator-fips-2.0 |
affected |
chainguard |
external-secrets-operator-fips-2.0 |
— |
| external-secrets-operator-fips-2.1 |
affected |
chainguard |
external-secrets-operator-fips-2.1 |
— |
| external-secrets-operator-fips-2.2 |
affected |
chainguard |
external-secrets-operator-fips-2.2 |
— |
| external-secrets-operator-fips-2.3 |
affected |
chainguard |
external-secrets-operator-fips-2.3 |
— |
| external-secrets-operator-fips-2.4 |
affected |
chainguard |
external-secrets-operator-fips-2.4 |
— |
| external-secrets-operator-fips-2.5 |
affected |
chainguard |
external-secrets-operator-fips-2.5 |
— |
| external-secrets-operator-fips-2.6 |
affected |
chainguard |
external-secrets-operator-fips-2.6 |
— |
| external-secrets-operator-fips-2.7 |
affected |
chainguard |
external-secrets-operator-fips-2.7 |
— |
| flagger |
affected |
chainguard |
flagger |
— |
| flagger-fips |
affected |
chainguard |
flagger-fips |
— |
| flyte |
affected |
chainguard |
flyte |
— |
| flyte |
affected |
wolfi |
flyte |
— |
| gatekeeper-3.20 |
affected |
wolfi |
gatekeeper-3.20 |
— |
| gatekeeper-3.20 |
affected |
chainguard |
gatekeeper-3.20 |
— |
| gatekeeper-3.21 |
affected |
chainguard |
gatekeeper-3.21 |
— |
| gatekeeper-3.21 |
affected |
wolfi |
gatekeeper-3.21 |
— |
| gatekeeper-3.22 |
affected |
chainguard |
gatekeeper-3.22 |
— |
| gatekeeper-3.22 |
affected |
wolfi |
gatekeeper-3.22 |
— |
| gatekeeper-fips-3.20 |
affected |
chainguard |
gatekeeper-fips-3.20 |
— |
| gatekeeper-fips-3.21 |
affected |
chainguard |
gatekeeper-fips-3.21 |
— |
| gatekeeper-fips-3.22 |
affected |
chainguard |
gatekeeper-fips-3.22 |
— |
| gitlab-cng-18.10 |
affected |
chainguard |
gitlab-cng-18.10 |
— |
| gitlab-cng-18.11 |
affected |
chainguard |
gitlab-cng-18.11 |
— |
| gitlab-cng-19.0 |
affected |
chainguard |
gitlab-cng-19.0 |
— |
| gitlab-cng-19.1 |
affected |
chainguard |
gitlab-cng-19.1 |
— |
| gitlab-cng-fips-18.10 |
affected |
chainguard |
gitlab-cng-fips-18.10 |
— |
| gitlab-cng-fips-18.11 |
affected |
chainguard |
gitlab-cng-fips-18.11 |
— |
| gitlab-cng-fips-19.0 |
affected |
chainguard |
gitlab-cng-fips-19.0 |
— |
| gitlab-cng-fips-19.1 |
affected |
chainguard |
gitlab-cng-fips-19.1 |
— |
| gitlab-runner-18.10 |
affected |
wolfi |
gitlab-runner-18.10 |
— |
| gitlab-runner-18.10 |
affected |
chainguard |
gitlab-runner-18.10 |
— |
| gitlab-runner-18.11 |
affected |
chainguard |
gitlab-runner-18.11 |
— |
| gitlab-runner-18.11 |
affected |
wolfi |
gitlab-runner-18.11 |
— |
| gitlab-runner-19.0 |
affected |
chainguard |
gitlab-runner-19.0 |
— |
| gitlab-runner-19.0 |
affected |
wolfi |
gitlab-runner-19.0 |
— |
| gitlab-runner-19.1 |
affected |
chainguard |
gitlab-runner-19.1 |
— |
| gitlab-runner-19.1 |
affected |
wolfi |
gitlab-runner-19.1 |
— |
| gitlab-runner-fips-18.10 |
affected |
chainguard |
gitlab-runner-fips-18.10 |
— |
| gitlab-runner-fips-18.11 |
affected |
chainguard |
gitlab-runner-fips-18.11 |
— |
| gitlab-runner-fips-19.0 |
affected |
chainguard |
gitlab-runner-fips-19.0 |
— |
| gitlab-runner-fips-19.1 |
affected |
chainguard |
gitlab-runner-fips-19.1 |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitsign |
affected |
chainguard |
gitsign |
— |
| gitsign |
affected |
wolfi |
gitsign |
— |
| go-getter-2 |
affected |
chainguard |
go-getter-2 |
— |
| go-getter-2.1 |
affected |
chainguard |
go-getter-2.1 |
— |
| go-getter-2.2 |
affected |
chainguard |
go-getter-2.2 |
— |
| go-getter-2-fips |
affected |
chainguard |
go-getter-2-fips |
— |
| gomplate-4 |
affected |
chainguard |
gomplate-4 |
— |
| gomplate-5 |
affected |
chainguard |
gomplate-5 |
— |
| gomplate-5 |
affected |
wolfi |
gomplate-5 |
— |
| gomplate-fips-4 |
affected |
chainguard |
gomplate-fips-4 |
— |
| gomplate-fips-5 |
affected |
chainguard |
gomplate-fips-5 |
— |
| google-cloud-otel-ops-collector |
affected |
chainguard |
google-cloud-otel-ops-collector |
— |
| gostatsd |
affected |
wolfi |
gostatsd |
— |
| gostatsd |
affected |
chainguard |
gostatsd |
— |
| grafana-10.1 |
affected |
chainguard |
grafana-10.1 |
— |
| grafana-11.6 |
affected |
chainguard |
grafana-11.6 |
— |
| grafana-12.0 |
affected |
chainguard |
grafana-12.0 |
— |
| grafana-12.0 |
affected |
wolfi |
grafana-12.0 |
— |
| grafana-12.1 |
affected |
chainguard |
grafana-12.1 |
— |
| grafana-12.1 |
affected |
wolfi |
grafana-12.1 |
— |
| grafana-12.2 |
affected |
chainguard |
grafana-12.2 |
— |
| grafana-12.2 |
affected |
wolfi |
grafana-12.2 |
— |
| grafana-12.3 |
affected |
wolfi |
grafana-12.3 |
— |
| grafana-12.3 |
affected |
chainguard |
grafana-12.3 |
— |
| grafana-12.4 |
affected |
wolfi |
grafana-12.4 |
— |
| grafana-12.4 |
affected |
chainguard |
grafana-12.4 |
— |
| grafana-13.0 |
affected |
chainguard |
grafana-13.0 |
— |
| grafana-13.0 |
affected |
wolfi |
grafana-13.0 |
— |
| grafana-13.1 |
affected |
chainguard |
grafana-13.1 |
— |
| grafana-agent-operator |
affected |
chainguard |
grafana-agent-operator |
— |
| grafana-agent-operator |
affected |
wolfi |
grafana-agent-operator |
— |
| grafana-fips-11.6 |
affected |
chainguard |
grafana-fips-11.6 |
— |
| grafana-fips-12.0 |
affected |
chainguard |
grafana-fips-12.0 |
— |
| grafana-fips-12.1 |
affected |
chainguard |
grafana-fips-12.1 |
— |
| grafana-fips-12.2 |
affected |
chainguard |
grafana-fips-12.2 |
— |
| grafana-fips-12.3 |
affected |
chainguard |
grafana-fips-12.3 |
— |
| grafana-fips-12.4 |
affected |
chainguard |
grafana-fips-12.4 |
— |
| grafana-fips-13.0 |
affected |
chainguard |
grafana-fips-13.0 |
— |
| grafana-fips-13.1 |
affected |
chainguard |
grafana-fips-13.1 |
— |
| grafana-mimir-2.17 |
affected |
chainguard |
grafana-mimir-2.17 |
— |
| grafana-mimir-3.0 |
affected |
wolfi |
grafana-mimir-3.0 |
— |
| grafana-mimir-3.0 |
affected |
chainguard |
grafana-mimir-3.0 |
— |
| grafana-mimir-fips-2.17 |
affected |
chainguard |
grafana-mimir-fips-2.17 |
— |
| grafana-mimir-fips-3.0 |
affected |
chainguard |
grafana-mimir-fips-3.0 |
— |
| grafana-pyroscope-1.12 |
affected |
chainguard |
grafana-pyroscope-1.12 |
— |
| grafana-pyroscope-1.13 |
affected |
wolfi |
grafana-pyroscope-1.13 |
— |
| grafana-pyroscope-1.13 |
affected |
chainguard |
grafana-pyroscope-1.13 |
— |
| grafana-pyroscope-1.14 |
affected |
chainguard |
grafana-pyroscope-1.14 |
— |
| grept |
affected |
chainguard |
grept |
— |
| grept-fips |
affected |
chainguard |
grept-fips |
— |
| guac |
affected |
chainguard |
guac |
— |
| guac |
affected |
wolfi |
guac |
— |
| harbor-2.12 |
affected |
chainguard |
harbor-2.12 |
— |
| harbor-2.13 |
affected |
chainguard |
harbor-2.13 |
— |
| harbor-2.13 |
affected |
wolfi |
harbor-2.13 |
— |
| harbor-2.14 |
affected |
chainguard |
harbor-2.14 |
— |
| harbor-2.14 |
affected |
wolfi |
harbor-2.14 |
— |
| harbor-2.15 |
affected |
chainguard |
harbor-2.15 |
— |
| harbor-fips-2.12 |
affected |
chainguard |
harbor-fips-2.12 |
— |
| harbor-fips-2.13 |
affected |
chainguard |
harbor-fips-2.13 |
— |
| harbor-fips-2.14 |
affected |
chainguard |
harbor-fips-2.14 |
— |
| harbor-fips-2.15 |
affected |
chainguard |
harbor-fips-2.15 |
— |
| harbor-registry |
affected |
wolfi |
harbor-registry |
— |
| harbor-registry |
affected |
chainguard |
harbor-registry |
— |
| harbor-registry-fips |
affected |
chainguard |
harbor-registry-fips |
— |
| harvester |
affected |
chainguard |
harvester |
— |
| harvester-fips |
affected |
chainguard |
harvester-fips |
— |
| influxd-2.7 |
affected |
chainguard |
influxd-2.7 |
— |
| juicefs-1.2 |
affected |
chainguard |
juicefs-1.2 |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k8s-image-swapper |
affected |
chainguard |
k8s-image-swapper |
— |
| k8s-image-swapper-fips |
affected |
chainguard |
k8s-image-swapper-fips |
— |
| karpenter-0.33 |
affected |
chainguard |
karpenter-0.33 |
— |
| karpenter-0.34 |
affected |
chainguard |
karpenter-0.34 |
— |
| karpenter-0.35 |
affected |
chainguard |
karpenter-0.35 |
— |
| karpenter-0.36 |
affected |
chainguard |
karpenter-0.36 |
— |
| karpenter-0.37 |
affected |
chainguard |
karpenter-0.37 |
— |
| karpenter-fips-0.33 |
affected |
chainguard |
karpenter-fips-0.33 |
— |
| karpenter-fips-0.34 |
affected |
chainguard |
karpenter-fips-0.34 |
— |
| karpenter-fips-0.35 |
affected |
chainguard |
karpenter-fips-0.35 |
— |
| karpenter-fips-0.36 |
affected |
chainguard |
karpenter-fips-0.36 |
— |
| karpenter-fips-0.37 |
affected |
chainguard |
karpenter-fips-0.37 |
— |
| kiam |
affected |
chainguard |
kiam |
— |
| kots |
affected |
wolfi |
kots |
— |
| kots |
affected |
chainguard |
kots |
— |
| kserve |
affected |
chainguard |
kserve |
— |
| kserve |
affected |
wolfi |
kserve |
— |
| kserve-fips |
affected |
chainguard |
kserve-fips |
— |
| kserve-localmodelnode-agent |
affected |
chainguard |
kserve-localmodelnode-agent |
— |
| kserve-localmodelnode-agent-fips |
affected |
chainguard |
kserve-localmodelnode-agent-fips |
— |
| kserve-modelmesh-serving |
affected |
wolfi |
kserve-modelmesh-serving |
— |
| kserve-modelmesh-serving |
affected |
chainguard |
kserve-modelmesh-serving |
— |
| kube-arangodb-1.3 |
affected |
wolfi |
kube-arangodb-1.3 |
— |
| kube-arangodb-1.3 |
affected |
chainguard |
kube-arangodb-1.3 |
— |
| kube-arangodb-1.4 |
affected |
wolfi |
kube-arangodb-1.4 |
— |
| kube-arangodb-1.4 |
affected |
chainguard |
kube-arangodb-1.4 |
— |
| kube-arangodb-fips-1.3 |
affected |
chainguard |
kube-arangodb-fips-1.3 |
— |
| kube-arangodb-fips-1.4 |
affected |
chainguard |
kube-arangodb-fips-1.4 |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubeflow-pipelines-driver-fips |
affected |
chainguard |
kubeflow-pipelines-driver-fips |
— |
| kubeflow-pipelines-fips |
affected |
chainguard |
kubeflow-pipelines-fips |
— |
| kubernetes-event-exporter |
affected |
chainguard |
kubernetes-event-exporter |
— |
| kubernetes-event-exporter |
affected |
wolfi |
kubernetes-event-exporter |
— |
| kubernetes-event-exporter-fips |
affected |
chainguard |
kubernetes-event-exporter-fips |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape-operator |
affected |
wolfi |
kubescape-operator |
— |
| kubescape-operator |
affected |
chainguard |
kubescape-operator |
— |
| kubescape-operator-fips |
affected |
chainguard |
kubescape-operator-fips |
— |
| kubescape-server |
affected |
chainguard |
kubescape-server |
— |
| kubescape-server-fips |
affected |
chainguard |
kubescape-server-fips |
— |
| kubevirt-cdi-uploadserver-1.5 |
affected |
chainguard |
kubevirt-cdi-uploadserver-1.5 |
— |
| kubevirt-cdi-uploadserver-1.59 |
affected |
chainguard |
kubevirt-cdi-uploadserver-1.59 |
— |
| kubevirt-cdi-uploadserver-1.6 |
affected |
chainguard |
kubevirt-cdi-uploadserver-1.6 |
— |
| kubevirt-cdi-uploadserver-fips-1.5 |
affected |
chainguard |
kubevirt-cdi-uploadserver-fips-1.5 |
— |
| kubevirt-cdi-uploadserver-fips-1.59 |
affected |
chainguard |
kubevirt-cdi-uploadserver-fips-1.59 |
— |
| kubevirt-cdi-uploadserver-fips-1.6 |
affected |
chainguard |
kubevirt-cdi-uploadserver-fips-1.6 |
— |
| loki-2.9 |
affected |
chainguard |
loki-2.9 |
— |
| loki-3.4 |
affected |
chainguard |
loki-3.4 |
— |
| loki-3.5 |
affected |
wolfi |
loki-3.5 |
— |
| loki-3.5 |
affected |
chainguard |
loki-3.5 |
— |
| loki-3.6 |
affected |
chainguard |
loki-3.6 |
— |
| loki-3.6 |
affected |
wolfi |
loki-3.6 |
— |
| loki-3.7 |
affected |
chainguard |
loki-3.7 |
— |
| loki-3.7 |
affected |
wolfi |
loki-3.7 |
— |
| loki-fips-2.9 |
affected |
chainguard |
loki-fips-2.9 |
— |
| loki-fips-3.4 |
affected |
chainguard |
loki-fips-3.4 |
— |
| loki-fips-3.5 |
affected |
chainguard |
loki-fips-3.5 |
— |
| loki-fips-3.6 |
affected |
chainguard |
loki-fips-3.6 |
— |
| loki-fips-3.7 |
affected |
chainguard |
loki-fips-3.7 |
— |
| longhorn-backing-image-manager-1.8 |
affected |
chainguard |
longhorn-backing-image-manager-1.8 |
— |
| longhorn-backing-image-manager-1.9 |
affected |
chainguard |
longhorn-backing-image-manager-1.9 |
— |
| longhorn-backing-image-manager-fips-1.8 |
affected |
chainguard |
longhorn-backing-image-manager-fips-1.8 |
— |
| longhorn-backing-image-manager-fips-1.9 |
affected |
chainguard |
longhorn-backing-image-manager-fips-1.9 |
— |
| longhorn-engine-1.8 |
affected |
chainguard |
longhorn-engine-1.8 |
— |
| longhorn-engine-1.9 |
affected |
chainguard |
longhorn-engine-1.9 |
— |
| longhorn-instance-manager-1.8 |
affected |
chainguard |
longhorn-instance-manager-1.8 |
— |
| longhorn-instance-manager-1.8-fips |
affected |
chainguard |
longhorn-instance-manager-1.8-fips |
— |
| longhorn-instance-manager-1.9 |
affected |
chainguard |
longhorn-instance-manager-1.9 |
— |
| longhorn-instance-manager-1.9-fips |
affected |
chainguard |
longhorn-instance-manager-1.9-fips |
— |
| mapotf |
affected |
chainguard |
mapotf |
— |
| mapotf-fips |
affected |
chainguard |
mapotf-fips |
— |
| mattermost-10.11 |
affected |
chainguard |
mattermost-10.11 |
— |
| mattermost-11.1 |
affected |
chainguard |
mattermost-11.1 |
— |
| mattermost-11.1 |
affected |
wolfi |
mattermost-11.1 |
— |
| mattermost-11.2 |
affected |
chainguard |
mattermost-11.2 |
— |
| mattermost-11.2 |
affected |
wolfi |
mattermost-11.2 |
— |
| mattermost-fips-10.11 |
affected |
chainguard |
mattermost-fips-10.11 |
— |
| mattermost-fips-11.1 |
affected |
chainguard |
mattermost-fips-11.1 |
— |
| mattermost-fips-11.2 |
affected |
chainguard |
mattermost-fips-11.2 |
— |
| metrics-agent |
affected |
wolfi |
metrics-agent |
— |
| metrics-agent |
affected |
chainguard |
metrics-agent |
— |
| metrics-agent-fips |
affected |
chainguard |
metrics-agent-fips |
— |
| monstache |
affected |
chainguard |
monstache |
— |
| neuvector |
affected |
chainguard |
neuvector |
— |
| neuvector-fips |
affected |
chainguard |
neuvector-fips |
— |
| neuvector-scanner |
affected |
chainguard |
neuvector-scanner |
— |
| neuvector-scanner |
affected |
wolfi |
neuvector-scanner |
— |
| neuvector-scanner-fips |
affected |
chainguard |
neuvector-scanner-fips |
— |
| newrelic-nri-statsd |
affected |
chainguard |
newrelic-nri-statsd |
— |
| newrelic-nri-statsd |
affected |
wolfi |
newrelic-nri-statsd |
— |
| node-problem-detector-0.8 |
affected |
chainguard |
node-problem-detector-0.8 |
— |
| node-problem-detector-1.34 |
affected |
chainguard |
node-problem-detector-1.34 |
— |
| node-problem-detector-1.35 |
affected |
wolfi |
node-problem-detector-1.35 |
— |
| node-problem-detector-1.35 |
affected |
chainguard |
node-problem-detector-1.35 |
— |
| node-problem-detector-fips-0.8 |
affected |
chainguard |
node-problem-detector-fips-0.8 |
— |
| node-problem-detector-fips-1.34 |
affected |
chainguard |
node-problem-detector-fips-1.34 |
— |
| node-problem-detector-fips-1.35 |
affected |
chainguard |
node-problem-detector-fips-1.35 |
— |
| nrdot-collector |
affected |
chainguard |
nrdot-collector |
— |
| nrdot-collector-fips |
affected |
chainguard |
nrdot-collector-fips |
— |
| nrdot-collector-k8s |
affected |
chainguard |
nrdot-collector-k8s |
— |
| nrdot-collector-k8s-fips |
affected |
chainguard |
nrdot-collector-k8s-fips |
— |
| openbao |
affected |
wolfi |
openbao |
— |
| openbao |
affected |
chainguard |
openbao |
— |
| openbao-fips |
affected |
chainguard |
openbao-fips |
— |
| opencost |
affected |
chainguard |
opencost |
— |
| opencost |
affected |
wolfi |
opencost |
— |
| opencost-fips |
affected |
chainguard |
opencost-fips |
— |
| opentelemetry-collector |
affected |
chainguard |
opentelemetry-collector |
— |
| opentelemetry-collector |
affected |
wolfi |
opentelemetry-collector |
— |
| opentelemetry-collector-contrib |
affected |
wolfi |
opentelemetry-collector-contrib |
— |
| opentelemetry-collector-contrib |
affected |
chainguard |
opentelemetry-collector-contrib |
— |
| opentelemetry-collector-contrib-fips |
affected |
chainguard |
opentelemetry-collector-contrib-fips |
— |
| opentelemetry-collector-fips |
affected |
chainguard |
opentelemetry-collector-fips |
— |
| opentelemetry-collector-k8s |
affected |
chainguard |
opentelemetry-collector-k8s |
— |
| opentelemetry-collector-k8s-fips |
affected |
chainguard |
opentelemetry-collector-k8s-fips |
— |
| opentofu-1.9 |
affected |
wolfi |
opentofu-1.9 |
— |
| opentofu-1.9 |
affected |
chainguard |
opentofu-1.9 |
— |
| opentofu-fips-1.9 |
affected |
chainguard |
opentofu-fips-1.9 |
— |
| packer |
affected |
chainguard |
packer |
— |
| packer-fips |
affected |
chainguard |
packer-fips |
— |
| plutono |
affected |
chainguard |
plutono |
— |
| plutono-fips |
affected |
chainguard |
plutono-fips |
— |
| porch |
affected |
chainguard |
porch |
— |
| porch-fips |
affected |
chainguard |
porch-fips |
— |
| postgres-operator |
affected |
wolfi |
postgres-operator |
— |
| postgres-operator |
affected |
chainguard |
postgres-operator |
— |
| postgres-operator-fips |
affected |
chainguard |
postgres-operator-fips |
— |
| prometheus-2.51 |
affected |
chainguard |
