Google Security Advisories · March 2022 — Google Security Advisories
493 advisories 280 CVEs 21 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2022-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 21 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2022-1040

GoogleExploitedCISA KEV listedCRITICAL2022-03-25

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

CVEs:CVE-2022-1040

Affected products

ProductStatusVendorPackageEcosystem
sfos affected sophos
Upstream advisory

CVE-2022-1040

Project ZeroExploitedCISA KEV listed2022-03-25

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

CVEs:CVE-2022-1040

Upstream advisory

MGASA-2022-0118

Open SourceExploitedCISA KEV listed2022-03-28

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

CVE-2022-1096

Project ZeroExploitedCISA KEV listed2022-03-28

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1096

Upstream advisory

CVE-2022-1096

GoogleExploitedCISA KEV listedHIGH2022-03-28

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1096

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DSA-5110-1

Open SourceExploitedCISA KEV listed2022-03-28

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-26871

GoogleExploitedCISA KEV listedCRITICAL2022-03-29

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

CVEs:CVE-2022-26871

Affected products

ProductStatusVendorPackageEcosystem
apex_central affected trendmicro
apex_one affected trendmicro
Upstream advisory

CVE-2022-26871

Project ZeroExploitedCISA KEV listed2022-03-29

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

CVEs:CVE-2022-26871

Upstream advisory

CVE-2022-26485

GoogleExploitedCISA KEV listedCRITICAL2022-03-07

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0...

CVEs:CVE-2022-26485

Affected products

ProductStatusVendorPackageEcosystem
firefox affected mozilla
firefox_focus affected mozilla
firefox_mobile affected mozilla
thunderbird affected mozilla
Upstream advisory

CVE-2022-26485

Project ZeroExploitedCISA KEV listed2022-03-07

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

CVEs:CVE-2022-26485

Upstream advisory

PUB-A-213464034

GoogleExploitedCISA KEV listedHIGH2022-03-01

PUB-A-213464034

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-26486

Project ZeroExploitedCISA KEV listed2022-03-07

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

CVEs:CVE-2022-26486

Upstream advisory

CVE-2022-26486

GoogleExploitedCISA KEV listedCRITICAL2022-03-07

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox fo...

CVEs:CVE-2022-26486

Affected products

ProductStatusVendorPackageEcosystem
firefox affected mozilla
firefox_focus affected mozilla
firefox_mobile affected mozilla
thunderbird affected mozilla
Upstream advisory

CVE-2021-39793

Open SourceExploitedCISA KEV listedHIGH2022-03-07

In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2021-39793

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39793

Project ZeroExploitedCISA KEV listed2022-03-07

In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A

CVEs:CVE-2021-39793

Upstream advisory

PUB-A-210470189

GoogleExploitedCISA KEV listedHIGH2022-03-01

PUB-A-210470189

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39708

Open SourceActive exploitation (sightings)HIGH2022-03-07

In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2021-39708

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-8xf4-w7qw-pjjw

Open SourceActive exploitation (sightings)CRITICAL2022-03-30

Firebase PHP-JWT key/algorithm type confusion

Affected products

ProductStatusVendorPackageEcosystem
php-jwt affected firebase firebase/php-jwt
php-jwt affected firebase firebase/php-jwt
Upstream advisory

GHSA-8xf4-w7qw-pjjw

Open SourceActive exploitation (sightings)CRITICAL2022-03-30

Firebase PHP-JWT key/algorithm type confusion

Affected products

ProductStatusVendorPackageEcosystem
php-jwt affected firebase firebase/php-jwt
Upstream advisory

CVE-2021-46743

Open SourceActive exploitation (sightings)CRITICAL2022-03-29

In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect...

CVEs:CVE-2021-46743

Affected products

ProductStatusVendorPackageEcosystem
firebase_php-jwt affected google
Upstream advisory

CVE-2021-46743

Open SourceActive exploitation (sightings)CRITICAL2022-03-29

Firebase PHP-JWT key/algorithm type confusion

CVEs:CVE-2021-46743

Affected products

ProductStatusVendorPackageEcosystem
php-jwt affected firebase firebase/php-jwt
Upstream advisory

CVE-2021-39726

Open SourceActive exploitation (sightings)HIGH2022-03-07

In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2021-39726

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-181782896

GoogleActive exploitation (sightings)MEDIUM2022-03-01

PUB-A-181782896

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39692

Open SourceActive exploitation (sightings)HIGH2022-03-07

In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction...

CVEs:CVE-2021-39692

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39667

Open SourceActive exploitation (sightings)HIGH2022-03-07

In ih264d_parse_decode_slice of ih264d_parse_slice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for...

CVEs:CVE-2021-39667

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39710

Open SourceActive exploitation (sightings)HIGH2022-03-07

Product: AndroidVersions: Android kernelAndroid ID: A-202160245References: N/A

CVEs:CVE-2021-39710

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39720

Open SourceActive exploitation (sightings)HIGH2022-03-07

Product: AndroidVersions: Android kernelAndroid ID: A-207433926References: N/A

CVEs:CVE-2021-39720

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-202160245

GoogleActive exploitation (sightings)2022-03-01

PUB-A-202160245

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-207433926

GoogleActive exploitation (sightings)2022-03-01

PUB-A-207433926

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39701

Open SourceActive exploitation (sightings)HIGH2022-03-07

In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or permission due to improper input validation. This could lead to local escalation of privilege with no add...

CVEs:CVE-2021-39701

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39702

Open SourceActive exploitation (sightings)HIGH2022-03-07

In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privilege...

CVEs:CVE-2021-39702

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-209469958

GoogleActive exploitation (sightings)2022-03-01

ASB-A-209469958

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-39715

Open SourceActive exploitation (sightings)MEDIUM2022-03-07

In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-39715

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-178379135

GoogleActive exploitation (sightings)MEDIUM2022-03-01

PUB-A-178379135

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-39695

Open SourceActive exploitation (sightings)HIGH2022-03-07

In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2021-39695

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39709

Open SourceActive exploitation (sightings)HIGH2022-03-07

In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...

CVEs:CVE-2021-39709

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39694

Open SourceActive exploitation (sightings)HIGH2022-03-07

In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User in...

CVEs:CVE-2021-39694

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39703

Open SourceActive exploitation (sightings)HIGH2022-03-07

In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2021-39703

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39707

Open SourceActive exploitation (sightings)HIGH2022-03-07

In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...

CVEs:CVE-2021-39707

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-190406215

GoogleActive exploitation (sightings)2022-03-01

PUB-A-190406215

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-39722

Open SourceActive exploitation (sightings)MEDIUM2022-03-07

In ProtocolStkProactiveCommandAdapter::Init of protocolstkadapter.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is...

CVEs:CVE-2021-39722

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39724

Open SourceActive exploitation (sightings)MEDIUM2022-03-07

In TuningProviderBase::GetTuningTreeSet of tuning_provider_base.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not n...

CVEs:CVE-2021-39724

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39729

Open SourceActive exploitation (sightings)HIGH2022-03-07

In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2021-39729

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39733

Open SourceActive exploitation (sightings)HIGH2022-03-07

In amcs_cdev_unlocked_ioctl of audiometrics.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2021-39733

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-202006191

GoogleActive exploitation (sightings)HIGH2022-03-01

PUB-A-202006191

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-204585345

GoogleActive exploitation (sightings)MEDIUM2022-03-01

PUB-A-204585345

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-205753190

GoogleActive exploitation (sightings)MEDIUM2022-03-01

PUB-A-205753190

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-206128522

GoogleActive exploitation (sightings)HIGH2022-03-01

PUB-A-206128522

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39721

Open SourceActive exploitation (sightings)HIGH2022-03-07

In TBD of TBD, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...

CVEs:CVE-2021-39721

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39725

Open SourceActive exploitation (sightings)HIGH2022-03-07

In gasket_free_coherent_memory_all of gasket_page_table.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-39725

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-151454974

GoogleActive exploitation (sightings)HIGH2022-03-01

PUB-A-151454974

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-195726151

GoogleActive exploitation (sightings)HIGH2022-03-01

PUB-A-195726151

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39734

Open SourceActive exploitation (sightings)HIGH2022-03-07

In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User...

CVEs:CVE-2021-39734

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-208650395

GoogleActive exploitation (sightings)NONE2022-03-01

PUB-A-208650395

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39727

Open SourceActive exploitation (sightings)MEDIUM2022-03-07

In eicPresentationRetrieveEntryValue of acropora/app/identity/libeic/EicPresentation.c, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with System execution privileges needed. User in...

CVEs:CVE-2021-39727

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39792

Open SourceActive exploitation (sightings)HIGH2022-03-07

In usb_gadget_giveback_request of core.c, there is a possible use after free out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2021-39792

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-161010552

GoogleActive exploitation (sightings)HIGH2022-03-01

PUB-A-161010552

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-196388042

GoogleActive exploitation (sightings)MEDIUM2022-03-01

PUB-A-196388042

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39712

Open SourceActive exploitation (sightings)MEDIUM2022-03-07

In TBD of TBD, there is a possible user after free vulnerability due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...

CVEs:CVE-2021-39712

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-176918884

GoogleActive exploitation (sightings)NONE2022-03-01

PUB-A-176918884

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-205243414

GooglePoC exploitHIGH2022-03-01

PUB-A-205243414

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-0811

GooglePoC exploitCRITICAL2022-03-15

A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the clu...

CVEs:CVE-2022-0811

Affected products

ProductStatusVendorPackageEcosystem
cri-o affected kubernetes
Upstream advisory

CVE-2022-0811

GooglePoC exploitHIGH2022-03-15

Code Injection in CRI-O

CVEs:CVE-2022-0811

Affected products

ProductStatusVendorPackageEcosystem
cri-o/cri-o affected github.com github.com/cri-o/cri-o
Upstream advisory

CLSA-2022-1648048535

Open SourcePoC exploitHIGH2022-03-23

Fix CVE(s): CVE-2021-3737

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

CLSA-2022-1647969910

Open SourcePoC exploitHIGH2022-03-22

Fix CVE(s): CVE-2021-3737

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

CLSA-2022-1647254655

Open SourcePoC exploit2022-03-14

Fix CVE(s): CVE-2022-0391

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

GHSA-8c26-wmh5-6g9v

Open SourcePoC exploitHIGH2022-03-19

golang.org/x/crypto/ssh Denial of service via crafted Signer

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-8c26-wmh5-6g9v

Open SourcePoC exploitHIGH2022-03-19

golang.org/x/crypto/ssh Denial of service via crafted Signer

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
k3d affected chainguard k3d
k3d affected wolfi k3d
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

DEBIAN-CVE-2022-27191

Open SourcePoC exploitHIGH2022-03-18

DEBIAN-CVE-2022-27191

Affected products

ProductStatusVendorPackageEcosystem
golang-go.crypto affected Debian:11 golang-go.crypto
golang-go.crypto affected Debian:12 golang-go.crypto
golang-go.crypto affected Debian:13 golang-go.crypto
golang-go.crypto affected Debian:14 golang-go.crypto
Upstream advisory