prometheus-2.51 |
— |
| prometheus-3.12 |
affected |
chainguard |
prometheus-3.12 |
— |
| prometheus-3.12 |
affected |
wolfi |
prometheus-3.12 |
— |
| prometheus-3.5 |
affected |
chainguard |
prometheus-3.5 |
— |
| prometheus-fips-3.12 |
affected |
chainguard |
prometheus-fips-3.12 |
— |
| prometheus-fips-3.5 |
affected |
chainguard |
prometheus-fips-3.5 |
— |
| promxy |
affected |
chainguard |
promxy |
— |
| promxy |
affected |
wolfi |
promxy |
— |
| promxy-fips |
affected |
chainguard |
promxy-fips |
— |
| rancher-2.10 |
affected |
chainguard |
rancher-2.10 |
— |
| rancher-2.11 |
affected |
chainguard |
rancher-2.11 |
— |
| rancher-2.12 |
affected |
chainguard |
rancher-2.12 |
— |
| rancher-2.13 |
affected |
wolfi |
rancher-2.13 |
— |
| rancher-2.13 |
affected |
chainguard |
rancher-2.13 |
— |
| rancher-2.14 |
affected |
wolfi |
rancher-2.14 |
— |
| rancher-2.14 |
affected |
chainguard |
rancher-2.14 |
— |
| rancher-agent-2.10 |
affected |
chainguard |
rancher-agent-2.10 |
— |
| rancher-agent-2.11 |
affected |
chainguard |
rancher-agent-2.11 |
— |
| rancher-agent-2.12 |
affected |
chainguard |
rancher-agent-2.12 |
— |
| rancher-agent-2.13 |
affected |
chainguard |
rancher-agent-2.13 |
— |
| rancher-agent-2.13 |
affected |
wolfi |
rancher-agent-2.13 |
— |
| rancher-agent-2.14 |
affected |
wolfi |
rancher-agent-2.14 |
— |
| rancher-agent-2.14 |
affected |
chainguard |
rancher-agent-2.14 |
— |
| rancher-agent-2.9 |
affected |
chainguard |
rancher-agent-2.9 |
— |
| rancher-machine |
affected |
chainguard |
rancher-machine |
— |
| rancher-machine |
affected |
wolfi |
rancher-machine |
— |
| redpanda-25.1 |
affected |
chainguard |
redpanda-25.1 |
— |
| redpanda-25.2 |
affected |
chainguard |
redpanda-25.2 |
— |
| redpanda-25.3 |
affected |
chainguard |
redpanda-25.3 |
— |
| rook-1.18 |
affected |
chainguard |
rook-1.18 |
— |
| rook-1.19 |
affected |
chainguard |
rook-1.19 |
— |
| rook-1.19 |
affected |
wolfi |
rook-1.19 |
— |
| rook-fips-1.18 |
affected |
chainguard |
rook-fips-1.18 |
— |
| rook-fips-1.19 |
affected |
chainguard |
rook-fips-1.19 |
— |
| s5cmd |
affected |
wolfi |
s5cmd |
— |
| s5cmd |
affected |
chainguard |
s5cmd |
— |
| s5cmd-fips |
affected |
chainguard |
s5cmd-fips |
— |
| seaweedfs |
affected |
chainguard |
seaweedfs |
— |
| seaweedfs |
affected |
wolfi |
seaweedfs |
— |
| seaweedfs-fips |
affected |
chainguard |
seaweedfs-fips |
— |
| seaweedfs-operator |
affected |
chainguard |
seaweedfs-operator |
— |
| seaweedfs-operator-fips |
affected |
chainguard |
seaweedfs-operator-fips |
— |
| seaweedfs-rocksdb |
affected |
chainguard |
seaweedfs-rocksdb |
— |
| seaweedfs-rocksdb-fips |
affected |
chainguard |
seaweedfs-rocksdb-fips |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| splunk-otel-collector |
affected |
wolfi |
splunk-otel-collector |
— |
| splunk-otel-collector |
affected |
chainguard |
splunk-otel-collector |
— |
| splunk-otel-collector-fips |
affected |
chainguard |
splunk-otel-collector-fips |
— |
| steampipe |
affected |
wolfi |
steampipe |
— |
| steampipe |
affected |
chainguard |
steampipe |
— |
| step-ca |
affected |
wolfi |
step-ca |
— |
| step-ca |
affected |
chainguard |
step-ca |
— |
| step-ca-fips |
affected |
chainguard |
step-ca-fips |
— |
| tekton-chains |
affected |
chainguard |
tekton-chains |
— |
| tekton-chains |
affected |
wolfi |
tekton-chains |
— |
| tekton-chains-fips |
affected |
chainguard |
tekton-chains-fips |
— |
| teleport-17 |
affected |
chainguard |
teleport-17 |
— |
| teleport-operator-fips-16 |
affected |
chainguard |
teleport-operator-fips-16 |
— |
| teleport-operator-fips-17 |
affected |
chainguard |
teleport-operator-fips-17 |
— |
| tempo-2.8 |
affected |
chainguard |
tempo-2.8 |
— |
| tempo-2.9 |
affected |
chainguard |
tempo-2.9 |
— |
| tempo-fips-2.8 |
affected |
chainguard |
tempo-fips-2.8 |
— |
| tempo-fips-2.9 |
affected |
chainguard |
tempo-fips-2.9 |
— |
| terraform |
affected |
wolfi |
terraform |
— |
| terraform |
affected |
chainguard |
terraform |
— |
| terraform-1.10 |
affected |
chainguard |
terraform-1.10 |
— |
| terraform-1.11 |
affected |
chainguard |
terraform-1.11 |
— |
| terraform-1.12 |
affected |
chainguard |
terraform-1.12 |
— |
| terraform-1.9 |
affected |
chainguard |
terraform-1.9 |
— |
| terragrunt |
affected |
chainguard |
terragrunt |
— |
| terragrunt |
affected |
wolfi |
terragrunt |
— |
| terragrunt-fips |
affected |
chainguard |
terragrunt-fips |
— |
| tigera-operator-1.28 |
affected |
chainguard |
tigera-operator-1.28 |
— |
| tigera-operator-1.29 |
affected |
chainguard |
tigera-operator-1.29 |
— |
| tigera-operator-1.34 |
affected |
chainguard |
tigera-operator-1.34 |
— |
| tigera-operator-1.36 |
affected |
chainguard |
tigera-operator-1.36 |
— |
| tigera-operator-1.37 |
affected |
chainguard |
tigera-operator-1.37 |
— |
| tigera-operator-1.38 |
affected |
chainguard |
tigera-operator-1.38 |
— |
| tigera-operator-1.40 |
affected |
wolfi |
tigera-operator-1.40 |
— |
| tigera-operator-1.40 |
affected |
chainguard |
tigera-operator-1.40 |
— |
| tigera-operator-1.41 |
affected |
wolfi |
tigera-operator-1.41 |
— |
| tigera-operator-1.41 |
affected |
chainguard |
tigera-operator-1.41 |
— |
| tigera-operator-fips-1.29 |
affected |
chainguard |
tigera-operator-fips-1.29 |
— |
| tigera-operator-fips-1.34 |
affected |
chainguard |
tigera-operator-fips-1.34 |
— |
| tigera-operator-fips-1.36 |
affected |
chainguard |
tigera-operator-fips-1.36 |
— |
| tigera-operator-fips-1.37 |
affected |
chainguard |
tigera-operator-fips-1.37 |
— |
| tigera-operator-fips-1.38 |
affected |
chainguard |
tigera-operator-fips-1.38 |
— |
| tigera-operator-fips-1.40 |
affected |
chainguard |
tigera-operator-fips-1.40 |
— |
| tigera-operator-fips-1.41 |
affected |
chainguard |
tigera-operator-fips-1.41 |
— |
| trillian |
affected |
chainguard |
trillian |
— |
| trillian |
affected |
wolfi |
trillian |
— |
| trillian-fips |
affected |
chainguard |
trillian-fips |
— |
| vault-1.16 |
affected |
chainguard |
vault-1.16 |
— |
| vault-1.17 |
affected |
chainguard |
vault-1.17 |
— |
| vault-1.18 |
affected |
chainguard |
vault-1.18 |
— |
| vault-1.19 |
affected |
chainguard |
vault-1.19 |
— |
| vault-1.20 |
affected |
chainguard |
vault-1.20 |
— |
| vault-1.21 |
affected |
chainguard |
vault-1.21 |
— |
| vault-2.0 |
affected |
chainguard |
vault-2.0 |
— |
| vault-benchmark |
affected |
wolfi |
vault-benchmark |
— |
| vault-benchmark |
affected |
chainguard |
vault-benchmark |
— |
| vault-env |
affected |
wolfi |
vault-env |
— |
| vault-env |
affected |
chainguard |
vault-env |
— |
| vault-fips-1.21 |
affected |
chainguard |
vault-fips-1.21 |
— |
| vault-fips-2.0 |
affected |
chainguard |
vault-fips-2.0 |
— |
| vault-secrets-operator |
affected |
chainguard |
vault-secrets-operator |
— |
| vault-secrets-operator-fips |
affected |
chainguard |
vault-secrets-operator-fips |
— |
| vault-secrets-webhook |
affected |
chainguard |
vault-secrets-webhook |
— |
| vault-secrets-webhook |
affected |
wolfi |
vault-secrets-webhook |
— |
| verticadb-operator |
affected |
wolfi |
verticadb-operator |
— |
| verticadb-operator |
affected |
chainguard |
verticadb-operator |
— |
| verticadb-operator-fips |
affected |
chainguard |
verticadb-operator-fips |
— |
| wal-g |
affected |
wolfi |
wal-g |
— |
| wal-g |
affected |
chainguard |
wal-g |
— |
| weaviate |
affected |
wolfi |
weaviate |
— |
| weaviate |
affected |
chainguard |
weaviate |
— |
| zot |
affected |
chainguard |
zot |
— |
| zot |
affected |
wolfi |
zot |
— |
GooglePoC exploitCRITICAL2022-02-11
CBC padding oracle issue in AWS S3 Crypto SDK for golang
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aws/aws-sdk-go |
affected |
github.com |
github.com/aws/aws-sdk-go |
— |
Open SourcePoC exploit2022-02-11
CBC padding oracle issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| amazon-cloudwatch-agent |
affected |
wolfi |
amazon-cloudwatch-agent |
— |
| amazon-cloudwatch-agent |
affected |
chainguard |
amazon-cloudwatch-agent |
— |
| amazon-cloudwatch-agent-fips |
affected |
chainguard |
amazon-cloudwatch-agent-fips |
— |
| amazon-ecs-agent |
affected |
chainguard |
amazon-ecs-agent |
— |
| amazon-ecs-agent-fips |
affected |
chainguard |
amazon-ecs-agent-fips |
— |
| apply-cve-bump |
affected |
chainguard |
apply-cve-bump |
— |
| argo-cd-3.0 |
affected |
chainguard |
argo-cd-3.0 |
— |
| argo-cd-3.1 |
affected |
chainguard |
argo-cd-3.1 |
— |
| argo-cd-3.2 |
affected |
wolfi |
argo-cd-3.2 |
— |
| argo-cd-3.2 |
affected |
chainguard |
argo-cd-3.2 |
— |
| argo-cd-3.3 |
affected |
chainguard |
argo-cd-3.3 |
— |
| argo-cd-3.3 |
affected |
wolfi |
argo-cd-3.3 |
— |
| argo-cd-fips-3.0 |
affected |
chainguard |
argo-cd-fips-3.0 |
— |
| argo-cd-fips-3.1 |
affected |
chainguard |
argo-cd-fips-3.1 |
— |
| argo-cd-fips-3.2 |
affected |
chainguard |
argo-cd-fips-3.2 |
— |
| argo-cd-fips-3.3 |
affected |
chainguard |
argo-cd-fips-3.3 |
— |
| argo-events |
affected |
chainguard |
argo-events |
— |
| argo-events |
affected |
wolfi |
argo-events |
— |
| argo-events-fips |
affected |
chainguard |
argo-events-fips |
— |
| argo-rollouts |
affected |
wolfi |
argo-rollouts |
— |
| argo-rollouts |
affected |
chainguard |
argo-rollouts |
— |
| argo-rollouts-fips |
affected |
chainguard |
argo-rollouts-fips |
— |
| atlas-1.0 |
affected |
chainguard |
atlas-1.0 |
— |
| atlas-1.0-fips |
affected |
chainguard |
atlas-1.0-fips |
— |
| atlas-1.1 |
affected |
chainguard |
atlas-1.1 |
— |
| atlas-1.1-fips |
affected |
chainguard |
atlas-1.1-fips |
— |
| atlas-1.2 |
affected |
chainguard |
atlas-1.2 |
— |
| aws/aws-sdk-go |
affected |
github.com |
github.com/aws/aws-sdk-go |
— |
| aws-flb-cloudwatch |
affected |
wolfi |
aws-flb-cloudwatch |
— |
| aws-flb-cloudwatch |
affected |
chainguard |
aws-flb-cloudwatch |
— |
| aws-flb-cloudwatch-fips |
affected |
chainguard |
aws-flb-cloudwatch-fips |
— |
| aws-flb-firehose |
affected |
chainguard |
aws-flb-firehose |
— |
| aws-flb-firehose |
affected |
wolfi |
aws-flb-firehose |
— |
| aws-flb-firehose-fips |
affected |
chainguard |
aws-flb-firehose-fips |
— |
| aws-flb-kinesis |
affected |
wolfi |
aws-flb-kinesis |
— |
| aws-flb-kinesis |
affected |
chainguard |
aws-flb-kinesis |
— |
| aws-flb-kinesis-fips |
affected |
chainguard |
aws-flb-kinesis-fips |
— |
| aws-node-termination-handler |
affected |
wolfi |
aws-node-termination-handler |
— |
| aws-node-termination-handler |
affected |
chainguard |
aws-node-termination-handler |
— |
| aws-node-termination-handler-fips |
affected |
chainguard |
aws-node-termination-handler-fips |
— |
| aws-nuke |
affected |
wolfi |
aws-nuke |
— |
| aws-nuke |
affected |
chainguard |
aws-nuke |
— |
| aws-nuke-fips |
affected |
chainguard |
aws-nuke-fips |
— |
| aws-otel-collector |
affected |
chainguard |
aws-otel-collector |
— |
| aws-otel-collector |
affected |
wolfi |
aws-otel-collector |
— |
| aws-otel-collector-fips |
affected |
chainguard |
aws-otel-collector-fips |
— |
| aws-s3-controller |
affected |
wolfi |
aws-s3-controller |
— |
| aws-s3-controller |
affected |
chainguard |
aws-s3-controller |
— |
| aws-sigv4-proxy |
affected |
chainguard |
aws-sigv4-proxy |
— |
| aws-sigv4-proxy |
affected |
wolfi |
aws-sigv4-proxy |
— |
| aws-sigv4-proxy-fips |
affected |
chainguard |
aws-sigv4-proxy-fips |
— |
| bank-vaults |
affected |
wolfi |
bank-vaults |
— |
| bank-vaults |
affected |
chainguard |
bank-vaults |
— |
| bank-vaults-fips |
affected |
chainguard |
bank-vaults-fips |
— |
| bank-vaults-vault-operator |
affected |
chainguard |
bank-vaults-vault-operator |
— |
| bank-vaults-vault-operator-fips |
affected |
chainguard |
bank-vaults-vault-operator-fips |
— |
| cadence |
affected |
chainguard |
cadence |
— |
| cadence-fips |
affected |
chainguard |
cadence-fips |
— |
| cephcsi |
affected |
chainguard |
cephcsi |
— |
| cephcsi-fips |
affected |
chainguard |
cephcsi-fips |
— |
| cert-exporter |
affected |
wolfi |
cert-exporter |
— |
| cert-exporter |
affected |
chainguard |
cert-exporter |
— |
| cert-exporter-fips |
affected |
chainguard |
cert-exporter-fips |
— |
| certificate-transparency |
affected |
chainguard |
certificate-transparency |
— |
| certificate-transparency |
affected |
wolfi |
certificate-transparency |
— |
| certificate-transparency-fips |
affected |
chainguard |
certificate-transparency-fips |
— |
| cg |
affected |
chainguard |
cg |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| chartmuseum-fips |
affected |
chainguard |
chartmuseum-fips |
— |
| cloudbeat-9.0 |
affected |
chainguard |
cloudbeat-9.0 |
— |
| cloudbeat-fips-8.17 |
affected |
chainguard |
cloudbeat-fips-8.17 |
— |
| cloudbeat-fips-9.0 |
affected |
chainguard |
cloudbeat-fips-9.0 |
— |
| cloud-sql-proxy-2.16 |
affected |
wolfi |
cloud-sql-proxy-2.16 |
— |
| cloud-sql-proxy-2.16 |
affected |
chainguard |
cloud-sql-proxy-2.16 |
— |
| cloud-sql-proxy-2.17 |
affected |
chainguard |
cloud-sql-proxy-2.17 |
— |
| cloud-sql-proxy-2.18 |
affected |
chainguard |
cloud-sql-proxy-2.18 |
— |
| cloud-sql-proxy-2.21 |
affected |
wolfi |
cloud-sql-proxy-2.21 |
— |
| cloud-sql-proxy-2.21 |
affected |
chainguard |
cloud-sql-proxy-2.21 |
— |
| cloud-sql-proxy-2.22 |
affected |
wolfi |
cloud-sql-proxy-2.22 |
— |
| cloud-sql-proxy-2.22 |
affected |
chainguard |
cloud-sql-proxy-2.22 |
— |
| cloud-sql-proxy-fips |
affected |
chainguard |
cloud-sql-proxy-fips |
— |
| cluster-autoscaler-1.32 |
affected |
chainguard |
cluster-autoscaler-1.32 |
— |
| cluster-autoscaler-1.33 |
affected |
chainguard |
cluster-autoscaler-1.33 |
— |
| cluster-autoscaler-1.34 |
affected |
wolfi |
cluster-autoscaler-1.34 |
— |
| cluster-autoscaler-1.34 |
affected |
chainguard |
cluster-autoscaler-1.34 |
— |
| cluster-autoscaler-fips-1.32 |
affected |
chainguard |
cluster-autoscaler-fips-1.32 |
— |
| cluster-autoscaler-fips-1.33 |
affected |
chainguard |
cluster-autoscaler-fips-1.33 |
— |
| cluster-autoscaler-fips-1.34 |
affected |
chainguard |
cluster-autoscaler-fips-1.34 |
— |
| commercial-grafana-11.6 |
affected |
chainguard |
commercial-grafana-11.6 |
— |
| commercial-grafana-12.1 |
affected |
chainguard |
commercial-grafana-12.1 |
— |
| commercial-grafana-12.2 |
affected |
chainguard |
commercial-grafana-12.2 |
— |
| commercial-grafana-12.3 |
affected |
chainguard |
commercial-grafana-12.3 |
— |
| commercial-grafana-12.4 |
affected |
chainguard |
commercial-grafana-12.4 |
— |
| commercial-grafana-13.0 |
affected |
chainguard |
commercial-grafana-13.0 |
— |
| consul-1.18 |
affected |
chainguard |
consul-1.18 |
— |
| consul-1.19 |
affected |
chainguard |
consul-1.19 |
— |
| consul-1.20 |
affected |
chainguard |
consul-1.20 |
— |
| consul-1.21 |
affected |
chainguard |
consul-1.21 |
— |
| consul-fips-1.20 |
affected |
chainguard |
consul-fips-1.20 |
— |
| consul-fips-1.21 |
affected |
chainguard |
consul-fips-1.21 |
— |
| consul-k8s-1.1 |
affected |
chainguard |
consul-k8s-1.1 |
— |
| consul-k8s-1.3 |
affected |
chainguard |
consul-k8s-1.3 |
— |
| consul-k8s-1.4 |
affected |
chainguard |
consul-k8s-1.4 |
— |
| consul-k8s-1.5 |
affected |
chainguard |
consul-k8s-1.5 |
— |
| consul-k8s-1.6 |
affected |
chainguard |
consul-k8s-1.6 |
— |
| consul-k8s-fips-1.1 |
affected |
chainguard |
consul-k8s-fips-1.1 |
— |
| consul-k8s-fips-1.3 |
affected |
chainguard |
consul-k8s-fips-1.3 |
— |
| consul-k8s-fips-1.4 |
affected |
chainguard |
consul-k8s-fips-1.4 |
— |
| consul-k8s-fips-1.5 |
affected |
chainguard |
consul-k8s-fips-1.5 |
— |
| consul-k8s-fips-1.6 |
affected |
chainguard |
consul-k8s-fips-1.6 |
— |
| crossplane-aws-provider |
affected |
chainguard |
crossplane-aws-provider |
— |
| crossplane-aws-provider-fips |
affected |
chainguard |
crossplane-aws-provider-fips |
— |
| dapr-1.14 |
affected |
chainguard |
dapr-1.14 |
— |
| dapr-1.15 |
affected |
chainguard |
dapr-1.15 |
— |
| dapr-1.16 |
affected |
chainguard |
dapr-1.16 |
— |
| dapr-1.16 |
affected |
wolfi |
dapr-1.16 |
— |
| dapr-fips-1.14 |
affected |
chainguard |
dapr-fips-1.14 |
— |
| dapr-fips-1.15 |
affected |
chainguard |
dapr-fips-1.15 |
— |
| dapr-fips-1.16 |
affected |
chainguard |
dapr-fips-1.16 |
— |
| datadog-agent-7.71 |
affected |
chainguard |
datadog-agent-7.71 |
— |
| datadog-agent-7.77 |
affected |
wolfi |
datadog-agent-7.77 |
— |
| datadog-agent-7.77 |
affected |
chainguard |
datadog-agent-7.77 |
— |
| datadog-agent-7.78 |
affected |
chainguard |
datadog-agent-7.78 |
— |
| datadog-agent-7.78 |
affected |
wolfi |
datadog-agent-7.78 |
— |
| datadog-agent-7.79 |
affected |
wolfi |
datadog-agent-7.79 |
— |
| datadog-agent-7.79 |
affected |
chainguard |
datadog-agent-7.79 |
— |
| datadog-agent-fips-7.71 |
affected |
chainguard |
datadog-agent-fips-7.71 |
— |
| datadog-agent-fips-7.77 |
affected |
chainguard |
datadog-agent-fips-7.77 |
— |
| datadog-agent-fips-7.78 |