CVE-2022-27191

Open SourcePoC exploitHIGH2022-03-18

golang.org/x/crypto/ssh Denial of service via crafted Signer

CVEs:CVE-2022-27191

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CVE-2022-27191

Open SourcePoC exploitHIGH2022-03-18

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

CVEs:CVE-2022-27191

Affected products

ProductStatusVendorPackageEcosystem
advanced_cluster_management_for_kubernetes affected redhat
extra_packages_for_enterprise_linux affected fedoraproject
fedora affected fedoraproject
ssh affected golang
Upstream advisory

OESA-2022-1585

Open SourcePoC exploit2022-03-19

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP2 golang
golang affected openEuler:20.03-LTS-SP3 golang
Upstream advisory

MGASA-2022-0091

Open SourcePoC exploitHIGH2022-03-07

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

SUSE-SU-2022:1040-1

Open SourcePoC exploit2022-03-30

Security update for protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected SUSE:Linux Enterprise Installer Updates 15 SP2 protobuf
protobuf affected SUSE:Linux Enterprise Module for Basesystem 15 SP3 protobuf
protobuf affected SUSE:Linux Enterprise Module for Development Tools 15 SP3 protobuf
protobuf affected SUSE:Linux Enterprise Module for Package Hub 15 SP3 protobuf
protobuf affected SUSE:Linux Enterprise Module for Package Hub 15 SP4 protobuf
protobuf affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 protobuf
protobuf affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 protobuf
protobuf affected SUSE:Manager Server Module 4.1 protobuf
protobuf affected SUSE:Manager Server Module 4.2 protobuf
protobuf affected SUSE:Linux Enterprise Real Time 15 SP2 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.0 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.1 protobuf
Upstream advisory

openSUSE-SU-2022:1040-1

Open SourcePoC exploit2022-03-30

Security update for protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected openSUSE:Leap 15.3 protobuf
Upstream advisory

openSUSE-SU-2022:0823-1

Open SourcePoC exploit2022-03-14

Security update for protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected openSUSE:Leap 15.3 protobuf
Upstream advisory

PUB-A-192972537

GooglePoC exploit2022-03-01

PUB-A-192972537

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-39706

Open SourcePoC exploitHIGH2022-03-07

In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2021-39706

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-210292376

GooglePoC exploitHIGH2022-03-01

ASB-A-210292376

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-174738029

GooglePoC exploitNONE2022-03-01

ASB-A-174738029

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-39698

Open SourcePoC exploitHIGH2022-03-07

In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...

CVEs:CVE-2021-39698

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-185125206

GooglePoC exploitHIGH2022-03-01

ASB-A-185125206

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-39713

Open SourcePoC exploitHIGH2022-03-07

Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel

CVEs:CVE-2021-39713

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

PUB-A-173788806

GooglePoC exploit2022-03-01

PUB-A-173788806

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-39749

Open SourcePoC exploitHIGH2022-03-30

In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2021-39749

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39704

Open SourcePoC exploitHIGH2022-03-07

In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service without user notification due to a permissions bypass. This could lead to local escalation of privilege with no additional execution...

CVEs:CVE-2021-39704

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39690

Open SourcePoC exploitMEDIUM2022-03-07

In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2021-39690

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-1134

GoogleCoalition ESS 30-63%HIGH2022-03-30

Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1134

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-c3h9-896r-86jm

Open SourceCoalition ESS < 30%HIGH2022-03-28

Improper Input Validation in GoGo Protobuf

Affected products

ProductStatusVendorPackageEcosystem
ctop affected chainguard ctop
ctop affected wolfi ctop
gogo/protobuf affected github.com github.com/gogo/protobuf
k3d affected chainguard k3d
k3d affected wolfi k3d
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
protobuf-c affected wolfi protobuf-c
protobuf-c affected chainguard protobuf-c
Upstream advisory

GHSA-c3h9-896r-86jm

Open SourceCoalition ESS < 30%HIGH2022-03-28

Improper Input Validation in GoGo Protobuf

Affected products

ProductStatusVendorPackageEcosystem
gogo/protobuf affected github.com github.com/gogo/protobuf
Upstream advisory

MGASA-2022-0126

Open SourceCoalition ESS < 30%2022-03-31

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

OESA-2022-1590

Open SourceCoalition ESS < 30%2022-03-26

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP3 golang
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP2 golang
Upstream advisory

AZL-79112

Open SourceCoalition ESS < 30%HIGH2022-03-05

CVE-2022-24921 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-8898

Open SourceCoalition ESS < 30%HIGH2022-03-05

CVE-2022-24921 affecting package golang for versions less than 1.17.8-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

CVE-2022-24921

GoogleCoalition ESS < 30%HIGH2022-03-05

regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.

CVEs:CVE-2022-24921

Affected products

ProductStatusVendorPackageEcosystem
astra_trident affected netapp
debian_linux affected debian
go affected golang
Upstream advisory

DEBIAN-CVE-2022-24921

Open SourceCoalition ESS < 30%HIGH2022-03-05

DEBIAN-CVE-2022-24921

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

GHSA-fpxq-w7p9-r924

Open SourceCoalition ESS < 30%HIGH2022-03-16

Arbitrary file read vulnerability in Jenkins kubernetes-cd Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

GHSA-fpxq-w7p9-r924

Open SourceCoalition ESS < 30%HIGH2022-03-16

Arbitrary file read vulnerability in Jenkins kubernetes-cd Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

CVE-2022-27208

Open SourceCoalition ESS < 30%MEDIUM2022-03-15

Arbitrary file read vulnerability in Jenkins kubernetes-cd Plugin

CVEs:CVE-2022-27208

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

CVE-2022-27208

Open SourceCoalition ESS < 30%HIGH2022-03-15

Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller.

CVEs:CVE-2022-27208

Affected products

ProductStatusVendorPackageEcosystem
kubernetes_continuous_deploy affected jenkins
Upstream advisory

openSUSE-SU-2022:0075-1

Open SourceCoalition ESS < 30%CRITICAL2022-03-07

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

DSA-5089-1

Open SourceCoalition ESS < 30%2022-03-04

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-0797

GoogleCoalition ESS < 30%HIGH2022-03-02

Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2022-0797

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-24512

Open SourceCoalition ESS < 30%MEDIUM2022-03-09

.NET Remote Code Execution Vulnerability

CVEs:CVE-2022-24512

Affected products

ProductStatusVendorPackageEcosystem
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

CVE-2022-24512

GoogleCoalition ESS < 30%CRITICAL2022-03-08

.NET and Visual Studio Remote Code Execution Vulnerability

CVEs:CVE-2022-24512

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
.net affected microsoft
.net_core affected microsoft
powershell affected microsoft
visual_studio_2019 affected microsoft
visual_studio_2022 affected microsoft
Upstream advisory

CVE-2022-24726

Open SourceCoalition ESS < 30%HIGH2022-03-10

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which result...

CVEs:CVE-2022-24726

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

CVE-2022-0230

GoogleCoalition ESS < 30%HIGH2022-03-14

The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against ad...

CVEs:CVE-2022-0230

Affected products

ProductStatusVendorPackageEcosystem
bwp-google-xml-sitemaps affected bwp-google-xml-sitemaps_project
Upstream advisory

CVE-2021-25068

GoogleCoalition ESS < 30%CRITICAL2022-03-28

The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard

CVEs:CVE-2021-25068

Affected products

ProductStatusVendorPackageEcosystem
sync_woocommerce_product_feed_to_google_shopping affected dpl
Upstream advisory

MGASA-2022-0107

Open SourceCoalition ESS < 30%CRITICAL2022-03-21

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

openSUSE-SU-2022:0085-1

Open SourceCoalition ESS < 30%CRITICAL2022-03-20

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

DSA-5104-1

Open SourceCoalition ESS < 30%2022-03-18

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-0971

GoogleCoalition ESS < 30%CRITICAL2022-03-16

Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0971

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-24777

Open SourceCoalition ESS < 30%HIGH2022-03-25

Denial of Service via reachable assertion

CVEs:CVE-2022-24777

Affected products

ProductStatusVendorPackageEcosystem
grpc/grpc-swift affected github.com github.com/grpc/grpc-swift
Upstream advisory

CVE-2022-24777

Open SourceCoalition ESS < 30%CRITICAL2022-03-25

grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is due to incorrect logic when han...

CVEs:CVE-2022-24777

Affected products

ProductStatusVendorPackageEcosystem
grpc_swift affected linuxfoundation
Upstream advisory

CVE-2022-0789

GoogleCoalition ESS < 30%CRITICAL2022-03-02

Heap buffer overflow in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0789

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0809

GoogleCoalition ESS < 30%HIGH2022-03-02

Out of bounds memory access in WebXR in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0809

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0800

GoogleCoalition ESS < 30%HIGH2022-03-02

Heap buffer overflow in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0800

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0796

GoogleCoalition ESS < 30%CRITICAL2022-03-02

Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0796

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0976

GoogleCoalition ESS < 30%CRITICAL2022-03-16

Heap buffer overflow in GPU in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0976

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0799

GoogleCoalition ESS < 30%HIGH2022-03-02

Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file.

CVEs:CVE-2022-0799

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0795

GoogleCoalition ESS < 30%HIGH2022-03-02

Type confusion in Blink Layout in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0795

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0792

GoogleCoalition ESS < 30%MEDIUM2022-03-02

Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0792

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0794

GoogleCoalition ESS < 30%HIGH2022-03-02

Use after free in WebShare in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0794

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0806

GoogleCoalition ESS < 30%HIGH2022-03-02

Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-0806

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0791

GoogleCoalition ESS < 30%HIGH2022-03-02

Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions.

CVEs:CVE-2022-0791

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0805

GoogleCoalition ESS < 30%HIGH2022-03-02

Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

CVEs:CVE-2022-0805

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0790

GoogleCoalition ESS < 30%CRITICAL2022-03-02

Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2022-0790

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-23x5-j68g-6jpw

Open SourceCoalition ESS < 30%MEDIUM2022-03-16

Missing permission checks in Jenkins kubernetes-cd Plugin allow enumerating credentials IDs

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

GHSA-23x5-j68g-6jpw

Open SourceCoalition ESS < 30%MEDIUM2022-03-16

Missing permission checks in Jenkins kubernetes-cd Plugin allow enumerating credentials IDs

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

GHSA-794j-hx96-4w3m

Open SourceCoalition ESS < 30%HIGH2022-03-16

CSRF vulnerability and missing permission checks in Jenkins kubernetes-cd Plugin allow capturing credentials

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

GHSA-794j-hx96-4w3m

Open SourceCoalition ESS < 30%HIGH2022-03-16

CSRF vulnerability and missing permission checks in Jenkins kubernetes-cd Plugin allow capturing credentials