affected |
chainguard |
datadog-agent-fips-7.78 |
— |
| datadog-agent-fips-7.79 |
affected |
chainguard |
datadog-agent-fips-7.79 |
— |
| distribution |
affected |
chainguard |
distribution |
— |
| distribution |
affected |
wolfi |
distribution |
— |
| distribution-fips |
affected |
chainguard |
distribution-fips |
— |
| drone |
affected |
chainguard |
drone |
— |
| drone-fips |
affected |
chainguard |
drone-fips |
— |
| elastic-agent-8.19 |
affected |
chainguard |
elastic-agent-8.19 |
— |
| elastic-agent-9.1 |
affected |
chainguard |
elastic-agent-9.1 |
— |
| elastic-agent-9.2 |
affected |
chainguard |
elastic-agent-9.2 |
— |
| elastic-agent-9.3 |
affected |
chainguard |
elastic-agent-9.3 |
— |
| elastic-agent-9.4 |
affected |
chainguard |
elastic-agent-9.4 |
— |
| elastic-agent-fips-8.19 |
affected |
chainguard |
elastic-agent-fips-8.19 |
— |
| elastic-agent-fips-9.1 |
affected |
chainguard |
elastic-agent-fips-9.1 |
— |
| elastic-agent-fips-9.2 |
affected |
chainguard |
elastic-agent-fips-9.2 |
— |
| elastic-agent-fips-9.3 |
affected |
chainguard |
elastic-agent-fips-9.3 |
— |
| elastic-agent-fips-9.4 |
affected |
chainguard |
elastic-agent-fips-9.4 |
— |
| external-secrets-fips |
affected |
chainguard |
external-secrets-fips |
— |
| external-secrets-operator-1.2 |
affected |
chainguard |
external-secrets-operator-1.2 |
— |
| external-secrets-operator-1.3 |
affected |
chainguard |
external-secrets-operator-1.3 |
— |
| external-secrets-operator-2.0 |
affected |
chainguard |
external-secrets-operator-2.0 |
— |
| external-secrets-operator-2.0 |
affected |
wolfi |
external-secrets-operator-2.0 |
— |
| external-secrets-operator-2.1 |
affected |
chainguard |
external-secrets-operator-2.1 |
— |
| external-secrets-operator-2.1 |
affected |
wolfi |
external-secrets-operator-2.1 |
— |
| external-secrets-operator-2.2 |
affected |
wolfi |
external-secrets-operator-2.2 |
— |
| external-secrets-operator-2.2 |
affected |
chainguard |
external-secrets-operator-2.2 |
— |
| external-secrets-operator-2.3 |
affected |
wolfi |
external-secrets-operator-2.3 |
— |
| external-secrets-operator-2.3 |
affected |
chainguard |
external-secrets-operator-2.3 |
— |
| external-secrets-operator-2.4 |
affected |
wolfi |
external-secrets-operator-2.4 |
— |
| external-secrets-operator-2.4 |
affected |
chainguard |
external-secrets-operator-2.4 |
— |
| external-secrets-operator-2.5 |
affected |
wolfi |
external-secrets-operator-2.5 |
— |
| external-secrets-operator-2.5 |
affected |
chainguard |
external-secrets-operator-2.5 |
— |
| external-secrets-operator-2.6 |
affected |
chainguard |
external-secrets-operator-2.6 |
— |
| external-secrets-operator-2.6 |
affected |
wolfi |
external-secrets-operator-2.6 |
— |
| external-secrets-operator-2.7 |
affected |
chainguard |
external-secrets-operator-2.7 |
— |
| external-secrets-operator-fips-1.2 |
affected |
chainguard |
external-secrets-operator-fips-1.2 |
— |
| external-secrets-operator-fips-1.3 |
affected |
chainguard |
external-secrets-operator-fips-1.3 |
— |
| external-secrets-operator-fips-2.0 |
affected |
chainguard |
external-secrets-operator-fips-2.0 |
— |
| external-secrets-operator-fips-2.1 |
affected |
chainguard |
external-secrets-operator-fips-2.1 |
— |
| external-secrets-operator-fips-2.2 |
affected |
chainguard |
external-secrets-operator-fips-2.2 |
— |
| external-secrets-operator-fips-2.3 |
affected |
chainguard |
external-secrets-operator-fips-2.3 |
— |
| external-secrets-operator-fips-2.4 |
affected |
chainguard |
external-secrets-operator-fips-2.4 |
— |
| external-secrets-operator-fips-2.5 |
affected |
chainguard |
external-secrets-operator-fips-2.5 |
— |
| external-secrets-operator-fips-2.6 |
affected |
chainguard |
external-secrets-operator-fips-2.6 |
— |
| external-secrets-operator-fips-2.7 |
affected |
chainguard |
external-secrets-operator-fips-2.7 |
— |
| flagger |
affected |
chainguard |
flagger |
— |
| flagger-fips |
affected |
chainguard |
flagger-fips |
— |
| flyte |
affected |
wolfi |
flyte |
— |
| flyte |
affected |
chainguard |
flyte |
— |
| gatekeeper-3.20 |
affected |
chainguard |
gatekeeper-3.20 |
— |
| gatekeeper-3.21 |
affected |
chainguard |
gatekeeper-3.21 |
— |
| gatekeeper-3.21 |
affected |
wolfi |
gatekeeper-3.21 |
— |
| gatekeeper-3.22 |
affected |
wolfi |
gatekeeper-3.22 |
— |
| gatekeeper-3.22 |
affected |
chainguard |
gatekeeper-3.22 |
— |
| gatekeeper-fips-3.20 |
affected |
chainguard |
gatekeeper-fips-3.20 |
— |
| gatekeeper-fips-3.21 |
affected |
chainguard |
gatekeeper-fips-3.21 |
— |
| gatekeeper-fips-3.22 |
affected |
chainguard |
gatekeeper-fips-3.22 |
— |
| gitlab-cng-18.10 |
affected |
chainguard |
gitlab-cng-18.10 |
— |
| gitlab-cng-18.11 |
affected |
chainguard |
gitlab-cng-18.11 |
— |
| gitlab-cng-19.0 |
affected |
chainguard |
gitlab-cng-19.0 |
— |
| gitlab-cng-19.1 |
affected |
chainguard |
gitlab-cng-19.1 |
— |
| gitlab-cng-fips-18.10 |
affected |
chainguard |
gitlab-cng-fips-18.10 |
— |
| gitlab-cng-fips-18.11 |
affected |
chainguard |
gitlab-cng-fips-18.11 |
— |
| gitlab-cng-fips-19.0 |
affected |
chainguard |
gitlab-cng-fips-19.0 |
— |
| gitlab-cng-fips-19.1 |
affected |
chainguard |
gitlab-cng-fips-19.1 |
— |
| gitlab-runner-18.10 |
affected |
chainguard |
gitlab-runner-18.10 |
— |
| gitlab-runner-18.10 |
affected |
wolfi |
gitlab-runner-18.10 |
— |
| gitlab-runner-18.11 |
affected |
chainguard |
gitlab-runner-18.11 |
— |
| gitlab-runner-18.11 |
affected |
wolfi |
gitlab-runner-18.11 |
— |
| gitlab-runner-19.0 |
affected |
chainguard |
gitlab-runner-19.0 |
— |
| gitlab-runner-19.0 |
affected |
wolfi |
gitlab-runner-19.0 |
— |
| gitlab-runner-19.1 |
affected |
chainguard |
gitlab-runner-19.1 |
— |
| gitlab-runner-19.1 |
affected |
wolfi |
gitlab-runner-19.1 |
— |
| gitlab-runner-fips-18.10 |
affected |
chainguard |
gitlab-runner-fips-18.10 |
— |
| gitlab-runner-fips-18.11 |
affected |
chainguard |
gitlab-runner-fips-18.11 |
— |
| gitlab-runner-fips-19.0 |
affected |
chainguard |
gitlab-runner-fips-19.0 |
— |
| gitlab-runner-fips-19.1 |
affected |
chainguard |
gitlab-runner-fips-19.1 |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gitsign |
affected |
chainguard |
gitsign |
— |
| gitsign |
affected |
wolfi |
gitsign |
— |
| go-getter-2 |
affected |
chainguard |
go-getter-2 |
— |
| go-getter-2.1 |
affected |
chainguard |
go-getter-2.1 |
— |
| go-getter-2.2 |
affected |
chainguard |
go-getter-2.2 |
— |
| go-getter-2-fips |
affected |
chainguard |
go-getter-2-fips |
— |
| gomplate-4 |
affected |
chainguard |
gomplate-4 |
— |
| gomplate-5 |
affected |
wolfi |
gomplate-5 |
— |
| gomplate-5 |
affected |
chainguard |
gomplate-5 |
— |
| gomplate-fips-4 |
affected |
chainguard |
gomplate-fips-4 |
— |
| gomplate-fips-5 |
affected |
chainguard |
gomplate-fips-5 |
— |
| google-cloud-otel-ops-collector |
affected |
chainguard |
google-cloud-otel-ops-collector |
— |
| gostatsd |
affected |
chainguard |
gostatsd |
— |
| gostatsd |
affected |
wolfi |
gostatsd |
— |
| grafana-11.6 |
affected |
chainguard |
grafana-11.6 |
— |
| grafana-12.0 |
affected |
chainguard |
grafana-12.0 |
— |
| grafana-12.1 |
affected |
chainguard |
grafana-12.1 |
— |
| grafana-12.2 |
affected |
chainguard |
grafana-12.2 |
— |
| grafana-12.3 |
affected |
chainguard |
grafana-12.3 |
— |
| grafana-12.3 |
affected |
wolfi |
grafana-12.3 |
— |
| grafana-12.4 |
affected |
chainguard |
grafana-12.4 |
— |
| grafana-12.4 |
affected |
wolfi |
grafana-12.4 |
— |
| grafana-13.0 |
affected |
chainguard |
grafana-13.0 |
— |
| grafana-13.0 |
affected |
wolfi |
grafana-13.0 |
— |
| grafana-13.1 |
affected |
chainguard |
grafana-13.1 |
— |
| grafana-agent-operator |
affected |
chainguard |
grafana-agent-operator |
— |
| grafana-agent-operator |
affected |
wolfi |
grafana-agent-operator |
— |
| grafana-fips-11.6 |
affected |
chainguard |
grafana-fips-11.6 |
— |
| grafana-fips-12.0 |
affected |
chainguard |
grafana-fips-12.0 |
— |
| grafana-fips-12.1 |
affected |
chainguard |
grafana-fips-12.1 |
— |
| grafana-fips-12.2 |
affected |
chainguard |
grafana-fips-12.2 |
— |
| grafana-fips-12.3 |
affected |
chainguard |
grafana-fips-12.3 |
— |
| grafana-fips-12.4 |
affected |
chainguard |
grafana-fips-12.4 |
— |
| grafana-fips-13.0 |
affected |
chainguard |
grafana-fips-13.0 |
— |
| grafana-fips-13.1 |
affected |
chainguard |
grafana-fips-13.1 |
— |
| grafana-mimir-2.17 |
affected |
chainguard |
grafana-mimir-2.17 |
— |
| grafana-mimir-3.0 |
affected |
wolfi |
grafana-mimir-3.0 |
— |
| grafana-mimir-3.0 |
affected |
chainguard |
grafana-mimir-3.0 |
— |
| grafana-mimir-fips-2.17 |
affected |
chainguard |
grafana-mimir-fips-2.17 |
— |
| grafana-mimir-fips-3.0 |
affected |
chainguard |
grafana-mimir-fips-3.0 |
— |
| grafana-pyroscope-1.12 |
affected |
chainguard |
grafana-pyroscope-1.12 |
— |
| grafana-pyroscope-1.13 |
affected |
chainguard |
grafana-pyroscope-1.13 |
— |
| grafana-pyroscope-1.14 |
affected |
chainguard |
grafana-pyroscope-1.14 |
— |
| grept |
affected |
chainguard |
grept |
— |
| grept-fips |
affected |
chainguard |
grept-fips |
— |
| guac |
affected |
chainguard |
guac |
— |
| guac |
affected |
wolfi |
guac |
— |
| harbor-2.12 |
affected |
chainguard |
harbor-2.12 |
— |
| harbor-2.13 |
affected |
chainguard |
harbor-2.13 |
— |
| harbor-2.14 |
affected |
wolfi |
harbor-2.14 |
— |
| harbor-2.14 |
affected |
chainguard |
harbor-2.14 |
— |
| harbor-2.15 |
affected |
chainguard |
harbor-2.15 |
— |
| harbor-fips-2.12 |
affected |
chainguard |
harbor-fips-2.12 |
— |
| harbor-fips-2.13 |
affected |
chainguard |
harbor-fips-2.13 |
— |
| harbor-fips-2.14 |
affected |
chainguard |
harbor-fips-2.14 |
— |
| harbor-fips-2.15 |
affected |
chainguard |
harbor-fips-2.15 |
— |
| harbor-registry |
affected |
wolfi |
harbor-registry |
— |
| harbor-registry |
affected |
chainguard |
harbor-registry |
— |
| harbor-registry-fips |
affected |
chainguard |
harbor-registry-fips |
— |
| harvester |
affected |
chainguard |
harvester |
— |
| harvester-fips |
affected |
chainguard |
harvester-fips |
— |
| influxd-2.7 |
affected |
chainguard |
influxd-2.7 |
— |
| juicefs-1.2 |
affected |
chainguard |
juicefs-1.2 |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k8s-image-swapper |
affected |
chainguard |
k8s-image-swapper |
— |
| k8s-image-swapper-fips |
affected |
chainguard |
k8s-image-swapper-fips |
— |
| karpenter-0.33 |
affected |
chainguard |
karpenter-0.33 |
— |
| karpenter-0.34 |
affected |
chainguard |
karpenter-0.34 |
— |
| karpenter-0.35 |
affected |
chainguard |
karpenter-0.35 |
— |
| karpenter-0.36 |
affected |
chainguard |
karpenter-0.36 |
— |
| karpenter-0.37 |
affected |
chainguard |
karpenter-0.37 |
— |
| karpenter-fips-0.33 |
affected |
chainguard |
karpenter-fips-0.33 |
— |
| karpenter-fips-0.34 |
affected |
chainguard |
karpenter-fips-0.34 |
— |
| karpenter-fips-0.35 |
affected |
chainguard |
karpenter-fips-0.35 |
— |
| karpenter-fips-0.36 |
affected |
chainguard |
karpenter-fips-0.36 |
— |
| karpenter-fips-0.37 |
affected |
chainguard |
karpenter-fips-0.37 |
— |
| kiam |
affected |
chainguard |
kiam |
— |
| kots |
affected |
wolfi |
kots |
— |
| kots |
affected |
chainguard |
kots |
— |
| kserve |
affected |
wolfi |
kserve |
— |
| kserve |
affected |
chainguard |
kserve |
— |
| kserve-fips |
affected |
chainguard |
kserve-fips |
— |
| kserve-localmodelnode-agent |
affected |
chainguard |
kserve-localmodelnode-agent |
— |
| kserve-localmodelnode-agent-fips |
affected |
chainguard |
kserve-localmodelnode-agent-fips |
— |
| kserve-modelmesh-serving |
affected |
wolfi |
kserve-modelmesh-serving |
— |
| kserve-modelmesh-serving |
affected |
chainguard |
kserve-modelmesh-serving |
— |
| kube-arangodb-1.3 |
affected |
chainguard |
kube-arangodb-1.3 |
— |
| kube-arangodb-1.4 |
affected |
chainguard |
kube-arangodb-1.4 |
— |
| kube-arangodb-1.4 |
affected |
wolfi |
kube-arangodb-1.4 |
— |
| kube-arangodb-fips-1.3 |
affected |
chainguard |
kube-arangodb-fips-1.3 |
— |
| kube-arangodb-fips-1.4 |
affected |
chainguard |
kube-arangodb-fips-1.4 |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubeflow-pipelines-driver-fips |
affected |
chainguard |
kubeflow-pipelines-driver-fips |
— |
| kubeflow-pipelines-fips |
affected |
chainguard |
kubeflow-pipelines-fips |
— |
| kubernetes-event-exporter |
affected |
chainguard |
kubernetes-event-exporter |
— |
| kubernetes-event-exporter |
affected |
wolfi |
kubernetes-event-exporter |
— |
| kubernetes-event-exporter-fips |
affected |
chainguard |
kubernetes-event-exporter-fips |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubescape-operator |
affected |
chainguard |
kubescape-operator |
— |
| kubescape-operator |
affected |
wolfi |
kubescape-operator |
— |
| kubescape-operator-fips |
affected |
chainguard |
kubescape-operator-fips |
— |
| kubescape-server |
affected |
chainguard |
kubescape-server |
— |
| kubescape-server-fips |
affected |
chainguard |
kubescape-server-fips |
— |
| kubevirt-cdi-uploadserver-1.5 |
affected |
chainguard |
kubevirt-cdi-uploadserver-1.5 |
— |
| kubevirt-cdi-uploadserver-1.6 |
affected |
chainguard |
kubevirt-cdi-uploadserver-1.6 |
— |
| kubevirt-cdi-uploadserver-fips-1.5 |
affected |
chainguard |
kubevirt-cdi-uploadserver-fips-1.5 |
— |
| kubevirt-cdi-uploadserver-fips-1.6 |
affected |
chainguard |
kubevirt-cdi-uploadserver-fips-1.6 |
— |
| loki-2.9 |
affected |
chainguard |
loki-2.9 |
— |
| loki-3.4 |
affected |
chainguard |
loki-3.4 |
— |
| loki-3.5 |
affected |
chainguard |
loki-3.5 |
— |
| loki-3.6 |
affected |
wolfi |
loki-3.6 |
— |
| loki-3.6 |
affected |
chainguard |
loki-3.6 |
— |
| loki-3.7 |
affected |
chainguard |
loki-3.7 |
— |
| loki-3.7 |
affected |
wolfi |
loki-3.7 |
— |
| loki-fips-2.9 |
affected |
chainguard |
loki-fips-2.9 |
— |
| loki-fips-3.4 |
affected |
chainguard |
loki-fips-3.4 |
— |
| loki-fips-3.5 |
affected |
chainguard |
loki-fips-3.5 |
— |
| loki-fips-3.6 |
affected |
chainguard |
loki-fips-3.6 |
— |
| loki-fips-3.7 |
affected |
chainguard |
loki-fips-3.7 |
— |
| longhorn-backing-image-manager-1.8 |
affected |
chainguard |
longhorn-backing-image-manager-1.8 |
— |
| longhorn-backing-image-manager-1.9 |
affected |
chainguard |
longhorn-backing-image-manager-1.9 |
— |
| longhorn-backing-image-manager-fips-1.8 |
affected |
chainguard |
longhorn-backing-image-manager-fips-1.8 |
— |
| longhorn-backing-image-manager-fips-1.9 |
affected |
chainguard |
longhorn-backing-image-manager-fips-1.9 |
— |
| longhorn-engine-1.8 |
affected |
chainguard |
longhorn-engine-1.8 |
— |
| longhorn-engine-1.9 |
affected |
chainguard |
longhorn-engine-1.9 |
— |
| longhorn-instance-manager-1.8 |
affected |
chainguard |
longhorn-instance-manager-1.8 |
— |
| longhorn-instance-manager-1.8-fips |
affected |
chainguard |
longhorn-instance-manager-1.8-fips |
— |
| longhorn-instance-manager-1.9 |
affected |
chainguard |
longhorn-instance-manager-1.9 |
— |
| longhorn-instance-manager-1.9-fips |
affected |
chainguard |
longhorn-instance-manager-1.9-fips |
— |
| mapotf |
affected |
chainguard |
mapotf |
— |
| mapotf-fips |
affected |
chainguard |
mapotf-fips |
— |
| mattermost-10.11 |
affected |
chainguard |
mattermost-10.11 |
— |
| mattermost-11.1 |
affected |
chainguard |
mattermost-11.1 |
— |
| mattermost-11.1 |
affected |
wolfi |
mattermost-11.1 |
— |
| mattermost-11.2 |
affected |
chainguard |
mattermost-11.2 |
— |
| mattermost-fips-10.11 |
affected |
chainguard |
mattermost-fips-10.11 |
— |
| mattermost-fips-11.1 |
affected |
chainguard |
mattermost-fips-11.1 |
— |
| mattermost-fips-11.2 |
affected |
chainguard |
mattermost-fips-11.2 |
— |
| metrics-agent |
affected |
wolfi |
metrics-agent |
— |
| metrics-agent |
affected |
chainguard |
metrics-agent |
— |
| metrics-agent-fips |
affected |
chainguard |
metrics-agent-fips |
— |
| monstache |
affected |
chainguard |
monstache |
— |
| neuvector |
affected |
chainguard |
neuvector |
— |
| neuvector-fips |
affected |
chainguard |
neuvector-fips |
— |
| neuvector-scanner |
affected |
wolfi |
neuvector-scanner |
— |
| neuvector-scanner |
affected |
chainguard |
neuvector-scanner |
— |
| neuvector-scanner-fips |
affected |
chainguard |
neuvector-scanner-fips |
— |
| newrelic-nri-statsd |
affected |
chainguard |
newrelic-nri-statsd |
— |
| newrelic-nri-statsd |
affected |
wolfi |
newrelic-nri-statsd |
— |
| node-problem-detector-0.8 |
affected |
chainguard |
node-problem-detector-0.8 |
— |
| node-problem-detector-1.34 |
affected |
chainguard |
node-problem-detector-1.34 |
— |
| node-problem-detector-1.35 |
affected |
wolfi |
node-problem-detector-1.35 |
— |
| node-problem-detector-1.35 |
affected |
chainguard |
node-problem-detector-1.35 |
— |
| node-problem-detector-fips-0.8 |
affected |
chainguard |
node-problem-detector-fips-0.8 |
— |
| node-problem-detector-fips-1.34 |
affected |
chainguard |