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

CVE-2022-27209

Open SourceCoalition ESS < 30%MEDIUM2022-03-15

Missing permission checks in Jenkins kubernetes-cd Plugin allow enumerating credentials IDs

CVEs:CVE-2022-27209

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

CVE-2022-27209

Open SourceCoalition ESS < 30%MEDIUM2022-03-15

A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVEs:CVE-2022-27209

Affected products

ProductStatusVendorPackageEcosystem
kubernetes_continuous_deploy affected jenkins
Upstream advisory

CVE-2022-27211

Open SourceCoalition ESS < 30%HIGH2022-03-15

CSRF vulnerability and missing permission checks in Jenkins kubernetes-cd Plugin allow capturing credentials

CVEs:CVE-2022-27211

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

CVE-2022-27211

Open SourceCoalition ESS < 30%MEDIUM2022-03-15

A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another m...

CVEs:CVE-2022-27211

Affected products

ProductStatusVendorPackageEcosystem
kubernetes_continuous_deploy affected jenkins
Upstream advisory

CVE-2022-0808

GoogleCoalition ESS < 30%HIGH2022-03-02

Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in a series of user interaction to potentially exploit heap corruption via user interactions.

CVEs:CVE-2022-0808

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0977

GoogleCoalition ESS < 30%CRITICAL2022-03-16

Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0977

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0807

GoogleCoalition ESS < 30%MEDIUM2022-03-02

Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2022-0807

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1125

GoogleCoalition ESS < 30%HIGH2022-03-30

Use after free in Portals in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

CVEs:CVE-2022-1125

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1139

GoogleCoalition ESS < 30%MEDIUM2022-03-30

Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-1139

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0802

GoogleCoalition ESS < 30%MEDIUM2022-03-02

Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2022-0802

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0804

GoogleCoalition ESS < 30%MEDIUM2022-03-02

Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2022-0804

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1146

GoogleCoalition ESS < 30%CRITICAL2022-03-30

Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-1146

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1133

GoogleCoalition ESS < 30%CRITICAL2022-03-30

Use after free in WebRTC Perf in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1133

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0973

GoogleCoalition ESS < 30%CRITICAL2022-03-16

Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0973

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0978

GoogleCoalition ESS < 30%CRITICAL2022-03-16

Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0978

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0803

GoogleCoalition ESS < 30%MEDIUM2022-03-02

Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2022-0803

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0974

GoogleCoalition ESS < 30%HIGH2022-03-16

Use after free in Splitscreen in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0974

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0975

GoogleCoalition ESS < 30%CRITICAL2022-03-16

Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0975

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1135

GoogleCoalition ESS < 30%HIGH2022-03-30

Use after free in Shopping Cart in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via standard feature user interaction.

CVEs:CVE-2022-1135

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0979

GoogleCoalition ESS < 30%HIGH2022-03-16

Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0979

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1141

GoogleCoalition ESS < 30%HIGH2022-03-30

Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.

CVEs:CVE-2022-1141

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1130

GoogleCoalition ESS < 30%HIGH2022-03-30

Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to send arbitrary intents from any app via a malicious app.

CVEs:CVE-2022-1130

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1129

GoogleCoalition ESS < 30%MEDIUM2022-03-30

Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2022-1129

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0972

GoogleCoalition ESS < 30%CRITICAL2022-03-16

Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-0972

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1142

GoogleCoalition ESS < 30%HIGH2022-03-30

Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.

CVEs:CVE-2022-1142

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-39762

Open SourceCoalition ESS < 30%HIGH2022-03-30

In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...

CVEs:CVE-2021-39762

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-0793

GoogleCoalition ESS < 30%HIGH2022-03-02

Use after free in Cast in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted Chrome Extension.

CVEs:CVE-2022-0793

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-vq6c-fvxw-p45v

Open SourceCoalition ESS < 30%HIGH2022-03-16

CSRF vulnerability in Jenkins kubernetes-cd Plugin allow capturing credentials

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

GHSA-vq6c-fvxw-p45v

Open SourceCoalition ESS < 30%HIGH2022-03-16

CSRF vulnerability in Jenkins kubernetes-cd Plugin allow capturing credentials

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

CVE-2022-27210

Open SourceCoalition ESS < 30%MEDIUM2022-03-15

A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method,...

CVEs:CVE-2022-27210

Affected products

ProductStatusVendorPackageEcosystem
kubernetes_continuous_deploy affected jenkins
Upstream advisory

CVE-2022-27210

Open SourceCoalition ESS < 30%HIGH2022-03-15

CSRF vulnerability in Jenkins kubernetes-cd Plugin allow capturing credentials

CVEs:CVE-2022-27210

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:kubernetes-cd affected Maven org.jenkins-ci.plugins:kubernetes-cd
Upstream advisory

CVE-2022-26899

Open SourceCoalition ESS < 30%CRITICAL2022-03-08

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-26899

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-0798

GoogleCoalition ESS < 30%CRITICAL2022-03-02

Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

CVEs:CVE-2022-0798

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1145

GoogleCoalition ESS < 30%HIGH2022-03-30

Use after free in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interaction and profile destruction.

CVEs:CVE-2022-1145

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1137

GoogleCoalition ESS < 30%HIGH2022-03-30

Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially sensitive information via a crafted HTML page.

CVEs:CVE-2022-1137

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0980

GoogleCoalition ESS < 30%HIGH2022-03-16

Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interactions.

CVEs:CVE-2022-0980

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0229

GoogleCoalition ESS < 30%HIGH2022-03-21

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users cou...