node-problem-detector-fips-1.34 |
— |
| node-problem-detector-fips-1.35 |
affected |
chainguard |
node-problem-detector-fips-1.35 |
— |
| nrdot-collector |
affected |
chainguard |
nrdot-collector |
— |
| nrdot-collector-fips |
affected |
chainguard |
nrdot-collector-fips |
— |
| nrdot-collector-k8s |
affected |
chainguard |
nrdot-collector-k8s |
— |
| nrdot-collector-k8s-fips |
affected |
chainguard |
nrdot-collector-k8s-fips |
— |
| openbao |
affected |
chainguard |
openbao |
— |
| openbao |
affected |
wolfi |
openbao |
— |
| openbao-fips |
affected |
chainguard |
openbao-fips |
— |
| opencost |
affected |
wolfi |
opencost |
— |
| opencost |
affected |
chainguard |
opencost |
— |
| opencost-fips |
affected |
chainguard |
opencost-fips |
— |
| opentelemetry-collector |
affected |
wolfi |
opentelemetry-collector |
— |
| opentelemetry-collector |
affected |
chainguard |
opentelemetry-collector |
— |
| opentelemetry-collector-contrib |
affected |
chainguard |
opentelemetry-collector-contrib |
— |
| opentelemetry-collector-contrib |
affected |
wolfi |
opentelemetry-collector-contrib |
— |
| opentelemetry-collector-contrib-fips |
affected |
chainguard |
opentelemetry-collector-contrib-fips |
— |
| opentelemetry-collector-fips |
affected |
chainguard |
opentelemetry-collector-fips |
— |
| opentelemetry-collector-k8s |
affected |
chainguard |
opentelemetry-collector-k8s |
— |
| opentelemetry-collector-k8s-fips |
affected |
chainguard |
opentelemetry-collector-k8s-fips |
— |
| opentofu-1.9 |
affected |
wolfi |
opentofu-1.9 |
— |
| opentofu-1.9 |
affected |
chainguard |
opentofu-1.9 |
— |
| opentofu-fips-1.9 |
affected |
chainguard |
opentofu-fips-1.9 |
— |
| packer |
affected |
chainguard |
packer |
— |
| packer-fips |
affected |
chainguard |
packer-fips |
— |
| plutono |
affected |
chainguard |
plutono |
— |
| plutono-fips |
affected |
chainguard |
plutono-fips |
— |
| porch |
affected |
chainguard |
porch |
— |
| porch-fips |
affected |
chainguard |
porch-fips |
— |
| postgres-operator |
affected |
wolfi |
postgres-operator |
— |
| postgres-operator |
affected |
chainguard |
postgres-operator |
— |
| postgres-operator-fips |
affected |
chainguard |
postgres-operator-fips |
— |
| prometheus-2.51 |
affected |
chainguard |
prometheus-2.51 |
— |
| prometheus-3.12 |
affected |
chainguard |
prometheus-3.12 |
— |
| prometheus-3.12 |
affected |
wolfi |
prometheus-3.12 |
— |
| prometheus-3.5 |
affected |
chainguard |
prometheus-3.5 |
— |
| prometheus-fips-3.12 |
affected |
chainguard |
prometheus-fips-3.12 |
— |
| prometheus-fips-3.5 |
affected |
chainguard |
prometheus-fips-3.5 |
— |
| promxy |
affected |
wolfi |
promxy |
— |
| promxy |
affected |
chainguard |
promxy |
— |
| promxy-fips |
affected |
chainguard |
promxy-fips |
— |
| rancher-2.10 |
affected |
chainguard |
rancher-2.10 |
— |
| rancher-2.11 |
affected |
chainguard |
rancher-2.11 |
— |
| rancher-2.12 |
affected |
chainguard |
rancher-2.12 |
— |
| rancher-2.13 |
affected |
wolfi |
rancher-2.13 |
— |
| rancher-2.13 |
affected |
chainguard |
rancher-2.13 |
— |
| rancher-2.14 |
affected |
wolfi |
rancher-2.14 |
— |
| rancher-2.14 |
affected |
chainguard |
rancher-2.14 |
— |
| rancher-agent-2.10 |
affected |
chainguard |
rancher-agent-2.10 |
— |
| rancher-agent-2.11 |
affected |
chainguard |
rancher-agent-2.11 |
— |
| rancher-agent-2.12 |
affected |
chainguard |
rancher-agent-2.12 |
— |
| rancher-agent-2.13 |
affected |
wolfi |
rancher-agent-2.13 |
— |
| rancher-agent-2.13 |
affected |
chainguard |
rancher-agent-2.13 |
— |
| rancher-agent-2.14 |
affected |
wolfi |
rancher-agent-2.14 |
— |
| rancher-agent-2.14 |
affected |
chainguard |
rancher-agent-2.14 |
— |
| rancher-agent-2.9 |
affected |
chainguard |
rancher-agent-2.9 |
— |
| rancher-machine |
affected |
wolfi |
rancher-machine |
— |
| rancher-machine |
affected |
chainguard |
rancher-machine |
— |
| redpanda-25.1 |
affected |
chainguard |
redpanda-25.1 |
— |
| redpanda-25.2 |
affected |
chainguard |
redpanda-25.2 |
— |
| redpanda-25.3 |
affected |
chainguard |
redpanda-25.3 |
— |
| rook-1.18 |
affected |
chainguard |
rook-1.18 |
— |
| rook-1.19 |
affected |
wolfi |
rook-1.19 |
— |
| rook-1.19 |
affected |
chainguard |
rook-1.19 |
— |
| rook-fips-1.18 |
affected |
chainguard |
rook-fips-1.18 |
— |
| rook-fips-1.19 |
affected |
chainguard |
rook-fips-1.19 |
— |
| s5cmd |
affected |
wolfi |
s5cmd |
— |
| s5cmd |
affected |
chainguard |
s5cmd |
— |
| s5cmd-fips |
affected |
chainguard |
s5cmd-fips |
— |
| seaweedfs |
affected |
wolfi |
seaweedfs |
— |
| seaweedfs |
affected |
chainguard |
seaweedfs |
— |
| seaweedfs-fips |
affected |
chainguard |
seaweedfs-fips |
— |
| seaweedfs-operator |
affected |
chainguard |
seaweedfs-operator |
— |
| seaweedfs-operator-fips |
affected |
chainguard |
seaweedfs-operator-fips |
— |
| seaweedfs-rocksdb |
affected |
chainguard |
seaweedfs-rocksdb |
— |
| seaweedfs-rocksdb-fips |
affected |
chainguard |
seaweedfs-rocksdb-fips |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| splunk-otel-collector |
affected |
wolfi |
splunk-otel-collector |
— |
| splunk-otel-collector |
affected |
chainguard |
splunk-otel-collector |
— |
| splunk-otel-collector-fips |
affected |
chainguard |
splunk-otel-collector-fips |
— |
| steampipe |
affected |
wolfi |
steampipe |
— |
| steampipe |
affected |
chainguard |
steampipe |
— |
| step-ca |
affected |
wolfi |
step-ca |
— |
| step-ca |
affected |
chainguard |
step-ca |
— |
| step-ca-fips |
affected |
chainguard |
step-ca-fips |
— |
| tekton-chains |
affected |
chainguard |
tekton-chains |
— |
| tekton-chains |
affected |
wolfi |
tekton-chains |
— |
| tekton-chains-fips |
affected |
chainguard |
tekton-chains-fips |
— |
| teleport-17 |
affected |
chainguard |
teleport-17 |
— |
| teleport-operator-fips-16 |
affected |
chainguard |
teleport-operator-fips-16 |
— |
| teleport-operator-fips-17 |
affected |
chainguard |
teleport-operator-fips-17 |
— |
| tempo-2.8 |
affected |
chainguard |
tempo-2.8 |
— |
| tempo-2.9 |
affected |
chainguard |
tempo-2.9 |
— |
| tempo-fips-2.8 |
affected |
chainguard |
tempo-fips-2.8 |
— |
| tempo-fips-2.9 |
affected |
chainguard |
tempo-fips-2.9 |
— |
| terraform |
affected |
wolfi |
terraform |
— |
| terraform |
affected |
chainguard |
terraform |
— |
| terraform-1.10 |
affected |
chainguard |
terraform-1.10 |
— |
| terraform-1.11 |
affected |
chainguard |
terraform-1.11 |
— |
| terraform-1.12 |
affected |
chainguard |
terraform-1.12 |
— |
| terraform-1.9 |
affected |
chainguard |
terraform-1.9 |
— |
| terragrunt |
affected |
chainguard |
terragrunt |
— |
| terragrunt |
affected |
wolfi |
terragrunt |
— |
| terragrunt-fips |
affected |
chainguard |
terragrunt-fips |
— |
| tigera-operator-1.28 |
affected |
chainguard |
tigera-operator-1.28 |
— |
| tigera-operator-1.29 |
affected |
chainguard |
tigera-operator-1.29 |
— |
| tigera-operator-1.34 |
affected |
chainguard |
tigera-operator-1.34 |
— |
| tigera-operator-1.36 |
affected |
chainguard |
tigera-operator-1.36 |
— |
| tigera-operator-1.37 |
affected |
chainguard |
tigera-operator-1.37 |
— |
| tigera-operator-1.38 |
affected |
chainguard |
tigera-operator-1.38 |
— |
| tigera-operator-1.40 |
affected |
wolfi |
tigera-operator-1.40 |
— |
| tigera-operator-1.40 |
affected |
chainguard |
tigera-operator-1.40 |
— |
| tigera-operator-1.41 |
affected |
chainguard |
tigera-operator-1.41 |
— |
| tigera-operator-1.41 |
affected |
wolfi |
tigera-operator-1.41 |
— |
| tigera-operator-fips-1.29 |
affected |
chainguard |
tigera-operator-fips-1.29 |
— |
| tigera-operator-fips-1.34 |
affected |
chainguard |
tigera-operator-fips-1.34 |
— |
| tigera-operator-fips-1.36 |
affected |
chainguard |
tigera-operator-fips-1.36 |
— |
| tigera-operator-fips-1.37 |
affected |
chainguard |
tigera-operator-fips-1.37 |
— |
| tigera-operator-fips-1.38 |
affected |
chainguard |
tigera-operator-fips-1.38 |
— |
| tigera-operator-fips-1.40 |
affected |
chainguard |
tigera-operator-fips-1.40 |
— |
| tigera-operator-fips-1.41 |
affected |
chainguard |
tigera-operator-fips-1.41 |
— |
| trillian |
affected |
wolfi |
trillian |
— |
| trillian |
affected |
chainguard |
trillian |
— |
| trillian-fips |
affected |
chainguard |
trillian-fips |
— |
| vault-1.16 |
affected |
chainguard |
vault-1.16 |
— |
| vault-1.17 |
affected |
chainguard |
vault-1.17 |
— |
| vault-1.18 |
affected |
chainguard |
vault-1.18 |
— |
| vault-1.19 |
affected |
chainguard |
vault-1.19 |
— |
| vault-1.20 |
affected |
chainguard |
vault-1.20 |
— |
| vault-1.21 |
affected |
chainguard |
vault-1.21 |
— |
| vault-2.0 |
affected |
chainguard |
vault-2.0 |
— |
| vault-benchmark |
affected |
wolfi |
vault-benchmark |
— |
| vault-benchmark |
affected |
chainguard |
vault-benchmark |
— |
| vault-env |
affected |
wolfi |
vault-env |
— |
| vault-env |
affected |
chainguard |
vault-env |
— |
| vault-fips-1.21 |
affected |
chainguard |
vault-fips-1.21 |
— |
| vault-fips-2.0 |
affected |
chainguard |
vault-fips-2.0 |
— |
| vault-secrets-operator |
affected |
chainguard |
vault-secrets-operator |
— |
| vault-secrets-operator-fips |
affected |
chainguard |
vault-secrets-operator-fips |
— |
| vault-secrets-webhook |
affected |
wolfi |
vault-secrets-webhook |
— |
| vault-secrets-webhook |
affected |
chainguard |
vault-secrets-webhook |
— |
| verticadb-operator |
affected |
chainguard |
verticadb-operator |
— |
| verticadb-operator |
affected |
wolfi |
verticadb-operator |
— |
| verticadb-operator-fips |
affected |
chainguard |
verticadb-operator-fips |
— |
| wal-g |
affected |
chainguard |
wal-g |
— |
| wal-g |
affected |
wolfi |
wal-g |
— |
| weaviate |
affected |
chainguard |
weaviate |
— |
| weaviate |
affected |
wolfi |
weaviate |
— |
| zot |
affected |
wolfi |
zot |
— |
| zot |
affected |
chainguard |
zot |
— |
GooglePoC exploitCRITICAL2022-02-11
In-band key negotiation issue in AWS S3 Crypto SDK for golang
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aws/aws-sdk-go |
affected |
github.com |
github.com/aws/aws-sdk-go |
— |
Open SourcePoC exploitCRITICAL2022-02-11
In-band key negotiation issue in AWS S3 Crypto SDK for golang
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| amazon-cloudwatch-agent |
affected |
wolfi |
amazon-cloudwatch-agent |
— |
| amazon-cloudwatch-agent |
affected |
chainguard |
amazon-cloudwatch-agent |
— |
| amazon-cloudwatch-agent-fips |
affected |
chainguard |
amazon-cloudwatch-agent-fips |
— |
| amazon-ecs-agent |
affected |
chainguard |
amazon-ecs-agent |
— |
| amazon-ecs-agent-fips |
affected |
chainguard |
amazon-ecs-agent-fips |
— |
| apply-cve-bump |
affected |
chainguard |
apply-cve-bump |
— |
| argo-cd-3.0 |
affected |
wolfi |
argo-cd-3.0 |
— |
| argo-cd-3.0 |
affected |
chainguard |
argo-cd-3.0 |
— |
| argo-cd-3.1 |
affected |
wolfi |
argo-cd-3.1 |
— |
| argo-cd-3.1 |
affected |
chainguard |
argo-cd-3.1 |
— |
| argo-cd-3.2 |
affected |
chainguard |
argo-cd-3.2 |
— |
| argo-cd-3.2 |
affected |
wolfi |
argo-cd-3.2 |
— |
| argo-cd-3.3 |
affected |
chainguard |
argo-cd-3.3 |
— |
| argo-cd-3.3 |
affected |
wolfi |
argo-cd-3.3 |
— |
| argo-cd-fips-3.0 |
affected |
chainguard |
argo-cd-fips-3.0 |
— |
| argo-cd-fips-3.1 |
affected |
chainguard |
argo-cd-fips-3.1 |
— |
| argo-cd-fips-3.2 |
affected |
chainguard |
argo-cd-fips-3.2 |
— |
| argo-cd-fips-3.3 |
affected |
chainguard |
argo-cd-fips-3.3 |
— |
| argo-events |
affected |
chainguard |
argo-events |
— |
| argo-events |
affected |
wolfi |
argo-events |
— |
| argo-events-fips |
affected |
chainguard |
argo-events-fips |
— |
| argo-rollouts |
affected |
chainguard |
argo-rollouts |
— |
| argo-rollouts |
affected |
wolfi |
argo-rollouts |
— |
| argo-rollouts-fips |
affected |
chainguard |
argo-rollouts-fips |
— |
| atlas-1.0 |
affected |
chainguard |
atlas-1.0 |
— |
| atlas-1.0-fips |
affected |
chainguard |
atlas-1.0-fips |
— |
| atlas-1.1 |
affected |
chainguard |
atlas-1.1 |
— |
| atlas-1.1-fips |
affected |
chainguard |
atlas-1.1-fips |
— |
| atlas-1.2 |
affected |
chainguard |
atlas-1.2 |
— |
| aws/aws-sdk-go |
affected |
github.com |
github.com/aws/aws-sdk-go |
— |
| aws-flb-cloudwatch |
affected |
chainguard |
aws-flb-cloudwatch |
— |
| aws-flb-cloudwatch |
affected |
wolfi |
aws-flb-cloudwatch |
— |
| aws-flb-cloudwatch-fips |
affected |
chainguard |
aws-flb-cloudwatch-fips |
— |
| aws-flb-firehose |
affected |
wolfi |
aws-flb-firehose |
— |
| aws-flb-firehose |
affected |
chainguard |
aws-flb-firehose |
— |
| aws-flb-firehose-fips |
affected |
chainguard |
aws-flb-firehose-fips |
— |
| aws-flb-kinesis |
affected |
wolfi |
aws-flb-kinesis |
— |
| aws-flb-kinesis |
affected |
chainguard |
aws-flb-kinesis |
— |
| aws-flb-kinesis-fips |
affected |
chainguard |
aws-flb-kinesis-fips |
— |
| aws-node-termination-handler |
affected |
wolfi |
aws-node-termination-handler |
— |
| aws-node-termination-handler |
affected |
chainguard |
aws-node-termination-handler |
— |
| aws-node-termination-handler-fips |
affected |
chainguard |
aws-node-termination-handler-fips |
— |
| aws-nuke |
affected |
chainguard |
aws-nuke |
— |
| aws-nuke |
affected |
wolfi |
aws-nuke |
— |
| aws-nuke-fips |
affected |
chainguard |
aws-nuke-fips |
— |
| aws-otel-collector |
affected |
chainguard |
aws-otel-collector |
— |
| aws-otel-collector |
affected |
wolfi |
aws-otel-collector |
— |
| aws-otel-collector-fips |
affected |
chainguard |
aws-otel-collector-fips |
— |
| aws-s3-controller |
affected |
wolfi |
aws-s3-controller |
— |
| aws-s3-controller |
affected |
chainguard |
aws-s3-controller |
— |
| aws-sigv4-proxy |
affected |
wolfi |
aws-sigv4-proxy |
— |
| aws-sigv4-proxy |
affected |
chainguard |
aws-sigv4-proxy |
— |
| aws-sigv4-proxy-fips |
affected |
chainguard |
aws-sigv4-proxy-fips |
— |
| bank-vaults |
affected |
chainguard |
bank-vaults |
— |
| bank-vaults |
affected |
wolfi |
bank-vaults |
— |
| bank-vaults-fips |
affected |
chainguard |
bank-vaults-fips |
— |
| bank-vaults-vault-operator |
affected |
chainguard |
bank-vaults-vault-operator |
— |
| bank-vaults-vault-operator-fips |
affected |
chainguard |
bank-vaults-vault-operator-fips |
— |
| cadence |
affected |
chainguard |
cadence |
— |
| cadence-fips |
affected |
chainguard |
cadence-fips |
— |
| cephcsi |
affected |
chainguard |
cephcsi |
— |
| cephcsi-fips |
affected |
chainguard |
cephcsi-fips |
— |
| cert-exporter |
affected |
wolfi |
cert-exporter |
— |
| cert-exporter |
affected |
chainguard |
cert-exporter |
— |
| cert-exporter-fips |
affected |
chainguard |
cert-exporter-fips |
— |
| certificate-transparency |
affected |
chainguard |
certificate-transparency |
— |
| certificate-transparency |
affected |
wolfi |
certificate-transparency |
— |
| certificate-transparency-fips |
affected |
chainguard |
certificate-transparency-fips |
— |
| cg |
affected |
chainguard |
cg |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| chartmuseum-fips |
affected |
chainguard |
chartmuseum-fips |
— |
| cloudbeat-9.0 |
affected |
chainguard |
cloudbeat-9.0 |
— |
| cloudbeat-fips-8.17 |
affected |
chainguard |
cloudbeat-fips-8.17 |
— |
| cloudbeat-fips-9.0 |
affected |
chainguard |
cloudbeat-fips-9.0 |
— |
| cloud-sql-proxy-2.16 |
affected |
wolfi |
cloud-sql-proxy-2.16 |
— |
| cloud-sql-proxy-2.16 |
affected |
chainguard |
cloud-sql-proxy-2.16 |
— |
| cloud-sql-proxy-2.17 |
affected |
chainguard |
cloud-sql-proxy-2.17 |
— |
| cloud-sql-proxy-2.17 |
affected |
wolfi |
cloud-sql-proxy-2.17 |
— |
| cloud-sql-proxy-2.18 |
affected |
chainguard |
cloud-sql-proxy-2.18 |
— |
| cloud-sql-proxy-2.18 |
affected |
wolfi |
cloud-sql-proxy-2.18 |
— |
| cloud-sql-proxy-2.21 |
affected |
chainguard |
cloud-sql-proxy-2.21 |
— |
| cloud-sql-proxy-2.21 |
affected |
wolfi |
cloud-sql-proxy-2.21 |
— |
| cloud-sql-proxy-2.22 |
affected |
wolfi |
cloud-sql-proxy-2.22 |
— |
| cloud-sql-proxy-2.22 |
affected |
chainguard |
cloud-sql-proxy-2.22 |
— |
| cloud-sql-proxy-fips |
affected |
chainguard |
cloud-sql-proxy-fips |
— |
| cluster-autoscaler-1.32 |
affected |
wolfi |
cluster-autoscaler-1.32 |
— |
| cluster-autoscaler-1.32 |
affected |
chainguard |
cluster-autoscaler-1.32 |
— |
| cluster-autoscaler-1.33 |
affected |
wolfi |
cluster-autoscaler-1.33 |
— |
| cluster-autoscaler-1.33 |
affected |
chainguard |
cluster-autoscaler-1.33 |
— |
| cluster-autoscaler-1.34 |
affected |
chainguard |
cluster-autoscaler-1.34 |
— |
| cluster-autoscaler-1.34 |
affected |
wolfi |
cluster-autoscaler-1.34 |
— |
| cluster-autoscaler-fips-1.32 |
affected |
chainguard |
cluster-autoscaler-fips-1.32 |
— |
| cluster-autoscaler-fips-1.33 |
affected |
chainguard |
cluster-autoscaler-fips-1.33 |
— |
| cluster-autoscaler-fips-1.34 |
affected |
chainguard |
cluster-autoscaler-fips-1.34 |
— |
| commercial-grafana-11.6 |
affected |
chainguard |
commercial-grafana-11.6 |
— |
| commercial-grafana-12.1 |
affected |
chainguard |
commercial-grafana-12.1 |
— |
| commercial-grafana-12.2 |
affected |
chainguard |
commercial-grafana-12.2 |
— |
| commercial-grafana-12.3 |
affected |
chainguard |
commercial-grafana-12.3 |
— |
| commercial-grafana-12.4 |
affected |
chainguard |
commercial-grafana-12.4 |
— |
| commercial-grafana-13.0 |
affected |
chainguard |
commercial-grafana-13.0 |
— |
| consul-1.18 |
affected |
chainguard |
consul-1.18 |
— |
| consul-1.19 |
affected |
chainguard |
consul-1.19 |
— |
| consul-1.20 |
affected |
chainguard |
consul-1.20 |
— |
| consul-1.21 |
affected |
chainguard |
consul-1.21 |
— |
| consul-fips-1.20 |
affected |
chainguard |
consul-fips-1.20 |
— |
| consul-fips-1.21 |
affected |
chainguard |
consul-fips-1.21 |
— |
| consul-k8s-1.1 |
affected |
chainguard |
consul-k8s-1.1 |
— |
| consul-k8s-1.3 |
affected |
chainguard |
consul-k8s-1.3 |
— |
| consul-k8s-1.4 |
affected |
chainguard |
consul-k8s-1.4 |
— |
| consul-k8s-1.5 |
affected |
chainguard |
consul-k8s-1.5 |
— |
| consul-k8s-1.6 |
affected |
chainguard |
consul-k8s-1.6 |
— |
| consul-k8s-1.6 |
affected |
wolfi |
consul-k8s-1.6 |
— |
| consul-k8s-fips-1.1 |
affected |
chainguard |
consul-k8s-fips-1.1 |
— |
| consul-k8s-fips-1.3 |
affected |
chainguard |
consul-k8s-fips-1.3 |
— |
| consul-k8s-fips-1.4 |
affected |
chainguard |
consul-k8s-fips-1.4 |
— |
| consul-k8s-fips-1.5 |
affected |
chainguard |
consul-k8s-fips-1.5 |
— |
| consul-k8s-fips-1.6 |
affected |
chainguard |
consul-k8s-fips-1.6 |
— |
| crossplane-aws-provider |
affected |
chainguard |
crossplane-aws-provider |
— |
| crossplane-aws-provider-fips |
affected |
chainguard |
crossplane-aws-provider-fips |
— |
| dapr-1.14 |
affected |
chainguard |
dapr-1.14 |
— |
| dapr-1.15 |
affected |
wolfi |
dapr-1.15 |
— |
| dapr-1.15 |
affected |
chainguard |
dapr-1.15 |
— |
| dapr-1.16 |
affected |
wolfi |
dapr-1.16 |
— |
| dapr-1.16 |
affected |
chainguard |
dapr-1.16 |
— |
| dapr-fips-1.14 |
affected |
chainguard |
dapr-fips-1.14 |
— |
| dapr-fips-1.15 |
affected |
chainguard |
dapr-fips-1.15 |
— |
| dapr-fips-1.16 |
affected |
chainguard |
dapr-fips-1.16 |
— |
| datadog-agent-7.71 |
affected |
chainguard |
datadog-agent-7.71 |
— |
| datadog-agent-7.77 |
affected |
wolfi |
datadog-agent-7.77 |
— |
| datadog-agent-7.77 |
affected |
chainguard |
datadog-agent-7.77 |
— |
| datadog-agent-7.78 |
affected |
chainguard |
datadog-agent-7.78 |
— |
| datadog-agent-7.78 |
affected |
wolfi |
datadog-agent-7.78 |
— |
| datadog-agent-7.79 |
affected |
chainguard |
datadog-agent-7.79 |
— |
| datadog-agent-7.79 |
affected |
wolfi |
datadog-agent-7.79 |
— |
| datadog-agent-fips-7.71 |
affected |
chainguard |
datadog-agent-fips-7.71 |
— |
| datadog-agent-fips-7.77 |
affected |
chainguard |
datadog-agent-fips-7.77 |
— |
| datadog-agent-fips-7.78 |
affected |
chainguard |
datadog-agent-fips-7.78 |
— |
| datadog-agent-fips-7.79 |
affected |
chainguard |
datadog-agent-fips-7.79 |
— |
| distribution |
affected |
wolfi |
distribution |
— |
| distribution |
affected |
chainguard |
distribution |
— |
| distribution-fips |
affected |
chainguard |
distribution-fips |
— |
| drone |
affected |
chainguard |
drone |
— |
| drone-fips |
affected |
chainguard |
drone-fips |
— |
| elastic-agent-8.19 |
affected |
chainguard |
elastic-agent-8.19 |
— |
| elastic-agent-9.1 |
affected |
chainguard |
elastic-agent-9.1 |
— |
| elastic-agent-9.2 |
affected |
chainguard |
elastic-agent-9.2 |
— |
| elastic-agent-9.3 |
affected |
chainguard |
elastic-agent-9.3 |
— |
| elastic-agent-9.4 |
affected |
chainguard |
elastic-agent-9.4 |
— |
| elastic-agent-fips-8.19 |
affected |
chainguard |
elastic-agent-fips-8.19 |
— |
| elastic-agent-fips-9.1 |
affected |
chainguard |
elastic-agent-fips-9.1 |
— |
| elastic-agent-fips-9.2 |
affected |
chainguard |
elastic-agent-fips-9.2 |
— |
| elastic-agent-fips-9.3 |
affected |
chainguard |
elastic-agent-fips-9.3 |
— |
| elastic-agent-fips-9.4 |
affected |
chainguard |
elastic-agent-fips-9.4 |
— |
| external-secrets-fips |
affected |
chainguard |
external-secrets-fips |
— |
| external-secrets-operator-1.2 |
affected |
wolfi |
external-secrets-operator-1.2 |
— |
| external-secrets-operator-1.2 |
affected |
chainguard |
external-secrets-operator-1.2 |
— |
| external-secrets-operator-1.3 |
affected |
chainguard |
external-secrets-operator-1.3 |
— |
| external-secrets-operator-1.3 |
affected |
wolfi |
external-secrets-operator-1.3 |
— |
| external-secrets-operator-2.0 |
affected |
wolfi |
external-secrets-operator-2.0 |
— |
| external-secrets-operator-2.0 |
affected |
chainguard |
external-secrets-operator-2.0 |
— |
| external-secrets-operator-2.1 |
affected |
wolfi |
external-secrets-operator-2.1 |
— |
| external-secrets-operator-2.1 |
affected |
chainguard |
external-secrets-operator-2.1 |
— |
| external-secrets-operator-2.2 |
affected |
wolfi |
external-secrets-operator-2.2 |
— |
| external-secrets-operator-2.2 |
affected |
chainguard |
external-secrets-operator-2.2 |
— |
| external-secrets-operator-2.3 |
affected |
chainguard |
external-secrets-operator-2.3 |
— |
| external-secrets-operator-2.3 |
affected |
wolfi |
external-secrets-operator-2.3 |
— |
| external-secrets-operator-2.4 |
affected |
wolfi |
external-secrets-operator-2.4 |
— |
| external-secrets-operator-2.4 |
affected |
chainguard |
external-secrets-operator-2.4 |
— |
| external-secrets-operator-2.5 |
affected |
chainguard |
external-secrets-operator-2.5 |
— |
| external-secrets-operator-2.5 |
affected |
wolfi |
external-secrets-operator-2.5 |
— |
| external-secrets-operator-2.6 |
affected |
wolfi |
external-secrets-operator-2.6 |
— |
| external-secrets-operator-2.6 |
affected |
chainguard |
external-secrets-operator-2.6 |
— |
| external-secrets-operator-2.7 |
affected |
chainguard |
external-secrets-operator-2.7 |
— |
| external-secrets-operator-fips-1.2 |
affected |
chainguard |
external-secrets-operator-fips-1.2 |
— |
| external-secrets-operator-fips-1.3 |
affected |
chainguard |
external-secrets-operator-fips-1.3 |
— |
| external-secrets-operator-fips-2.0 |
affected |
chainguard |
external-secrets-operator-fips-2.0 |
— |
| external-secrets-operator-fips-2.1 |
affected |
chainguard |
external-secrets-operator-fips-2.1 |
— |
| external-secrets-operator-fips-2.2 |
affected |
chainguard |
external-secrets-operator-fips-2.2 |
— |
| external-secrets-operator-fips-2.3 |
affected |
chainguard |
external-secrets-operator-fips-2.3 |
— |
| external-secrets-operator-fips-2.4 |
affected |
chainguard |
external-secrets-operator-fips-2.4 |
— |
| external-secrets-operator-fips-2.5 |
affected |
chainguard |
external-secrets-operator-fips-2.5 |
— |
| external-secrets-operator-fips-2.6 |
affected |
chainguard |
external-secrets-operator-fips-2.6 |
— |
| external-secrets-operator-fips-2.7 |
affected |
chainguard |
external-secrets-operator-fips-2.7 |
— |
| flagger |
affected |
chainguard |
flagger |
— |
| flagger-fips |
affected |
chainguard |
flagger-fips |
— |
| flyte |
affected |
chainguard |
flyte |
— |
| flyte |
affected |
wolfi |
flyte |
— |
| gatekeeper-3.20 |
affected |
chainguard |
gatekeeper-3.20 |
— |
| gatekeeper-3.20 |
affected |
wolfi |
gatekeeper-3.20 |
— |
| gatekeeper-3.21 |
affected |
chainguard |
gatekeeper-3.21 |
— |
| gatekeeper-3.21 |
affected |
wolfi |
gatekeeper-3.21 |
— |
| gatekeeper-3.22 |
affected |
chainguard |
gatekeeper-3.22 |
— |
| gatekeeper-3.22 |
affected |
wolfi |
gatekeeper-3.22 |
— |
| gatekeeper-fips-3.20 |
affected |
chainguard |
gatekeeper-fips-3.20 |
— |
| gatekeeper-fips-3.21 |
affected |
chainguard |
gatekeeper-fips-3.21 |
— |
| gatekeeper-fips-3.22 |
affected |
chainguard |
gatekeeper-fips-3.22 |
— |
| gitlab-cng-18.10 |
affected |
chainguard |
gitlab-cng-18.10 |
— |
| gitlab-cng-18.11 |
affected |
chainguard |
gitlab-cng-18.11 |
— |
| gitlab-cng-19.0 |
affected |
chainguard |
gitlab-cng-19.0 |
— |
| gitlab-cng-19.1 |
affected |
chainguard |
gitlab-cng-19.1 |
— |
| gitlab-cng-fips-18.10 |
affected |
chainguard |
gitlab-cng-fips-18.10 |
— |
| gitlab-cng-fips-18.11 |
affected |
chainguard |
gitlab-cng-fips-18.11 |
— |
| gitlab-cng-fips-19.0 |
affected |
chainguard |
gitlab-cng-fips-19.0 |
— |
| gitlab-cng-fips-19.1 |
affected |
chainguard |
gitlab-cng-fips-19.1 |
— |
| gitlab-runner-18.10 |
affected |
chainguard |
gitlab-runner-18.10 |
— |
| gitlab-runner-18.10 |
affected |
wolfi |
gitlab-runner-18.10 |
— |
| gitlab-runner-18.11 |
affected |
chainguard |
gitlab-runner-18.11 |
— |
| gitlab-runner-18.11 |
affected |
wolfi |
gitlab-runner-18.11 |
— |
| gitlab-runner-19.0 |
affected |
wolfi |
gitlab-runner-19.0 |
— |
| gitlab-runner-19.0 |
affected |
chainguard |
gitlab-runner-19.0 |
— |
| gitlab-runner-19.1 |
affected |
wolfi |
gitlab-runner-19.1 |
— |
| gitlab-runner-19.1 |
affected |
chainguard |
gitlab-runner-19.1 |
— |
| gitlab-runner-fips-18.10 |
affected |
chainguard |
gitlab-runner-fips-18.10 |
— |
| gitlab-runner-fips-18.11 |
affected |
chainguard |
gitlab-runner-fips-18.11 |
— |
| gitlab-runner-fips-19.0 |
affected |
chainguard |
gitlab-runner-fips-19.0 |
— |
| gitlab-runner-fips-19.1 |
affected |
chainguard |
gitlab-runner-fips-19.1 |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gitsign |
affected |
wolfi |
gitsign |
— |
| gitsign |
affected |
chainguard |
gitsign |
— |
| go-getter-2 |
affected |
chainguard |
go-getter-2 |
— |
| go-getter-2.1 |
affected |
chainguard |
go-getter-2.1 |
— |
| go-getter-2.2 |
affected |
chainguard |
go-getter-2.2 |
— |
| go-getter-2-fips |
affected |
chainguard |
go-getter-2-fips |
— |
| gomplate-4 |
affected |
chainguard |
gomplate-4 |
— |
| gomplate-5 |
affected |
chainguard |
gomplate-5 |
— |
| gomplate-5 |
affected |
wolfi |
gomplate-5 |
— |
| gomplate-fips-4 |
affected |
chainguard |
gomplate-fips-4 |
— |
| gomplate-fips-5 |
affected |
chainguard |
gomplate-fips-5 |
— |
| google-cloud-otel-ops-collector |
affected |
chainguard |
google-cloud-otel-ops-collector |
— |
| gostatsd |
affected |
chainguard |
gostatsd |
— |
| gostatsd |
affected |
wolfi |
gostatsd |
— |
| grafana-11.6 |
affected |
chainguard |
grafana-11.6 |
— |
| grafana-12.0 |
affected |
chainguard |
grafana-12.0 |
— |
| grafana-12.0 |
affected |
wolfi |
grafana-12.0 |
— |
| grafana-12.1 |
affected |
wolfi |
grafana-12.1 |
— |
| grafana-12.1 |
affected |
chainguard |
grafana-12.1 |
— |
| grafana-12.2 |
affected |
wolfi |
grafana-12.2 |
— |
| grafana-12.2 |
affected |
chainguard |
grafana-12.2 |
— |
| grafana-12.3 |
affected |
wolfi |
grafana-12.3 |
— |
| grafana-12.3 |
affected |
chainguard |
grafana-12.3 |
— |
| grafana-12.4 |
affected |
chainguard |
grafana-12.4 |
— |
| grafana-12.4 |
affected |
wolfi |
grafana-12.4 |
— |
| grafana-13.0 |
affected |
wolfi |
grafana-13.0 |
— |
| grafana-13.0 |
affected |
chainguard |
grafana-13.0 |
— |
| grafana-13.1 |
affected |
chainguard |
grafana-13.1 |
— |
| grafana-agent-operator |
affected |
wolfi |
grafana-agent-operator |
— |
| grafana-agent-operator |
affected |
chainguard |
grafana-agent-operator |
— |
| grafana-fips-11.6 |
affected |
chainguard |
grafana-fips-11.6 |
— |
| grafana-fips-12.0 |
affected |
chainguard |
grafana-fips-12.0 |
— |
| grafana-fips-12.1 |
affected |
chainguard |
grafana-fips-12.1 |
— |
| grafana-fips-12.2 |
affected |
chainguard |
grafana-fips-12.2 |
— |
| grafana-fips-12.3 |
affected |
chainguard |
grafana-fips-12.3 |
— |
| grafana-fips-12.4 |
affected |
chainguard |
grafana-fips-12.4 |
— |
| grafana-fips-13.0 |
affected |
chainguard |
grafana-fips-13.0 |
— |
| grafana-fips-13.1 |
affected |
chainguard |
grafana-fips-13.1 |
— |
| grafana-mimir-2.17 |
affected |
chainguard |
grafana-mimir-2.17 |
— |
| grafana-mimir-3.0 |
affected |
chainguard |
grafana-mimir-3.0 |
— |
| grafana-mimir-3.0 |
affected |
wolfi |
grafana-mimir-3.0 |
— |
| grafana-mimir-fips-2.17 |
affected |
chainguard |
grafana-mimir-fips-2.17 |
— |
| grafana-mimir-fips-3.0 |
affected |
chainguard |
grafana-mimir-fips-3.0 |
— |
| grafana-pyroscope-1.12 |
affected |
chainguard |
grafana-pyroscope-1.12 |
— |
| grafana-pyroscope-1.13 |
affected |
wolfi |
grafana-pyroscope-1.13 |
— |
| grafana-pyroscope-1.13 |
affected |
chainguard |
grafana-pyroscope-1.13 |
— |
| grafana-pyroscope-1.14 |
affected |
chainguard |
grafana-pyroscope-1.14 |
— |
| grept |
affected |
chainguard |
grept |
— |
| grept-fips |
affected |
chainguard |
grept-fips |
— |
| guac |
affected |
chainguard |
guac |
— |
| guac |
affected |
wolfi |
guac |
— |
| harbor-2.12 |
affected |
chainguard |
harbor-2.12 |
— |
| harbor-2.13 |
affected |
wolfi |
harbor-2.13 |
— |
| harbor-2.13 |
affected |
chainguard |
harbor-2.13 |
— |
| harbor-2.14 |
affected |
chainguard |
harbor-2.14 |
— |
| harbor-2.14 |
affected |
wolfi |
harbor-2.14 |
— |
| harbor-2.15 |
affected |
chainguard |
harbor-2.15 |
— |
| harbor-fips-2.12 |
affected |
chainguard |
harbor-fips-2.12 |
— |
| harbor-fips-2.13 |
affected |
chainguard |
harbor-fips-2.13 |
— |
| harbor-fips-2.14 |
affected |
chainguard |
harbor-fips-2.14 |
— |
| harbor-fips-2.15 |
affected |
chainguard |
harbor-fips-2.15 |
— |
| harbor-registry |
affected |
chainguard |
harbor-registry |
— |
| harbor-registry |
affected |
wolfi |
harbor-registry |
— |
| harbor-registry-fips |
affected |
chainguard |
harbor-registry-fips |
— |
| harvester |
affected |
chainguard |
harvester |
— |
| harvester-fips |
affected |
chainguard |
harvester-fips |
— |
| influxd-2.7 |
affected |
chainguard |
influxd-2.7 |
— |
| juicefs-1.2 |
affected |
chainguard |
juicefs-1.2 |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k8s-image-swapper |
affected |
chainguard |
k8s-image-swapper |
— |
| k8s-image-swapper-fips |
affected |
chainguard |
k8s-image-swapper-fips |
— |
| karpenter-0.33 |
affected |
chainguard |
karpenter-0.33 |
— |
| karpenter-0.34 |
affected |
chainguard |
karpenter-0.34 |
— |
| karpenter-0.35 |
affected |
chainguard |
karpenter-0.35 |
— |
| karpenter-0.36 |
affected |
chainguard |
karpenter-0.36 |
— |
| karpenter-0.37 |
affected |
chainguard |
karpenter-0.37 |
— |
| karpenter-fips-0.33 |
affected |
chainguard |
karpenter-fips-0.33 |
— |
| karpenter-fips-0.34 |
affected |
chainguard |
karpenter-fips-0.34 |
— |
| karpenter-fips-0.35 |
affected |
chainguard |
karpenter-fips-0.35 |
— |
| karpenter-fips-0.36 |
affected |
chainguard |
karpenter-fips-0.36 |
— |
| karpenter-fips-0.37 |
affected |
chainguard |
karpenter-fips-0.37 |
— |
| kiam |
affected |
chainguard |
kiam |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kserve |
affected |
wolfi |
kserve |
— |
| kserve |
affected |
chainguard |
kserve |
— |
| kserve-fips |
affected |
chainguard |
kserve-fips |
— |
| kserve-localmodelnode-agent |
affected |
chainguard |
kserve-localmodelnode-agent |
— |
| kserve-localmodelnode-agent-fips |
affected |
chainguard |
kserve-localmodelnode-agent-fips |
— |
| kserve-modelmesh-serving |
affected |
chainguard |
kserve-modelmesh-serving |
— |
| kserve-modelmesh-serving |
affected |
wolfi |
kserve-modelmesh-serving |
— |
| kube-arangodb-1.3 |
affected |
wolfi |
kube-arangodb-1.3 |
— |
| kube-arangodb-1.3 |
affected |
chainguard |
kube-arangodb-1.3 |
— |
| kube-arangodb-1.4 |
affected |
wolfi |
kube-arangodb-1.4 |
— |
| kube-arangodb-1.4 |
affected |
chainguard |
kube-arangodb-1.4 |
— |
| kube-arangodb-fips-1.3 |
affected |
chainguard |
kube-arangodb-fips-1.3 |
— |
| kube-arangodb-fips-1.4 |
affected |
chainguard |
kube-arangodb-fips-1.4 |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubeflow-pipelines-driver-fips |
affected |
chainguard |
kubeflow-pipelines-driver-fips |
— |
| kubeflow-pipelines-fips |
affected |
chainguard |
kubeflow-pipelines-fips |
— |
| kubernetes-event-exporter |
affected |
chainguard |
kubernetes-event-exporter |
— |
| kubernetes-event-exporter |
affected |
wolfi |
kubernetes-event-exporter |
— |
| kubernetes-event-exporter-fips |
affected |
chainguard |
kubernetes-event-exporter-fips |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubescape-operator |
affected |
wolfi |
kubescape-operator |
— |
| kubescape-operator |
affected |
chainguard |
kubescape-operator |
— |
| kubescape-operator-fips |
affected |
chainguard |
kubescape-operator-fips |
— |
| kubescape-server |
affected |
chainguard |
kubescape-server |
— |
| kubescape-server-fips |
affected |
chainguard |
kubescape-server-fips |
— |
| kubevirt-cdi-uploadserver-1.5 |
affected |
chainguard |
kubevirt-cdi-uploadserver-1.5 |
— |
| kubevirt-cdi-uploadserver-1.59 |
affected |
chainguard |
kubevirt-cdi-uploadserver-1.59 |
— |
| kubevirt-cdi-uploadserver-1.6 |
affected |
chainguard |
kubevirt-cdi-uploadserver-1.6 |
— |
| kubevirt-cdi-uploadserver-fips-1.5 |
affected |
chainguard |
kubevirt-cdi-uploadserver-fips-1.5 |
— |
| kubevirt-cdi-uploadserver-fips-1.59 |
affected |
chainguard |
kubevirt-cdi-uploadserver-fips-1.59 |