CVEs:CVE-2022-0229

Affected products

ProductStatusVendorPackageEcosystem
google_authenticator affected miniorange
Upstream advisory

PUB-A-207093880

GoogleCoalition ESS < 30%2022-03-01

PUB-A-207093880

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-214309660

GoogleCoalition ESS < 30%2022-03-01

PUB-A-214309660

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-214309790

GoogleCoalition ESS < 30%2022-03-01

PUB-A-214309790

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-0801

GoogleCoalition ESS < 30%CRITICAL2022-03-02

Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass XSS preventions via a crafted HTML page. (Chrome security severity: Medium)

CVEs:CVE-2022-0801

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-39723

Open SourceCoalition ESS < 30%HIGH2022-03-07

Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A

CVEs:CVE-2021-39723

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39737

Open SourceCoalition ESS < 30%HIGH2022-03-07

Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A

CVEs:CVE-2021-39737

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-208229524

GoogleCoalition ESS < 30%2022-03-01

PUB-A-208229524

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-209014813

GoogleCoalition ESS < 30%2022-03-01

PUB-A-209014813

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-197850306

GoogleCoalition ESS < 30%MEDIUM2022-03-01

PUB-A-197850306

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-25818

Open SourceCoalition ESS < 30%CRITICAL2022-03-10

Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.

CVEs:CVE-2022-25818

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-202511260

GoogleCoalition ESS < 30%HIGH2022-03-01

PUB-A-202511260

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-39716

Open SourceCoalition ESS < 30%HIGH2022-03-07

Product: AndroidVersions: Android kernelAndroid ID: A-206977562References: N/A

CVEs:CVE-2021-39716

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-206977562

GoogleCoalition ESS < 30%2022-03-01

PUB-A-206977562

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-195082947

GoogleCoalition ESS < 30%HIGH2022-03-01

PUB-A-195082947

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2021-39787

Open SourceCoalition ESS < 30%HIGH2022-03-30

In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: ...

CVEs:CVE-2021-39787

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39764

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead to local escalation of privilege via app spoofing with no additional execution privileges needed. User interaction is needed for exp...

CVEs:CVE-2021-39764

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39771

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for...

CVEs:CVE-2021-39771

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-3602

Open SourceCoalition ESS < 30%HIGH2022-03-03

DEBIAN-CVE-2021-3602

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-buildah affected Debian:11 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:12 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:13 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:14 golang-github-containers-buildah
Upstream advisory

CVE-2021-39780

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...

CVEs:CVE-2021-39780

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39742

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Prod...

CVEs:CVE-2021-39742

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39790

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.P...

CVEs:CVE-2021-39790

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-197154735

GoogleCoalition ESS < 30%MEDIUM2022-03-01

ASB-A-197154735

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-1132

GoogleCoalition ESS < 30%MEDIUM2022-03-30

Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation restrictions via physical access to the device.

CVEs:CVE-2022-1132

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-gv26-jpj9-c8gq

Open SourceCoalition ESS < 30%HIGH2022-03-18

Incomplete validation in `SparseSparseMinimum`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gv26-jpj9-c8gq

Open SourceCoalition ESS < 30%HIGH2022-03-18

Incomplete validation in `SparseSparseMinimum`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2021-39714

Open SourceCoalition ESS < 30%HIGH2022-03-07

In ion_buffer_kmap_get of ion.c, there is a possible use-after-free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2021-39714

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20054

Open SourceCoalition ESS < 30%HIGH2022-03-10

In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS...

CVEs:CVE-2022-20054

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39772

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2021-39772

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-22571

GoogleCoalition ESS < 30%MEDIUM2022-03-18

A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.

CVEs:CVE-2021-22571

Affected products

ProductStatusVendorPackageEcosystem
sa360_webquery_to_bigquery_exporter affected google
Upstream advisory

CVE-2021-39686

Open SourceCoalition ESS < 30%HIGH2022-03-07

In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2021-39686

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39711

Open SourceCoalition ESS < 30%MEDIUM2022-03-07

In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2021-39711

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-200688826

GoogleCoalition ESS < 30%NONE2022-03-01

ASB-A-200688826

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-154175781

GoogleCoalition ESS < 30%MEDIUM2022-03-01

PUB-A-154175781

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20060

Open SourceCoalition ESS < 30%MEDIUM2022-03-10

In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges nee...

CVEs:CVE-2022-20060

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20050

Open SourceCoalition ESS < 30%MEDIUM2022-03-10

In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0633...

CVEs:CVE-2022-20050

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20059

Open SourceCoalition ESS < 30%HIGH2022-03-10

In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User int...

CVEs:CVE-2022-20059

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20058

Open SourceCoalition ESS < 30%HIGH2022-03-10

In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User int...

CVEs:CVE-2022-20058

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20056

Open SourceCoalition ESS < 30%HIGH2022-03-10

In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User int...

CVEs:CVE-2022-20056

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0957

Open SourceCoalition ESS < 30%HIGH2022-03-07

In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to bypass Factory Reset Protections. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...

CVEs:CVE-2021-0957

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20055

Open SourceCoalition ESS < 30%HIGH2022-03-10

In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User int...

CVEs:CVE-2022-20055

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-22572

GoogleCoalition ESS < 30%MEDIUM2022-03-29

On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files in the the system temporary directory with world readable permissions. Any sensitive information writte...

CVEs:CVE-2021-22572

Affected products

ProductStatusVendorPackageEcosystem
data_transfer_project affected google
Upstream advisory

CVE-2021-39693

Open SourceCoalition ESS < 30%HIGH2022-03-07

In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User i...