— |
| kubevirt-cdi-uploadserver-fips-1.6 |
affected |
chainguard |
kubevirt-cdi-uploadserver-fips-1.6 |
— |
| loki-2.9 |
affected |
chainguard |
loki-2.9 |
— |
| loki-3.4 |
affected |
chainguard |
loki-3.4 |
— |
| loki-3.5 |
affected |
wolfi |
loki-3.5 |
— |
| loki-3.5 |
affected |
chainguard |
loki-3.5 |
— |
| loki-3.6 |
affected |
wolfi |
loki-3.6 |
— |
| loki-3.6 |
affected |
chainguard |
loki-3.6 |
— |
| loki-3.7 |
affected |
wolfi |
loki-3.7 |
— |
| loki-3.7 |
affected |
chainguard |
loki-3.7 |
— |
| loki-fips-2.9 |
affected |
chainguard |
loki-fips-2.9 |
— |
| loki-fips-3.4 |
affected |
chainguard |
loki-fips-3.4 |
— |
| loki-fips-3.5 |
affected |
chainguard |
loki-fips-3.5 |
— |
| loki-fips-3.6 |
affected |
chainguard |
loki-fips-3.6 |
— |
| loki-fips-3.7 |
affected |
chainguard |
loki-fips-3.7 |
— |
| longhorn-backing-image-manager-1.8 |
affected |
chainguard |
longhorn-backing-image-manager-1.8 |
— |
| longhorn-backing-image-manager-1.9 |
affected |
chainguard |
longhorn-backing-image-manager-1.9 |
— |
| longhorn-backing-image-manager-fips-1.8 |
affected |
chainguard |
longhorn-backing-image-manager-fips-1.8 |
— |
| longhorn-backing-image-manager-fips-1.9 |
affected |
chainguard |
longhorn-backing-image-manager-fips-1.9 |
— |
| longhorn-engine-1.8 |
affected |
chainguard |
longhorn-engine-1.8 |
— |
| longhorn-engine-1.9 |
affected |
chainguard |
longhorn-engine-1.9 |
— |
| longhorn-instance-manager-1.8 |
affected |
chainguard |
longhorn-instance-manager-1.8 |
— |
| longhorn-instance-manager-1.8-fips |
affected |
chainguard |
longhorn-instance-manager-1.8-fips |
— |
| longhorn-instance-manager-1.9 |
affected |
chainguard |
longhorn-instance-manager-1.9 |
— |
| longhorn-instance-manager-1.9-fips |
affected |
chainguard |
longhorn-instance-manager-1.9-fips |
— |
| mapotf |
affected |
chainguard |
mapotf |
— |
| mapotf-fips |
affected |
chainguard |
mapotf-fips |
— |
| mattermost-10.11 |
affected |
chainguard |
mattermost-10.11 |
— |
| mattermost-11.1 |
affected |
wolfi |
mattermost-11.1 |
— |
| mattermost-11.1 |
affected |
chainguard |
mattermost-11.1 |
— |
| mattermost-11.2 |
affected |
chainguard |
mattermost-11.2 |
— |
| mattermost-11.2 |
affected |
wolfi |
mattermost-11.2 |
— |
| mattermost-fips-10.11 |
affected |
chainguard |
mattermost-fips-10.11 |
— |
| mattermost-fips-11.1 |
affected |
chainguard |
mattermost-fips-11.1 |
— |
| mattermost-fips-11.2 |
affected |
chainguard |
mattermost-fips-11.2 |
— |
| metrics-agent |
affected |
chainguard |
metrics-agent |
— |
| metrics-agent |
affected |
wolfi |
metrics-agent |
— |
| metrics-agent-fips |
affected |
chainguard |
metrics-agent-fips |
— |
| monstache |
affected |
chainguard |
monstache |
— |
| neuvector |
affected |
chainguard |
neuvector |
— |
| neuvector-fips |
affected |
chainguard |
neuvector-fips |
— |
| neuvector-scanner |
affected |
chainguard |
neuvector-scanner |
— |
| neuvector-scanner |
affected |
wolfi |
neuvector-scanner |
— |
| neuvector-scanner-fips |
affected |
chainguard |
neuvector-scanner-fips |
— |
| newrelic-nri-statsd |
affected |
chainguard |
newrelic-nri-statsd |
— |
| newrelic-nri-statsd |
affected |
wolfi |
newrelic-nri-statsd |
— |
| node-problem-detector-0.8 |
affected |
chainguard |
node-problem-detector-0.8 |
— |
| node-problem-detector-1.34 |
affected |
chainguard |
node-problem-detector-1.34 |
— |
| node-problem-detector-1.35 |
affected |
chainguard |
node-problem-detector-1.35 |
— |
| node-problem-detector-1.35 |
affected |
wolfi |
node-problem-detector-1.35 |
— |
| node-problem-detector-fips-0.8 |
affected |
chainguard |
node-problem-detector-fips-0.8 |
— |
| node-problem-detector-fips-1.34 |
affected |
chainguard |
node-problem-detector-fips-1.34 |
— |
| node-problem-detector-fips-1.35 |
affected |
chainguard |
node-problem-detector-fips-1.35 |
— |
| nrdot-collector |
affected |
chainguard |
nrdot-collector |
— |
| nrdot-collector-fips |
affected |
chainguard |
nrdot-collector-fips |
— |
| nrdot-collector-k8s |
affected |
chainguard |
nrdot-collector-k8s |
— |
| nrdot-collector-k8s-fips |
affected |
chainguard |
nrdot-collector-k8s-fips |
— |
| openbao |
affected |
chainguard |
openbao |
— |
| openbao |
affected |
wolfi |
openbao |
— |
| openbao-fips |
affected |
chainguard |
openbao-fips |
— |
| opencost |
affected |
wolfi |
opencost |
— |
| opencost |
affected |
chainguard |
opencost |
— |
| opencost-fips |
affected |
chainguard |
opencost-fips |
— |
| opentelemetry-collector |
affected |
chainguard |
opentelemetry-collector |
— |
| opentelemetry-collector |
affected |
wolfi |
opentelemetry-collector |
— |
| opentelemetry-collector-contrib |
affected |
wolfi |
opentelemetry-collector-contrib |
— |
| opentelemetry-collector-contrib |
affected |
chainguard |
opentelemetry-collector-contrib |
— |
| opentelemetry-collector-contrib-fips |
affected |
chainguard |
opentelemetry-collector-contrib-fips |
— |
| opentelemetry-collector-fips |
affected |
chainguard |
opentelemetry-collector-fips |
— |
| opentelemetry-collector-k8s |
affected |
chainguard |
opentelemetry-collector-k8s |
— |
| opentelemetry-collector-k8s-fips |
affected |
chainguard |
opentelemetry-collector-k8s-fips |
— |
| opentofu-1.9 |
affected |
wolfi |
opentofu-1.9 |
— |
| opentofu-1.9 |
affected |
chainguard |
opentofu-1.9 |
— |
| opentofu-fips-1.9 |
affected |
chainguard |
opentofu-fips-1.9 |
— |
| packer |
affected |
chainguard |
packer |
— |
| packer-fips |
affected |
chainguard |
packer-fips |
— |
| plutono |
affected |
chainguard |
plutono |
— |
| plutono-fips |
affected |
chainguard |
plutono-fips |
— |
| porch |
affected |
chainguard |
porch |
— |
| porch-fips |
affected |
chainguard |
porch-fips |
— |
| postgres-operator |
affected |
wolfi |
postgres-operator |
— |
| postgres-operator |
affected |
chainguard |
postgres-operator |
— |
| postgres-operator-fips |
affected |
chainguard |
postgres-operator-fips |
— |
| prometheus-2.51 |
affected |
chainguard |
prometheus-2.51 |
— |
| prometheus-3.12 |
affected |
chainguard |
prometheus-3.12 |
— |
| prometheus-3.12 |
affected |
wolfi |
prometheus-3.12 |
— |
| prometheus-3.5 |
affected |
chainguard |
prometheus-3.5 |
— |
| prometheus-fips-3.12 |
affected |
chainguard |
prometheus-fips-3.12 |
— |
| prometheus-fips-3.5 |
affected |
chainguard |
prometheus-fips-3.5 |
— |
| promxy |
affected |
wolfi |
promxy |
— |
| promxy |
affected |
chainguard |
promxy |
— |
| promxy-fips |
affected |
chainguard |
promxy-fips |
— |
| rancher-2.10 |
affected |
chainguard |
rancher-2.10 |
— |
| rancher-2.11 |
affected |
chainguard |
rancher-2.11 |
— |
| rancher-2.12 |
affected |
chainguard |
rancher-2.12 |
— |
| rancher-2.13 |
affected |
chainguard |
rancher-2.13 |
— |
| rancher-2.13 |
affected |
wolfi |
rancher-2.13 |
— |
| rancher-2.14 |
affected |
chainguard |
rancher-2.14 |
— |
| rancher-2.14 |
affected |
wolfi |
rancher-2.14 |
— |
| rancher-agent-2.10 |
affected |
chainguard |
rancher-agent-2.10 |
— |
| rancher-agent-2.11 |
affected |
chainguard |
rancher-agent-2.11 |
— |
| rancher-agent-2.12 |
affected |
chainguard |
rancher-agent-2.12 |
— |
| rancher-agent-2.13 |
affected |
chainguard |
rancher-agent-2.13 |
— |
| rancher-agent-2.13 |
affected |
wolfi |
rancher-agent-2.13 |
— |
| rancher-agent-2.14 |
affected |
chainguard |
rancher-agent-2.14 |
— |
| rancher-agent-2.14 |
affected |
wolfi |
rancher-agent-2.14 |
— |
| rancher-agent-2.9 |
affected |
chainguard |
rancher-agent-2.9 |
— |
| rancher-machine |
affected |
chainguard |
rancher-machine |
— |
| rancher-machine |
affected |
wolfi |
rancher-machine |
— |
| redpanda-25.1 |
affected |
chainguard |
redpanda-25.1 |
— |
| redpanda-25.2 |
affected |
chainguard |
redpanda-25.2 |
— |
| redpanda-25.3 |
affected |
chainguard |
redpanda-25.3 |
— |
| rook-1.18 |
affected |
chainguard |
rook-1.18 |
— |
| rook-1.19 |
affected |
wolfi |
rook-1.19 |
— |
| rook-1.19 |
affected |
chainguard |
rook-1.19 |
— |
| rook-fips-1.18 |
affected |
chainguard |
rook-fips-1.18 |
— |
| rook-fips-1.19 |
affected |
chainguard |
rook-fips-1.19 |
— |
| s5cmd |
affected |
wolfi |
s5cmd |
— |
| s5cmd |
affected |
chainguard |
s5cmd |
— |
| s5cmd-fips |
affected |
chainguard |
s5cmd-fips |
— |
| seaweedfs |
affected |
chainguard |
seaweedfs |
— |
| seaweedfs |
affected |
wolfi |
seaweedfs |
— |
| seaweedfs-fips |
affected |
chainguard |
seaweedfs-fips |
— |
| seaweedfs-operator |
affected |
chainguard |
seaweedfs-operator |
— |
| seaweedfs-operator-fips |
affected |
chainguard |
seaweedfs-operator-fips |
— |
| seaweedfs-rocksdb |
affected |
chainguard |
seaweedfs-rocksdb |
— |
| seaweedfs-rocksdb-fips |
affected |
chainguard |
seaweedfs-rocksdb-fips |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| splunk-otel-collector |
affected |
chainguard |
splunk-otel-collector |
— |
| splunk-otel-collector |
affected |
wolfi |
splunk-otel-collector |
— |
| splunk-otel-collector-fips |
affected |
chainguard |
splunk-otel-collector-fips |
— |
| steampipe |
affected |
wolfi |
steampipe |
— |
| steampipe |
affected |
chainguard |
steampipe |
— |
| step-ca |
affected |
wolfi |
step-ca |
— |
| step-ca |
affected |
chainguard |
step-ca |
— |
| step-ca-fips |
affected |
chainguard |
step-ca-fips |
— |
| tekton-chains |
affected |
wolfi |
tekton-chains |
— |
| tekton-chains |
affected |
chainguard |
tekton-chains |
— |
| tekton-chains-fips |
affected |
chainguard |
tekton-chains-fips |
— |
| teleport-17 |
affected |
chainguard |
teleport-17 |
— |
| teleport-operator-fips-16 |
affected |
chainguard |
teleport-operator-fips-16 |
— |
| teleport-operator-fips-17 |
affected |
chainguard |
teleport-operator-fips-17 |
— |
| tempo-2.8 |
affected |
chainguard |
tempo-2.8 |
— |
| tempo-2.9 |
affected |
chainguard |
tempo-2.9 |
— |
| tempo-fips-2.8 |
affected |
chainguard |
tempo-fips-2.8 |
— |
| tempo-fips-2.9 |
affected |
chainguard |
tempo-fips-2.9 |
— |
| terraform |
affected |
chainguard |
terraform |
— |
| terraform |
affected |
wolfi |
terraform |
— |
| terraform-1.10 |
affected |
chainguard |
terraform-1.10 |
— |
| terraform-1.11 |
affected |
chainguard |
terraform-1.11 |
— |
| terraform-1.12 |
affected |
chainguard |
terraform-1.12 |
— |
| terraform-1.9 |
affected |
chainguard |
terraform-1.9 |
— |
| terragrunt |
affected |
chainguard |
terragrunt |
— |
| terragrunt |
affected |
wolfi |
terragrunt |
— |
| terragrunt-fips |
affected |
chainguard |
terragrunt-fips |
— |
| tigera-operator-1.28 |
affected |
chainguard |
tigera-operator-1.28 |
— |
| tigera-operator-1.29 |
affected |
chainguard |
tigera-operator-1.29 |
— |
| tigera-operator-1.34 |
affected |
chainguard |
tigera-operator-1.34 |
— |
| tigera-operator-1.36 |
affected |
chainguard |
tigera-operator-1.36 |
— |
| tigera-operator-1.37 |
affected |
chainguard |
tigera-operator-1.37 |
— |
| tigera-operator-1.38 |
affected |
chainguard |
tigera-operator-1.38 |
— |
| tigera-operator-1.40 |
affected |
chainguard |
tigera-operator-1.40 |
— |
| tigera-operator-1.40 |
affected |
wolfi |
tigera-operator-1.40 |
— |
| tigera-operator-1.41 |
affected |
wolfi |
tigera-operator-1.41 |
— |
| tigera-operator-1.41 |
affected |
chainguard |
tigera-operator-1.41 |
— |
| tigera-operator-fips-1.29 |
affected |
chainguard |
tigera-operator-fips-1.29 |
— |
| tigera-operator-fips-1.34 |
affected |
chainguard |
tigera-operator-fips-1.34 |
— |
| tigera-operator-fips-1.36 |
affected |
chainguard |
tigera-operator-fips-1.36 |
— |
| tigera-operator-fips-1.37 |
affected |
chainguard |
tigera-operator-fips-1.37 |
— |
| tigera-operator-fips-1.38 |
affected |
chainguard |
tigera-operator-fips-1.38 |
— |
| tigera-operator-fips-1.40 |
affected |
chainguard |
tigera-operator-fips-1.40 |
— |
| tigera-operator-fips-1.41 |
affected |
chainguard |
tigera-operator-fips-1.41 |
— |
| trillian |
affected |
chainguard |
trillian |
— |
| trillian |
affected |
wolfi |
trillian |
— |
| trillian-fips |
affected |
chainguard |
trillian-fips |
— |
| vault-1.16 |
affected |
chainguard |
vault-1.16 |
— |
| vault-1.17 |
affected |
chainguard |
vault-1.17 |
— |
| vault-1.18 |
affected |
chainguard |
vault-1.18 |
— |
| vault-1.19 |
affected |
chainguard |
vault-1.19 |
— |
| vault-1.20 |
affected |
chainguard |
vault-1.20 |
— |
| vault-1.21 |
affected |
chainguard |
vault-1.21 |
— |
| vault-2.0 |
affected |
chainguard |
vault-2.0 |
— |
| vault-benchmark |
affected |
chainguard |
vault-benchmark |
— |
| vault-benchmark |
affected |
wolfi |
vault-benchmark |
— |
| vault-env |
affected |
wolfi |
vault-env |
— |
| vault-env |
affected |
chainguard |
vault-env |
— |
| vault-fips-1.21 |
affected |
chainguard |
vault-fips-1.21 |
— |
| vault-fips-2.0 |
affected |
chainguard |
vault-fips-2.0 |
— |
| vault-secrets-operator |
affected |
chainguard |
vault-secrets-operator |
— |
| vault-secrets-operator-fips |
affected |
chainguard |
vault-secrets-operator-fips |
— |
| vault-secrets-webhook |
affected |
wolfi |
vault-secrets-webhook |
— |
| vault-secrets-webhook |
affected |
chainguard |
vault-secrets-webhook |
— |
| verticadb-operator |
affected |
chainguard |
verticadb-operator |
— |
| verticadb-operator |
affected |
wolfi |
verticadb-operator |
— |
| verticadb-operator-fips |
affected |
chainguard |
verticadb-operator-fips |
— |
| wal-g |
affected |
wolfi |
wal-g |
— |
| wal-g |
affected |
chainguard |
wal-g |
— |
| weaviate |
affected |
wolfi |
weaviate |
— |
| weaviate |
affected |
chainguard |
weaviate |
— |
| zot |
affected |
chainguard |
zot |
— |
| zot |
affected |
wolfi |
zot |
— |
Open SourceEPSS > 79%CRITICAL2022-02-12
DEBIAN-CVE-2022-0306
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0289
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-08
In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2021-39675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-08
CVEs:CVE-2021-39675
Open SourceCoalition ESS < 30%2022-02-17
Panic on inputs with large exponents in math/big
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-17
Data race and crash in net/http
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-17
Infinite loop when decoding inputs in encoding/xml
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0290
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%2022-02-17
Certificate verification error on Windows in crypto/x509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-23
Unauthenticated control plane denial of service attack in Istio
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-23
Unauthenticated control plane denial of service attack in Istio
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cert-manager-istio-csr |
affected |
chainguard |
cert-manager-istio-csr |
— |
| cert-manager-istio-csr |
affected |
wolfi |
cert-manager-istio-csr |
— |
| cert-manager-istio-csr-fips |
affected |
chainguard |
cert-manager-istio-csr-fips |
— |
| istio |
affected |
istio.io |
istio.io/istio |
— |
| istio-cni-1.21 |
affected |
wolfi |
istio-cni-1.21 |
— |
| istio-cni-1.21 |
affected |
chainguard |
istio-cni-1.21 |
— |
| istio-cni-1.22 |
affected |
chainguard |
istio-cni-1.22 |
— |
| istio-cni-1.22 |
affected |
wolfi |
istio-cni-1.22 |
— |
| istio-fips-1.21 |
affected |
chainguard |
istio-fips-1.21 |
— |
| istio-operator-1.20 |
affected |
wolfi |
istio-operator-1.20 |
— |
| istio-operator-1.20 |
affected |
chainguard |
istio-operator-1.20 |
— |
| istio-operator-1.21 |
affected |
chainguard |
istio-operator-1.21 |
— |
| istio-operator-1.21 |
affected |
wolfi |
istio-operator-1.21 |
— |
| istio-operator-1.22 |
affected |
wolfi |
istio-operator-1.22 |
— |
| istio-operator-1.22 |
affected |
chainguard |
istio-operator-1.22 |
— |
| istio-pilot-agent-1.21 |
affected |
chainguard |
istio-pilot-agent-1.21 |
— |
| istio-pilot-agent-1.21 |
affected |
wolfi |
istio-pilot-agent-1.21 |
— |
| istio-pilot-agent-1.22 |
affected |
wolfi |
istio-pilot-agent-1.22 |
— |
| istio-pilot-agent-1.22 |
affected |
chainguard |
istio-pilot-agent-1.22 |
— |
| istio-pilot-discovery-1.21 |
affected |
chainguard |
istio-pilot-discovery-1.21 |
— |
| istio-pilot-discovery-1.21 |
affected |
wolfi |
istio-pilot-discovery-1.21 |
— |
| istio-pilot-discovery-1.22 |
affected |
wolfi |
istio-pilot-discovery-1.22 |
— |
| istio-pilot-discovery-1.22 |
affected |
chainguard |
istio-pilot-discovery-1.22 |
— |
| kgateway-2.3 |
affected |
chainguard |
kgateway-2.3 |
— |
| kgateway-2.4 |
affected |
chainguard |
kgateway-2.4 |
— |
| kgateway-fips-2.3 |
affected |
chainguard |
kgateway-fips-2.3 |
— |
| kgateway-fips-2.4 |
affected |
chainguard |
kgateway-fips-2.4 |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-22
Unauthenticated control plane denial of service attack in Istio
CVEs:CVE-2022-23635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-22
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which resu...
CVEs:CVE-2022-23635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
Microsoft Edge (Chromium-based) Tampering Vulnerability
CVEs:CVE-2022-23261
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-04
CVEs:CVE-2022-23261
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0100
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-12
DEBIAN-CVE-2022-0115
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-12
DEBIAN-CVE-2022-0117
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-15
Cryptographic Issues in ECK
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| elastic/cloud-on-k8s |
affected |
github.com |
github.com/elastic/cloud-on-k8s |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-15
Cryptographic Issues in ECK
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| elastic/cloud-on-k8s |
affected |
github.com |
github.com/elastic/cloud-on-k8s |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0104
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0096
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-12
DEBIAN-CVE-2022-0109
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-15
Directory traversal in Kubernetes Secrets Store CSI Driver
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| secrets-store-csi-driver |
affected |
sigs.k8s.io |
sigs.k8s.io/secrets-store-csi-driver |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-15
Directory traversal in Kubernetes Secrets Store CSI Driver
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| secrets-store-csi-driver |
affected |
sigs.k8s.io |
sigs.k8s.io/secrets-store-csi-driver |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-15
Directory traversal in sigs.k8s.io/secrets-store-csi-driver
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| secrets-store-csi-driver |
affected |
sigs.k8s.io |
sigs.k8s.io/secrets-store-csi-driver |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-12
DEBIAN-CVE-2022-0102
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-12
DEBIAN-CVE-2022-0114
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0106
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0105
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0103
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-23262
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-04
CVEs:CVE-2022-23262
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0099
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-123
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-68
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-68
CVEs:CVE-2022-23559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_size` and `lookup_size` are products of values provided by the user. Henc...
CVEs:CVE-2022-23559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Integer overflow in TFLite
CVEs:CVE-2022-23559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-15
Istio may not check inbound TCP connections against istio-policy
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-15
Istio may not check inbound TCP connections against istio-policy
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-12
DEBIAN-CVE-2022-0116
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-07
`CHECK`-failures during Grappler's `IsSimplifiableReshape` in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-07
`CHECK`-failures during Grappler's `IsSimplifiableReshape` in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-145
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-90
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-90
CVEs:CVE-2022-23581
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
`CHECK`-failures during Grappler's `IsSimplifiableReshape` in Tensorflow
CVEs:CVE-2022-23581
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `IsSimplifiableReshape` would trigger `CHECK` failures. The fix will be included...
CVEs:CVE-2022-23581
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-12
DEBIAN-CVE-2022-0118
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-15
Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0608
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-15
CVEs:CVE-2022-0608
Open SourceCoalition ESS < 30%MEDIUM2022-02-12
DEBIAN-CVE-2022-0112
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflows in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflows in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
Null pointer dereference in Grappler's `IsConstant`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
Null pointer dereference in Grappler's `IsConstant`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-153
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-98
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow can trigger a null pointer dereference. There are 2 places where this can occur, for the same malicious alteration of a `SavedModel` file...
CVEs:CVE-2022-23589
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
Null pointer dereference in Grappler's `IsConstant`
CVEs:CVE-2022-23589
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-98
CVEs:CVE-2022-23589
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-76
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Integer overflows in Tensorflow
CVEs:CVE-2022-23567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementations of `Sparse*Cwise*` ops are vulnerable to integer overflows. These can be used to trigger large allocations (so, OOM based denial of service) or `CHECK`-fails when building new...
CVEs:CVE-2022-23567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-76
CVEs:CVE-2022-23567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-12
DEBIAN-CVE-2022-0110
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-11
DEBIAN-CVE-2021-4101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Null-dereference in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Null-dereference in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Crash when type cannot be specialized in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Crash when type cannot be specialized in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
Memory leak in decoding PNG images
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
Memory leak in decoding PNG images
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-134
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-136
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-149
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-79
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-81
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-94
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Null-dereference in Tensorflow
CVEs:CVE-2022-23570
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, TensorFlow might do a null-dereference if attributes of some mutable arguments to some operations are missing from the proto. This is guarded by a `DCHECK`. ...
CVEs:CVE-2022-23570
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-79
CVEs:CVE-2022-23570
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Crash when type cannot be specialized in Tensorflow
CVEs:CVE-2022-23572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a type during shape inference. This case is covered by the `DCHECK` function however, `DCHECK` is a no-op in production builds and an as...
CVEs:CVE-2022-23572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-81
CVEs:CVE-2022-23572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
Memory leak in decoding PNG images
CVEs:CVE-2022-23585
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. When decoding PNG images TensorFlow can produce a memory leak if the image is invalid. After calling `png::CommonInitDecode(..., &decode)`, the `decode` value contains allocated buffers which can...
CVEs:CVE-2022-23585
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-94
CVEs:CVE-2022-23585
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-18
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a...
CVEs:CVE-2022-0451
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dart_software_development_kit |
affected |
dart |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Crash due to erroneous `StatusOr` in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Crash due to erroneous `StatusOr` in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-154
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-99
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Crash due to erroneous `StatusOr` in TensorFlow
CVEs:CVE-2022-23590
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-99
CVEs:CVE-2022-23590
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. A `GraphDef` from a TensorFlow `SavedModel` can be maliciously altered to cause a TensorFlow process to crash due to encountering a `StatusOr` value that is an error and forcibly extracting the v...
CVEs:CVE-2022-23590
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
Out of bounds memory access in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0470
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0470
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0467
GoogleCoalition ESS < 30%HIGH2022-02-02
Inappropriate implementation in Pointer Lock in Google Chrome on Windows prior to 98.0.4758.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2022-0467
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0107
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0098
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Out of bounds write in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Out of bounds write in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-130
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-75
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-75
CVEs:CVE-2022-23566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. TensorFlow is vulnerable to a heap OOB write in `Grappler`. The `set_output` function writes to an array at the specified index. Hence, this gives a malicious user a write primitive. The fix will...
CVEs:CVE-2022-23566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Out of bounds write in Tensorflow
CVEs:CVE-2022-23566
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0454
GoogleCoalition ESS < 30%CRITICAL2022-02-02
Heap buffer overflow in ANGLE in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0454
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-151
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-96
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-96
CVEs:CVE-2022-23587
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow is vulnerable to an integer overflow during cost estimation for crop and resize. Since the cropping parameters are user controlled, a mal...
CVEs:CVE-2022-23587
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Integer overflow in TensorFlow
CVEs:CVE-2022-23587
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0097
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
`CHECK`-failures in binary ops in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
`CHECK`-failures in binary ops in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-147
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-92
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
`CHECK`-failures in binary ops in Tensorflow
CVEs:CVE-2022-23583
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that any binary op would trigger `CHECK` failures. This occurs when the protobuf part corresponding to the tensor ar...
CVEs:CVE-2022-23583
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-92
CVEs:CVE-2022-23583
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-12
DEBIAN-CVE-2022-0311
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-02
CVEs:CVE-2022-0462
GoogleCoalition ESS < 30%MEDIUM2022-02-02
Inappropriate implementation in Scroll in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-0462
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
`CHECK`-fails due to attempting to build a reference tensor
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
`CHECK`-fails due to attempting to build a reference tensor
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-152
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-97
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that Grappler optimizer would attempt to build a tensor using a reference `dtype`. This would result in a crash due ...
CVEs:CVE-2022-23588
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-97
CVEs:CVE-2022-23588
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
`CHECK`-fails due to attempting to build a reference tensor
CVEs:CVE-2022-23588
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Segfault in `simplifyBroadcast` in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Segfault in `simplifyBroadcast` in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-102
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-157
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-157
CVEs:CVE-2022-23593
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. The `simplifyBroadcast` function in the MLIR-TFRT infrastructure in TensorFlow is vulnerable to a segfault (hence, denial of service), if called with scalar shapes. If all shapes are scalar, then...
CVEs:CVE-2022-23593
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Segfault in `simplifyBroadcast` in Tensorflow
CVEs:CVE-2022-23593
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-02
CVEs:CVE-2022-0461
GoogleCoalition ESS < 30%MEDIUM2022-02-02
Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass iframe sandbox via a crafted HTML page.
CVEs:CVE-2022-0461
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Out of bounds read in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Out of bounds read in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-156
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. TensorFlow's type inference can cause a heap out of bounds read as the bounds checking is done in a `DCHECK` (which is a no-op during production). An attacker can control the `input_idx` variable...
CVEs:CVE-2022-23592
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Out of bounds read in Tensorflow
CVEs:CVE-2022-23592
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-156
CVEs:CVE-2022-23592
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-12
DEBIAN-CVE-2022-0113
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-23
DEBIAN-CVE-2021-4070
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-v2ray-core |
affected |
Debian:11 |
golang-v2ray-core |
— |
| golang-v2ray-core |
affected |
Debian:12 |
golang-v2ray-core |
— |
| golang-v2ray-core |
affected |
Debian:13 |
golang-v2ray-core |
— |
| golang-v2ray-core |
affected |
Debian:14 |
golang-v2ray-core |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
Type confusion leading to segfault in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
Type confusion leading to segfault in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-110
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-55
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-55
CVEs:CVE-2022-21731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
Type confusion leading to segfault in Tensorflow
CVEs:CVE-2022-21731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ConcatV2` can be used to trigger a denial of service attack via a segfault caused by a type confusion. The `axis` argument is translated into `concat_di...
CVEs:CVE-2022-21731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Out of bounds read and write in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
— |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Out of bounds read and write in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-138
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-83
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. There is a typo in TensorFlow's `SpecializeType` which results in heap OOB read/write. Due to a typo, `arg` is initialized to the `i`th mutable argument in a loop where the loop index is `j`. Hen...
CVEs:CVE-2022-23574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-83
CVEs:CVE-2022-23574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Out of bounds read and write in Tensorflow
CVEs:CVE-2022-23574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.
CVEs:CVE-2022-0464
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0464
GoogleCoalition ESS < 30%CRITICAL2022-02-15
Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0603
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-15
CVEs:CVE-2022-0603
GoogleCoalition ESS < 30%CRITICAL2022-02-15
Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0606
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-15
CVEs:CVE-2022-0606
GoogleCoalition ESS < 30%HIGH2022-02-15
CVEs:CVE-2022-0607
GoogleCoalition ESS < 30%CRITICAL2022-02-15
Use after free in GPU in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0607
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
`CHECK`-failures during Grappler's `SafeToRemoveIdentity` in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
`CHECK`-failures during Grappler's `SafeToRemoveIdentity` in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-10
Memory exhaustion in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-10
Memory exhaustion in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Division by zero in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Division by zero in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-07
Abort caused by allocating a vector that is too large in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-07
Abort caused by allocating a vector that is too large in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-143
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-144
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-88
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-89
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
`CHECK`-failures during Grappler's `SafeToRemoveIdentity` in Tensorflow
CVEs:CVE-2022-23579
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-88
CVEs:CVE-2022-23579
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `SafeToRemoveIdentity` would trigger `CHECK` failures. The fix will be included ...
CVEs:CVE-2022-23579
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector based on a value from a tensor controlled by the user. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this co...
CVEs:CVE-2022-23580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-89
CVEs:CVE-2022-23580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
Abort caused by allocating a vector that is too large in Tensorflow
CVEs:CVE-2022-23580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-120
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-65
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
Division by zero in TFLite
CVEs:CVE-2022-21741
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-65
CVEs:CVE-2022-21741
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. ### Impact An attacker can craft a TFLite model that would trigger a division by zero in the implementation of depthwise convolutions. The parameters of the convolution can be user controlled and...
CVEs:CVE-2022-21741
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-112
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-57
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-03
PYSEC-2022-57
CVEs:CVE-2022-21733
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `StringNGrams` can be used to trigger a denial of service attack by causing an out of memory condition after an integer overflow. We are missing a validation on `pad_witdh` ...
CVEs:CVE-2022-21733
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Memory exhaustion in Tensorflow
CVEs:CVE-2022-21733
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Out of bounds read in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Out of bounds read in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-105
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-50
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
Out of bounds read in Tensorflow
CVEs:CVE-2022-21726
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-50
CVEs:CVE-2022-21726
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `Dequantize` does not fully validate the value of `axis` and can result in heap OOB accesses. The `axis` argument can be `-1` (the default value for the optional argument) o...
CVEs:CVE-2022-21726
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Out of bounds read in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Out of bounds read in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-109
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-54
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
Out of bounds read in Tensorflow
CVEs:CVE-2022-21730
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-54
CVEs:CVE-2022-21730
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalAvgPoolGrad` does not consider cases where the input tensors are invalid allowing an attacker to read from outside of bounds of heap. The fix will be included in ...
CVEs:CVE-2022-21730
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow in TFLite array creation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow in TFLite array creation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-67
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in `TfLiteIntArrayCreate`. The `TfLiteIntArrayGetSizeInBytes` returns an `int` instead of a `size_t. An attacker can cont...
CVEs:CVE-2022-23558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-67
CVEs:CVE-2022-23558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Integer overflow in TFLite array creation
CVEs:CVE-2022-23558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-12
DEBIAN-CVE-2022-0310
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflows in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflows in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Multiple `CHECK`-fails in `function.cc` in TensowFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Multiple `CHECK`-fails in `function.cc` in TensowFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-150
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-95
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that assertions in `function.cc` would be falsified and crash the Python interpreter. The fix will be included in Te...
CVEs:CVE-2022-23586
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-95
CVEs:CVE-2022-23586
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Multiple `CHECK`-fails in `function.cc` in TensowFlow
CVEs:CVE-2022-23586
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-132
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-77
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Integer overflows in Tensorflow
CVEs:CVE-2022-23568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-77
CVEs:CVE-2022-23568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `AddManySparseToTensorsMap` is vulnerable to an integer overflow which results in a `CHECK`-fail when building new `TensorShape` objects (so, an assert failure based denial ...
CVEs:CVE-2022-23568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Stack overflow in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Stack overflow in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-100
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-155
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Stack overflow in TensorFlow
CVEs:CVE-2022-23591
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. The `GraphDef` format in TensorFlow does not allow self recursive functions. The runtime assumes that this invariant is satisfied. However, a `GraphDef` containing a fragment such as the followin...
CVEs:CVE-2022-23591
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-155
CVEs:CVE-2022-23591
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Heap overflow in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
— |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Heap overflow in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-119
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-64
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Heap overflow in Tensorflow
CVEs:CVE-2022-21740
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-64
CVEs:CVE-2022-21740
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` is vulnerable to a heap overflow. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow...
CVEs:CVE-2022-21740
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-12
DEBIAN-CVE-2022-0111
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0459
GoogleCoalition ESS < 30%HIGH2022-02-02
Use after free in Screen Capture in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process and convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted ...
CVEs:CVE-2022-0459
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-23263
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-04
CVEs:CVE-2022-23263
Open SourceCoalition ESS < 30%HIGH2022-02-10
`CHECK`-failures in `TensorByteSize` in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
`CHECK`-failures in `TensorByteSize` in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-10
Integer overflow in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-10
Integer overflow in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
Null-dereference in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
Null-dereference in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
Division by zero in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
Division by zero in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
`CHECK`-failures in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
`CHECK`-failures in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-10
Overflow and uncaught divide by zero in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-10
Overflow and uncaught divide by zero in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-10
Division by zero in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-10
Division by zero in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Null pointer dereference in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Null pointer dereference in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow leading to crash in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow leading to crash in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Assertion failure based denial of service in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Assertion failure based denial of service in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-139
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-141
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-146
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-84
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-86
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-91
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-86
CVEs:CVE-2022-23577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Null-dereference in Tensorflow
CVEs:CVE-2022-23577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. The implementation of `GetInitOp` is vulnerable to a crash caused by dereferencing a null pointer. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow ...
CVEs:CVE-2022-23577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-84
CVEs:CVE-2022-23575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Integer overflow in Tensorflow
CVEs:CVE-2022-23575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateTensorSize` is vulnerable to an integer overflow if an attacker can create an operation which would involve a tensor with large enough number...
CVEs:CVE-2022-23575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that `TensorByteSize` would trigger `CHECK` failures. `TensorShape` constructor throws a `CHECK`-fail if shape is pa...
CVEs:CVE-2022-23582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-91
CVEs:CVE-2022-23582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
`CHECK`-failures in `TensorByteSize` in Tensorflow
CVEs:CVE-2022-23582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-116
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-117
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-118
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-61
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-62
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-63
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
Assertion failure based denial of service in Tensorflow
CVEs:CVE-2022-21737
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-61
CVEs:CVE-2022-21737
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `*Bincount` operations allows malicious users to cause denial of service by passing in arguments which would trigger a `CHECK`-fail. There are several conditions that the in...
CVEs:CVE-2022-21737
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-62
CVEs:CVE-2022-21738
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Integer overflow leading to crash in Tensorflow
CVEs:CVE-2022-21738
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` can be made to crash a TensorFlow process by an integer overflow whose result is then used in a memory allocation. The fix will be included in Tens...
CVEs:CVE-2022-21738
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-104
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-108
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-113
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-114
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-49
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-53
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-58
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-59
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-63
CVEs:CVE-2022-21739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `QuantizedMaxPool` has an undefined behavior where user controlled inputs can trigger a reference binding to null pointer. The fix will be included in TensorFlow 2.8.0. We w...
CVEs:CVE-2022-21739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
Null pointer dereference in TensorFlow
CVEs:CVE-2022-21739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `MapStage` is vulnerable a `CHECK`-fail if the key tensor is not a scalar. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2....
CVEs:CVE-2022-21734
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
`CHECK`-failures in Tensorflow
CVEs:CVE-2022-21734
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-58
CVEs:CVE-2022-21734
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
Division by zero in Tensorflow
CVEs:CVE-2022-21735
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalMaxPool` can be made to crash a TensorFlow process via a division by 0. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on Tenso...
CVEs:CVE-2022-21735
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-59
CVEs:CVE-2022-21735
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Overflow and uncaught divide by zero in Tensorflow
CVEs:CVE-2022-21729
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-53
CVEs:CVE-2022-21729
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `UnravelIndex` is vulnerable to a division by zero caused by an integer overflow bug. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on Te...
CVEs:CVE-2022-21729
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The estimator for the cost of some convolution operations can be made to execute a division by 0. The function fails to check that the stride argument is strictly positive. Hence, the fix is to a...
CVEs:CVE-2022-21725
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-03
Division by zero in Tensorflow
CVEs:CVE-2022-21725
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-03
PYSEC-2022-49
CVEs:CVE-2022-21725
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-10
Integer overflow in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-10
Integer overflow in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-140
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-85
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-85
CVEs:CVE-2022-23576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Integer overflow in Tensorflow
CVEs:CVE-2022-23576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateOutputSize` is vulnerable to an integer overflow if an attacker can create an operation which would involve tensors with large enough number ...
CVEs:CVE-2022-23576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
Null pointer dereference in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
Null pointer dereference in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-103
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-158
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
Null pointer dereference in TensorFlow
CVEs:CVE-2022-23595
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-158
CVEs:CVE-2022-23595
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. When building an XLA compilation cache, if default settings are used, TensorFlow triggers a null pointer dereference. In the default scenario, all devices are allowed, so `flr->config_proto` is `...
CVEs:CVE-2022-23595
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-15
Inappropriate implementation in Gamepad API in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0610
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-15
CVEs:CVE-2022-0610
GoogleCoalition ESS < 30%CRITICAL2022-02-02
CVEs:CVE-2022-0452
GoogleCoalition ESS < 30%CRITICAL2022-02-02
Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2022-0452
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-02
Use after free in Reader Mode in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0453
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0453
GoogleCoalition ESS < 30%HIGH2022-02-02
Type confusion in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0457
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0457
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0460
GoogleCoalition ESS < 30%CRITICAL2022-02-02
Use after free in Window Dialogue in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0460
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-09
Incorrect Permission Assignment for Critical Resource in CRI-O
CVEs:CVE-2022-0532
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cri-o/cri-o |
affected |
github.com |
github.com/cri-o/cri-o |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-09
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork k...