CVEs:CVE-2021-39693

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-chxf-fjcf-7fwp

GoogleCoalition ESS < 30%NONE2022-03-01

Possible filesystem space exhaustion by local users

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

GHSA-chxf-fjcf-7fwp

GoogleCoalition ESS < 30%MEDIUM2022-03-01

Possible filesystem space exhaustion by local users

Affected products

ProductStatusVendorPackageEcosystem
github.com/google/fscrypt affected Go github.com/google/fscrypt
google/fscrypt affected github.com github.com/google/fscrypt
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

CVE-2022-20057

Open SourceCoalition ESS < 30%HIGH2022-03-10

In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06271186; Issue ID: ALP...

CVEs:CVE-2022-20057

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39697

Open SourceCoalition ESS < 30%HIGH2022-03-07

In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missing permission check. This could lead to local escalation of privilege with User execution privileges ne...

CVEs:CVE-2021-39697

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39765

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndr...

CVEs:CVE-2021-39765

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20047

Open SourceCoalition ESS < 30%HIGH2022-03-07

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS059...

CVEs:CVE-2022-20047

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20048

Open SourceCoalition ESS < 30%HIGH2022-03-07

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS059...

CVEs:CVE-2022-20048

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-213116796

GoogleCoalition ESS < 30%HIGH2022-03-01

ASB-A-213116796

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-213120685

GoogleCoalition ESS < 30%HIGH2022-03-01

ASB-A-213120685

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-24931

Open SourceCoalition ESS < 30%CRITICAL2022-03-10

Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbitrary activity without a proper permission

CVEs:CVE-2022-24931

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39768

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2021-39768

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20053

Open SourceCoalition ESS < 30%HIGH2022-03-07

In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A...

CVEs:CVE-2022-20053

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-213120689

GoogleCoalition ESS < 30%NONE2022-03-01

ASB-A-213120689

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-24928

Open SourceCoalition ESS < 30%HIGH2022-03-10

Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP.

CVEs:CVE-2022-24928

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20049

Open SourceCoalition ESS < 30%MEDIUM2022-03-10

In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05954679; Is...

CVEs:CVE-2022-20049

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39781

Open SourceCoalition ESS < 30%HIGH2022-03-30

In SmsController, there is a possible information disclosure due to a permissions bypass. This could lead to local escalation of privilege and sending sms with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2021-39781

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39752

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Bubbles, there is a possible way to interfere with Bubbles due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...

CVEs:CVE-2021-39752

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39763

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2021-39763

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39767

Open SourceCoalition ESS < 30%HIGH2022-03-30

In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2021-39767

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39786

Open SourceCoalition ESS < 30%HIGH2022-03-30

In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1...

CVEs:CVE-2021-39786

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39741

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Keymaster, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2021-39741

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39746

Open SourceCoalition ESS < 30%HIGH2022-03-30

In PermissionController, there is a possible way to delete some local files due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product:...

CVEs:CVE-2021-39746

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39759

Open SourceCoalition ESS < 30%HIGH2022-03-30

In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...

CVEs:CVE-2021-39759

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39717

Open SourceCoalition ESS < 30%MEDIUM2022-03-07

In iaxxx_btp_write_words of iaxxx-btp.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2021-39717

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39718

Open SourceCoalition ESS < 30%HIGH2022-03-07

In ProtocolStkProactiveCommandAdapter::Init of protocolstkadapter.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction ...

CVEs:CVE-2021-39718

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39719

Open SourceCoalition ESS < 30%HIGH2022-03-07

In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2021-39719

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39730

Open SourceCoalition ESS < 30%MEDIUM2022-03-07

In TBD of TBD, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr...

CVEs:CVE-2021-39730

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39731

Open SourceCoalition ESS < 30%HIGH2022-03-07

In ProtocolStkProactiveCommandAdapter::Init of protocolstkadapter.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction ...

CVEs:CVE-2021-39731

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39732

Open SourceCoalition ESS < 30%HIGH2022-03-07

In copy_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2021-39732

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39736

Open SourceCoalition ESS < 30%HIGH2022-03-07

In prepare_io_entry and prepare_response of lwis_ioctl.c and lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interact...

CVEs:CVE-2021-39736

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-198653629

GoogleCoalition ESS < 30%MEDIUM2022-03-01

PUB-A-198653629

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-205035540

GoogleCoalition ESS < 30%HIGH2022-03-01

PUB-A-205035540

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-205036834

GoogleCoalition ESS < 30%HIGH2022-03-01

PUB-A-205036834

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-205992503

GoogleCoalition ESS < 30%HIGH2022-03-01

PUB-A-205992503

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-205995178

GoogleCoalition ESS < 30%HIGH2022-03-01

PUB-A-205995178

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-205995773

GoogleCoalition ESS < 30%HIGH2022-03-01

PUB-A-205995773

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-206472503

GoogleCoalition ESS < 30%MEDIUM2022-03-01

PUB-A-206472503

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39778

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction...

CVEs:CVE-2021-39778

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39740

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2021-39740

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39757

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In PermissionController, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2021-39757

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-23729

Open SourceCoalition ESS < 30%HIGH2022-03-04

When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.

CVEs:CVE-2022-23729

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-p93v-m2r2-4387

GoogleCoalition ESS < 30%MEDIUM2022-03-01

Denial of service via insufficient metadata validation

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

GHSA-p93v-m2r2-4387

GoogleCoalition ESS < 30%MEDIUM2022-03-01

Denial of service via insufficient metadata validation

Affected products

ProductStatusVendorPackageEcosystem
github.com/google/fscrypt affected Go github.com/google/fscrypt
google/fscrypt affected github.com github.com/google/fscrypt
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

CVE-2021-39788

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile...