CVEs:CVE-2022-0532
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cri-o |
affected |
kubernetes |
— |
— |
| openshift_container_platform |
affected |
redhat |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
Memory exhaustion in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-10
Memory exhaustion in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-111
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-56
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
Memory exhaustion in Tensorflow
CVEs:CVE-2022-21732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `ThreadPoolHandle` can be used to trigger a denial of service attack by allocating too much memory. This is because the `num_threads` argument is only checked to not be nega...
CVEs:CVE-2022-21732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-03
PYSEC-2022-56
CVEs:CVE-2022-21732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Division by zero in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Division by zero in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-121
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-66
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would trigger a division by zero in `BiasAndClamp` implementation. There is no check that the `bias_size` is non zero. The fix will be included in Tensor...
CVEs:CVE-2022-23557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-66
CVEs:CVE-2022-23557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Division by zero in TFLite
CVEs:CVE-2022-23557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Uninitialized variable access in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Uninitialized variable access in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-82
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined behavior. The implementation has a check that the left hand side of the ...
CVEs:CVE-2022-23573
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Uninitialized variable access in Tensorflow
CVEs:CVE-2022-23573
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-82
CVEs:CVE-2022-23573
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0465
GoogleCoalition ESS < 30%HIGH2022-02-02
Use after free in Extensions in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via user interaction.
CVEs:CVE-2022-0465
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Undefined behavior in `SparseTensorSliceDataset`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Undefined behavior in `SparseTensorSliceDataset`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-115
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-60
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-60
CVEs:CVE-2022-21736
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseTensorSliceDataset` has an undefined behavior: under certain condition it can be made to dereference a `nullptr` value. The 3 input arguments to `SparseTensorSliceDat...
CVEs:CVE-2022-21736
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
Undefined behavior in `SparseTensorSliceDataset`
CVEs:CVE-2022-21736
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-12
DEBIAN-CVE-2022-0300
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-12
DEBIAN-CVE-2022-0304
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-12
DEBIAN-CVE-2022-0120
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-11
DEBIAN-CVE-2021-4099
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-11
DEBIAN-CVE-2021-4100
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0458
GoogleCoalition ESS < 30%CRITICAL2022-02-02
Use after free in Thumbnail Tab Strip in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0458
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Use after free in `DecodePng` kernel
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Use after free in `DecodePng` kernel
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-148
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-93
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-93
CVEs:CVE-2022-23584
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a use after free behavior when decoding PNG images. After `png::CommonFreeDecode(&decode)` gets called, the values of `decode.width` and `decode.height` are in an unspe...
CVEs:CVE-2022-23584
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Use after free in `DecodePng` kernel
CVEs:CVE-2022-23584
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0468
GoogleCoalition ESS < 30%CRITICAL2022-02-02
Use after free in Payments in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0468
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-02
Use after free in Cast in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific interactions to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0469
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0469
Open SourceCoalition ESS < 30%MEDIUM2022-02-10
Memory leak in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-10
Memory leak in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-142
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-87
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
Memory leak in Tensorflow
CVEs:CVE-2022-23578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. If a graph node is invalid, TensorFlow can leak memory in the implementation of `ImmutableExecutorState::Initialize`. Here, we set `item->kernel` to `nullptr` but it is a simple `OpKernel*` point...
CVEs:CVE-2022-23578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-04
PYSEC-2022-87
CVEs:CVE-2022-23578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.
CVEs:CVE-2022-0463
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-02
CVEs:CVE-2022-0463
GoogleCoalition ESS < 30%2022-02-08
CVEs:CVE-2021-39665
Open SourceCoalition ESS < 30%HIGH2022-02-08
In checkSpsUpdated of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation....
CVEs:CVE-2021-39665
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-11
CVEs:CVE-2022-23264
Open SourceCoalition ESS < 30%MEDIUM2022-02-08
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2022-23264
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-106
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-51
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `Dequantize` is vulnerable to an integer overflow weakness. The `axis` argument can be `-1` (the default value for the optional argument) or any other po...
CVEs:CVE-2022-21727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-51
CVEs:CVE-2022-21727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Integer overflow in Tensorflow
CVEs:CVE-2022-21727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-02
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2022-0455
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-02
CVEs:CVE-2022-0455
GoogleCoalition ESS < 30%HIGH2022-02-15
CVEs:CVE-2022-0604
GoogleCoalition ESS < 30%HIGH2022-02-15
Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0604
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-11
DEBIAN-CVE-2021-4098
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-12
DEBIAN-CVE-2022-0292
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-02
Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2022-0466
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-02
CVEs:CVE-2022-0466
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Integer overflow in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-08
CVEs:CVE-2021-39616
Open SourceCoalition ESS < 30%HIGH2022-02-08
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438
CVEs:CVE-2021-39616
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-126
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-71
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. These can trigger undefined behavior or, in some scenarios, extremely large allocations. The fix will be included in TensorFlow 2.8.0...
CVEs:CVE-2022-23562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Integer overflow in Tensorflow
CVEs:CVE-2022-23562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-71
CVEs:CVE-2022-23562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%2022-02-01
ASB-A-204686438
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-12
DEBIAN-CVE-2022-0309
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-02-15
CVEs:CVE-2022-0605
GoogleCoalition ESS < 30%HIGH2022-02-15
Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a cra...
CVEs:CVE-2022-0605
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-28
CVEs:CVE-2021-25081
GoogleCoalition ESS < 30%MEDIUM2022-02-28
The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack
CVEs:CVE-2021-25081
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| wp_google_map |
affected |
wpgooglemap |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-08
ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily m...
CVEs:CVE-2021-39658
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-08
CVEs:CVE-2021-39658
GoogleCoalition ESS < 30%2022-02-01
ASB-A-207479207
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Out of bounds write in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Out of bounds write in TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-125
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-70
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Out of bounds write in TFLite
CVEs:CVE-2022-23561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause a write outside of bounds of an array in TFLite. In fact, the attacker can override the linked list used by the memory allocator. This can be...
CVEs:CVE-2022-23561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-70
CVEs:CVE-2022-23561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-12
DEBIAN-CVE-2022-0302
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-08
In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2021-39671
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-08
CVEs:CVE-2021-39671
Open SourceCoalition ESS < 30%HIGH2022-02-09
`CHECK`-failures in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
`CHECK`-failures in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Reachable Assertion in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Reachable Assertion in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-129
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-74
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-80
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
`CHECK`-failures in Tensorflow
CVEs:CVE-2022-23565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-74
CVEs:CVE-2022-23565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. An attacker can trigger denial of service via assertion failure by altering a `SavedModel` on disk such that `AttrDef`s of some operation are duplicated. The fix will be included in TensorFlow 2....
CVEs:CVE-2022-23565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based on user controlled arguments, if the tensors have an invalid `dtype` ...
CVEs:CVE-2022-23571
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-80
CVEs:CVE-2022-23571
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Reachable Assertion in Tensorflow
CVEs:CVE-2022-23571
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Reachable Assertion in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-09
Reachable Assertion in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-73
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Reachable Assertion in Tensorflow
CVEs:CVE-2022-23564
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. When decoding a resource handle tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based on user controlled arguments. This allows attackers t...
CVEs:CVE-2022-23564
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-73
CVEs:CVE-2022-23564
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
`CHECK`-fails when building invalid tensor shapes in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
`CHECK`-fails when building invalid tensor shapes in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-133
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
PYSEC-2022-78
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
`CHECK`-fails when building invalid tensor shapes in Tensorflow
CVEs:CVE-2022-23569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-03
Tensorflow is an Open Source Machine Learning Framework. Multiple operations in TensorFlow can be used to trigger a denial of service via `CHECK`-fails (i.e., assertion failures). This is similar to TFSA-2021-198 and has similar fixes. We have patched ...
CVEs:CVE-2022-23569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-03
PYSEC-2022-78
CVEs:CVE-2022-23569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-12
DEBIAN-CVE-2022-0301
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-11
Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.
CVEs:CVE-2022-23425
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-11
CVEs:CVE-2022-23425
GoogleCoalition ESS < 30%HIGH2022-02-11
CVEs:CVE-2021-39677
Open SourceCoalition ESS < 30%HIGH2022-02-11
In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘zero’ in size.Product: AndroidVersions: Android-11Android ID: A-205097028
CVEs:CVE-2021-39677
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-11
Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of service attack on a victim's devices.
CVEs:CVE-2022-24925
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-11
CVEs:CVE-2022-24925
GoogleCoalition ESS < 30%2022-02-01
ASB-A-204904989
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2022-02-01
ASB-A-204905255
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2022-02-01
ASB-A-204905325
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-11
TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/go-tpm |
affected |
github.com |
github.com/google/go-tpm |
— |
GoogleCoalition ESS < 30%CRITICAL2022-02-11
TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/go-tpm |
affected |
github.com |
github.com/google/go-tpm |
— |
GoogleCoalition ESS < 30%HIGH2022-02-11
CVEs:CVE-2022-23428
Open SourceCoalition ESS < 30%CRITICAL2022-02-11
An improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
CVEs:CVE-2022-23428
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-08
In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is no...
CVEs:CVE-2021-39663
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2021-39663
Open SourceCoalition ESS < 30%HIGH2022-02-08
In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVEs:CVE-2021-39674
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2021-39674
Open SourceCoalition ESS < 30%HIGH2022-02-09
In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126814; Issue ID:...
CVEs:CVE-2022-20044
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-09
CVEs:CVE-2022-20044
Open SourceCoalition ESS < 30%HIGH2022-02-09
In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126820; Issue ID:...
CVEs:CVE-2022-20045
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-09
CVEs:CVE-2022-20045
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2022-20025
Open SourceCoalition ESS < 30%HIGH2022-02-08
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0612683...
CVEs:CVE-2022-20025
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-08
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0612682...
CVEs:CVE-2022-20026
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2022-20026
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2022-20027
Open SourceCoalition ESS < 30%HIGH2022-02-08
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0612682...
CVEs:CVE-2022-20027
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-08
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0619866...
CVEs:CVE-2022-20028
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2022-20028
GoogleCoalition ESS < 30%HIGH2022-02-01
ASB-A-209700749
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-02-01
ASB-A-209702508
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-02-01
ASB-A-209702509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-02-01
ASB-A-209705229
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2022-02-01
PUB-A-195752523
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2022-02-01
PUB-A-195752651
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Out of bounds read in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Out of bounds read in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Out of bounds read in Tensorflow
CVEs:CVE-2022-23594
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. The TFG dialect of TensorFlow (MLIR) makes several assumptions about the incoming `GraphDef` before converting it to the MLIR-based dialect. If an attacker changes the `SavedModel` format on disk...
CVEs:CVE-2022-23594
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Out of bounds read in Tensorflow
CVEs:CVE-2022-23594
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%HIGH2022-02-09
CVEs:CVE-2022-20041
Open SourceCoalition ESS < 30%HIGH2022-02-09
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP...
CVEs:CVE-2022-20041
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP...
CVEs:CVE-2022-20043
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-09
CVEs:CVE-2022-20043
GoogleCoalition ESS < 30%2022-02-09
CVEs:CVE-2022-20030
Open SourceCoalition ESS < 30%HIGH2022-02-09
In vow driver, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS058377...
CVEs:CVE-2022-20030
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-08
In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings of app usage due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges ...
CVEs:CVE-2021-39619
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2021-39619
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2021-39672
Open SourceCoalition ESS < 30%HIGH2022-02-08
In fastboot, there is a possible secure boot bypass due to a configuration error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Version...
CVEs:CVE-2021-39672
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%NONE2022-02-01
ASB-A-202018701
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2021-39668
Open SourceCoalition ESS < 30%HIGH2022-02-08
In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. Us...
CVEs:CVE-2021-39668
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-26
Uncontrolled Resource Consumption in github.com/google/fscrypt
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/fscrypt |
affected |
github.com |
github.com/google/fscrypt |
— |
GoogleCoalition ESS < 30%HIGH2022-02-26
Uncontrolled Resource Consumption in github.com/google/fscrypt
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/fscrypt |
affected |
github.com |
github.com/google/fscrypt |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-25
Uncontrolled Resource Consumption in github.com/google/fscrypt
CVEs:CVE-2022-25326
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/fscrypt |
affected |
github.com |
github.com/google/fscrypt |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-25
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscry...
CVEs:CVE-2022-25326
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fscrypt |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-11
Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.
CVEs:CVE-2022-22292
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-11
CVEs:CVE-2022-22292
GoogleCoalition ESS < 30%HIGH2022-02-09
CVEs:CVE-2022-20040
Open SourceCoalition ESS < 30%HIGH2022-02-09
In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. ...
CVEs:CVE-2022-20040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-08
CVEs:CVE-2021-39664
Open SourceCoalition ESS < 30%MEDIUM2022-02-08
In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure when parsing an APK file with no additional execution privileges needed. User interaction is...
CVEs:CVE-2021-39664
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
In cmdq driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05747150; I...
CVEs:CVE-2022-20029
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-09
CVEs:CVE-2022-20029
GoogleCoalition ESS < 30%2022-02-09
CVEs:CVE-2022-20033
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
In camera driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862973;...
CVEs:CVE-2022-20033
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-09
CVEs:CVE-2022-20035
Open SourceCoalition ESS < 30%HIGH2022-02-09
In vcu driver, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171675; Issue ...
CVEs:CVE-2022-20035
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-08
In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...
CVEs:CVE-2021-39676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2021-39676
GoogleCoalition ESS < 30%2022-02-09
CVEs:CVE-2022-20042
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS061...
CVEs:CVE-2022-20042
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-09
CVEs:CVE-2022-20038
Open SourceCoalition ESS < 30%HIGH2022-02-09
In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183335; Is...
CVEs:CVE-2022-20038
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-09
CVEs:CVE-2022-20039
Open SourceCoalition ESS < 30%HIGH2022-02-09
In ccu driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183345; Issue ID...
CVEs:CVE-2022-20039
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
In fb driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05850708; Issue...
CVEs:CVE-2022-20031
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-09
CVEs:CVE-2022-20031
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...
CVEs:CVE-2022-20036
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-09
CVEs:CVE-2022-20036
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...
CVEs:CVE-2022-20037
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-09
CVEs:CVE-2022-20037
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...
CVEs:CVE-2022-20017
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-09
CVEs:CVE-2022-20017
GoogleCoalition ESS < 30%2022-02-11
CVEs:CVE-2022-23431
Open SourceCoalition ESS < 30%CRITICAL2022-02-11
An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
CVEs:CVE-2022-23431
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-11
CVEs:CVE-2022-23432
Open SourceCoalition ESS < 30%CRITICAL2022-02-11
An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
CVEs:CVE-2022-23432
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-11
CVEs:CVE-2021-39687
Open SourceCoalition ESS < 30%HIGH2022-02-11
In HandleTransactionIoEvent of actuator_driver.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2021-39687
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-01
PUB-A-204421047
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%LOW2022-02-11
PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
CVEs:CVE-2022-23999
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-02-11
CVEs:CVE-2022-23999
Open SourceCoalition ESS < 30%LOW2022-02-11
PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
CVEs:CVE-2022-24000
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-02-11
CVEs:CVE-2022-24000
Open SourceCoalition ESS < 30%HIGH2022-02-09
In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS...
CVEs:CVE-2022-20046
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-09
CVEs:CVE-2022-20046
Open SourceCoalition ESS < 30%HIGH2022-02-08
In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed....
CVEs:CVE-2021-39662
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2021-39662
GoogleCoalition ESS < 30%MEDIUM2022-02-26
User login denial of service in github.com/google/fscrypt
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/fscrypt |
affected |
github.com |
github.com/google/fscrypt |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-26
User login denial of service in github.com/google/fscrypt
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/fscrypt |
affected |
github.com |
github.com/google/fscrypt |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-25
User login denial of service in github.com/google/fscrypt
CVEs:CVE-2022-25327
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/fscrypt |
affected |
github.com |
github.com/google/fscrypt |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-25
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file th...
CVEs:CVE-2022-25327
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fscrypt |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-11
In TBD of TBD, there is a possible out of bounds read due to TBD. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAn...
CVEs:CVE-2021-39688
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-11
CVEs:CVE-2021-39688
Open SourceCoalition ESS < 30%MEDIUM2022-02-11
In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ...
CVEs:CVE-2021-0524
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-11
CVEs:CVE-2021-0524
GoogleCoalition ESS < 30%MEDIUM2022-02-08
CVEs:CVE-2021-39631
Open SourceCoalition ESS < 30%MEDIUM2022-02-08
In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functionality sets up the wrong security/privacy expectations due to a misleading message. This could lead to local information disclosure with no additional exec...
CVEs:CVE-2021-39631
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-08
In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2021-39666
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-08
CVEs:CVE-2021-39666
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2022-20024
Open SourceCoalition ESS < 30%HIGH2022-02-08
In system service, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS...
CVEs:CVE-2022-20024
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%NONE2022-02-01
ASB-A-209705228
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-01
PUB-A-206039140
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Insecure temporary file in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
Insecure temporary file in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-127
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
PYSEC-2022-72
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
PYSEC-2022-72
CVEs:CVE-2022-23563
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-02-04
Tensorflow is an Open Source Machine Learning Framework. In multiple places, TensorFlow uses `tempfile.mktemp` to create temporary files. While this is acceptable in testing, in utilities and libraries it is dangerous as a different process can create ...
CVEs:CVE-2022-23563
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-04
Insecure temporary file in Tensorflow
CVEs:CVE-2022-23563
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-02-11
Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device.
CVEs:CVE-2022-22291
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-11
CVEs:CVE-2022-22291
GoogleCoalition ESS < 30%2022-02-11
CVEs:CVE-2022-23426
Open SourceCoalition ESS < 30%MEDIUM2022-02-11
A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.
CVEs:CVE-2022-23426
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-11
PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent.
CVEs:CVE-2022-23427
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-11
CVEs:CVE-2022-23427
GoogleCoalition ESS < 30%2022-02-11
CVEs:CVE-2022-23429
Open SourceCoalition ESS < 30%HIGH2022-02-11
An improper boundary check in audio hal service prior to SMR Feb-2022 Release 1 allows attackers to read invalid memory and it leads to application crash.
CVEs:CVE-2022-23429
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-02-09
In vow driver, there is a possible memory corruption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05852822; Issue ID: AL...
CVEs:CVE-2022-20032
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-09
CVEs:CVE-2022-20032
GoogleCoalition ESS < 30%2022-02-11
CVEs:CVE-2022-24001
Open SourceCoalition ESS < 30%HIGH2022-02-11
Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.
CVEs:CVE-2022-24001
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-01
Go-Attestation Improper Input Validation with attacker-controlled TPM Quote
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/go-attestation |
affected |
github.com |
github.com/google/go-attestation |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-01
Go-Attestation Improper Input Validation with attacker-controlled TPM Quote
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/go-attestation |
affected |
github.com |
github.com/google/go-attestation |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-01
Go-Attestation Improper Input Validation with attacker-controlled TPM Quote
CVEs:CVE-2022-0317
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/go-attestation |
affected |
github.com |
github.com/google/go-attestation |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-01
An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-formed Quote over no/some PCRs, causing AKPublic.Verify to succeed despite the inconsistency. Subsequent use of the same set of PCR va...
CVEs:CVE-2022-0317
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go-attestation |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-02-09
CVEs:CVE-2022-20034
Open SourceCoalition ESS < 30%MEDIUM2022-02-09
In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges n...
CVEs:CVE-2022-20034
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-02-08
CVEs:CVE-2021-39669
Open SourceCoalition ESS < 30%HIGH2022-02-08
In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges...
CVEs:CVE-2021-39669
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-02-25
CVEs:CVE-2022-0247
GoogleCoalition ESS < 30%HIGH2022-02-25
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739...
CVEs:CVE-2022-0247
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fuchsia |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2022-02-15
Kubernetes Arbitrary Command Injection
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourceEPSS <= 49%CRITICAL2022-02-15
Kubernetes Arbitrary Command Injection
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourceEPSS <= 49%MEDIUM2022-02-15
Denial of service when parsing large forms in mime/multipart
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourceEPSS <= 49%HIGH2022-02-15
Directory Traversal in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourceEPSS <= 49%HIGH2022-02-15
Directory Traversal in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourceEPSS <= 49%CRITICAL2022-02-15
Directory traversal in k8s.io/kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
GoogleEPSS <= 49%MEDIUM2022-02-28
CVEs:CVE-2021-25011
GoogleEPSS <= 49%MEDIUM2022-02-28
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's...
CVEs:CVE-2021-25011
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| wp_google_map |
affected |
wpgooglemap |
— |
— |
Open SourceAll remainingHIGH2022-02-18
Null-dereference READ in istio.io/istio/security/pkg/util.ExtractJwtAud
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
Go |
istio |
— |
Open SourceAll remainingCRITICAL2022-02-09
NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceAll remainingCRITICAL2022-02-09
NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceAll remainingHIGH2022-02-09
Improper Validation of Integrity Check Value in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceAll remainingHIGH2022-02-09
Improper Validation of Integrity Check Value in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceAll remainingCRITICAL2022-02-09
Integer Overflow or Wraparound in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceAll remainingCRITICAL2022-02-09
Integer Overflow or Wraparound in TensorFlow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceAll remainingHIGH2022-02-06
Invalid-free in NIOHTTP2.NIOHTTP2Handler.
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc-swift |
affected |
OSS-Fuzz |
grpc-swift |
— |