CVEs:CVE-2021-39788

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39791

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges...

CVEs:CVE-2021-39791

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39766

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User i...

CVEs:CVE-2021-39766

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39773

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2021-39773

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39775

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In People, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User int...

CVEs:CVE-2021-39775

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39776

Open SourceCoalition ESS < 30%HIGH2022-03-30

In NFC, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ...

CVEs:CVE-2021-39776

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39777

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interacti...

CVEs:CVE-2021-39777

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39744

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...

CVEs:CVE-2021-39744

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39745

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...

CVEs:CVE-2021-39745

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39754

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. Use...

CVEs:CVE-2021-39754

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39755

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution pr...

CVEs:CVE-2021-39755

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39756

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User ...

CVEs:CVE-2021-39756

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39760

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In AudioService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. Us...

CVEs:CVE-2021-39760

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39761

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User inte...

CVEs:CVE-2021-39761

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39739

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2021-39739

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-25821

Open SourceCoalition ESS < 30%HIGH2022-03-10

Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.

CVEs:CVE-2022-25821

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39624

Open SourceCoalition ESS < 30%HIGH2022-03-07

In PackageManager, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2021-39624

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-25816

Open SourceCoalition ESS < 30%HIGH2022-03-10

Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication

CVEs:CVE-2022-25816

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-25819

Open SourceCoalition ESS < 30%MEDIUM2022-03-10

OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.

CVEs:CVE-2022-25819

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-24932

Open SourceCoalition ESS < 30%MEDIUM2022-03-10

Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.

CVEs:CVE-2022-24932

Affected products

ProductStatusVendorPackageEcosystem
android affected google
cloud affected samsung
Upstream advisory

CVE-2022-25817

Open SourceCoalition ESS < 30%MEDIUM2022-03-10

Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.

CVEs:CVE-2022-25817

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20002

Open SourceCoalition ESS < 30%HIGH2022-03-30

In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andro...

CVEs:CVE-2022-20002

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39774

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2021-39774

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39747

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2021-39747

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1000

Open SourceCoalition ESS < 30%HIGH2022-03-30

In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...

CVEs:CVE-2021-1000

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1033

Open SourceCoalition ESS < 30%HIGH2022-03-30

In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...

CVEs:CVE-2021-1033

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20051

Open SourceCoalition ESS < 30%MEDIUM2022-03-10

In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch...

CVEs:CVE-2022-20051

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39689

Open SourceCoalition ESS < 30%HIGH2022-03-07

In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2021-39689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39789

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...

CVEs:CVE-2021-39789

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39769

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User inter...

CVEs:CVE-2021-39769

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39770

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2021-39770

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39779

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call state with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2021-39779

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39782

Open SourceCoalition ESS < 30%HIGH2022-03-30

In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2021-39782

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39783

Open SourceCoalition ESS < 30%HIGH2022-03-30

In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andro...

CVEs:CVE-2021-39783

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39784

Open SourceCoalition ESS < 30%HIGH2022-03-30

In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2021-39784

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39743

Open SourceCoalition ESS < 30%HIGH2022-03-30

In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2021-39743

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39748

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2021-39748

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39750

Open SourceCoalition ESS < 30%HIGH2022-03-30

In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2021-39750

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39751

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2021-39751

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39753

Open SourceCoalition ESS < 30%MEDIUM2022-03-30

In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2021-39753

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39758

Open SourceCoalition ESS < 30%HIGH2022-03-30

In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2021-39758

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-25820

Open SourceCoalition ESS < 30%CRITICAL2022-03-10

A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.

CVEs:CVE-2022-25820

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-24929

Open SourceCoalition ESS < 30%HIGH2022-03-10

Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.

CVEs:CVE-2022-24929

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-25815

Open SourceCoalition ESS < 30%HIGH2022-03-10

PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

CVEs:CVE-2022-25815

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-25814

Open SourceCoalition ESS < 30%HIGH2022-03-10

PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

CVEs:CVE-2022-25814

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39735

Open SourceCoalition ESS < 30%HIGH2022-03-07

In gasket_alloc_coherent_memory of gasket_page_table.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-39735

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-151455484

GoogleCoalition ESS < 30%HIGH2022-03-01

PUB-A-151455484

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-0343

GoogleCoalition ESS < 30%HIGH2022-03-29

A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typically a developer) manually invoked the ./tools/run-dev-server script. It is recommended to upgrade to any version beyond 24.2

CVEs:CVE-2022-0343

Affected products

ProductStatusVendorPackageEcosystem
perfetto affected google
Upstream advisory

CVE-2022-25822

Open SourceCoalition ESS < 30%CRITICAL2022-03-10

An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.

CVEs:CVE-2022-25822

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2022-0099

Open SourceAll remaining2022-03-14

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

GHSA-w4f8-fxq2-j35v

GoogleAll remainingHIGH2022-03-01

Possible privilege escalation via bash completion script

Affected products

ProductStatusVendorPackageEcosystem
github.com/google/fscrypt affected Go github.com/google/fscrypt
google/fscrypt affected github.com github.com/google/fscrypt
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

GHSA-w4f8-fxq2-j35v

GoogleAll remainingHIGH2022-03-01

Possible privilege escalation via bash completion script

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

PUB-A-214310168

GoogleAll remaining2022-03-01

PUB-A-214310168

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.