CVE-2022-1040
CVEs:CVE-2022-1040
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 21 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2022-1040
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
CVEs:CVE-2022-1040
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| sfos | affected | sophos | — | — |
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
CVEs:CVE-2022-1040
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1096
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1096
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
CVEs:CVE-2022-26871
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apex_central | affected | trendmicro | — | — |
| apex_one | affected | trendmicro | — | — |
CVEs:CVE-2022-26871
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
CVEs:CVE-2022-26871
CVEs:CVE-2022-26485
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0...
CVEs:CVE-2022-26485
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firefox | affected | mozilla | — | — |
| firefox_focus | affected | mozilla | — | — |
| firefox_mobile | affected | mozilla | — | — |
| thunderbird | affected | mozilla | — | — |
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
CVEs:CVE-2022-26485
PUB-A-213464034
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
CVEs:CVE-2022-26486
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox fo...
CVEs:CVE-2022-26486
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firefox | affected | mozilla | — | — |
| firefox_focus | affected | mozilla | — | — |
| firefox_mobile | affected | mozilla | — | — |
| thunderbird | affected | mozilla | — | — |
CVEs:CVE-2022-26486
CVEs:CVE-2021-39793
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2021-39793
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A
CVEs:CVE-2021-39793
PUB-A-210470189
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-39708
In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2021-39708
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Firebase PHP-JWT key/algorithm type confusion
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php-jwt | affected | firebase | firebase/php-jwt | — |
| php-jwt | affected | firebase | firebase/php-jwt | — |
Firebase PHP-JWT key/algorithm type confusion
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php-jwt | affected | firebase | firebase/php-jwt | — |
In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect...
CVEs:CVE-2021-46743
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firebase_php-jwt | affected | — | — |
Firebase PHP-JWT key/algorithm type confusion
CVEs:CVE-2021-46743
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php-jwt | affected | firebase | firebase/php-jwt | — |
In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2021-39726
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39726
PUB-A-181782896
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction...
CVEs:CVE-2021-39692
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39692
CVEs:CVE-2021-39667
In ih264d_parse_decode_slice of ih264d_parse_slice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for...
CVEs:CVE-2021-39667
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Product: AndroidVersions: Android kernelAndroid ID: A-202160245References: N/A
CVEs:CVE-2021-39710
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39710
Product: AndroidVersions: Android kernelAndroid ID: A-207433926References: N/A
CVEs:CVE-2021-39720
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39720
PUB-A-202160245
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-207433926
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or permission due to improper input validation. This could lead to local escalation of privilege with no add...
CVEs:CVE-2021-39701
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39701
CVEs:CVE-2021-39702
In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privilege...
CVEs:CVE-2021-39702
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-209469958
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2021-39715
In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2021-39715
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-178379135
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2021-39695
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39695
In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...
CVEs:CVE-2021-39709
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39709
CVEs:CVE-2021-39694
In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User in...
CVEs:CVE-2021-39694
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2021-39703
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39703
CVEs:CVE-2021-39707
In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVEs:CVE-2021-39707
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-190406215
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
In ProtocolStkProactiveCommandAdapter::Init of protocolstkadapter.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is...
CVEs:CVE-2021-39722
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39722
CVEs:CVE-2021-39724
In TuningProviderBase::GetTuningTreeSet of tuning_provider_base.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not n...
CVEs:CVE-2021-39724
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2021-39729
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39729
CVEs:CVE-2021-39733
In amcs_cdev_unlocked_ioctl of audiometrics.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2021-39733
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-202006191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-204585345
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-205753190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-206128522
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-39721
In TBD of TBD, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...
CVEs:CVE-2021-39721
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39725
In gasket_free_coherent_memory_all of gasket_page_table.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2021-39725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-151454974
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-195726151
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-39734
In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User...
CVEs:CVE-2021-39734
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-208650395
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-39727
In eicPresentationRetrieveEntryValue of acropora/app/identity/libeic/EicPresentation.c, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with System execution privileges needed. User in...
CVEs:CVE-2021-39727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In usb_gadget_giveback_request of core.c, there is a possible use after free out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2021-39792
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39792
PUB-A-161010552
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-196388042
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In TBD of TBD, there is a possible user after free vulnerability due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...
CVEs:CVE-2021-39712
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39712
PUB-A-176918884
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-205243414
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the clu...
CVEs:CVE-2022-0811
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cri-o | affected | kubernetes | — | — |
Code Injection in CRI-O
CVEs:CVE-2022-0811
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cri-o/cri-o | affected | github.com | github.com/cri-o/cri-o | — |
Fix CVE(s): CVE-2021-3737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:16.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:16.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:16.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:16.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:16.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:16.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:16.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:16.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:16.04 | python2.7-minimal | — |
Fix CVE(s): CVE-2021-3737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:16.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:16.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:16.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:16.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:16.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:16.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:16.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:16.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:16.04 | python2.7-minimal | — |
Fix CVE(s): CVE-2022-0391
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:16.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:16.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:16.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:16.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:16.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:16.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:16.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:16.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:16.04 | python2.7-minimal | — |
golang.org/x/crypto/ssh Denial of service via crafted Signer
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
golang.org/x/crypto/ssh Denial of service via crafted Signer
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
DEBIAN-CVE-2022-27191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-go.crypto | affected | Debian:11 | golang-go.crypto | — |
| golang-go.crypto | affected | Debian:12 | golang-go.crypto | — |
| golang-go.crypto | affected | Debian:13 | golang-go.crypto | — |
| golang-go.crypto | affected | Debian:14 | golang-go.crypto | — |
golang.org/x/crypto/ssh Denial of service via crafted Signer
CVEs:CVE-2022-27191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
CVEs:CVE-2022-27191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| advanced_cluster_management_for_kubernetes | affected | redhat | — | — |
| extra_packages_for_enterprise_linux | affected | fedoraproject | — | — |
| fedora | affected | fedoraproject | — | — |
| ssh | affected | golang | — | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP2 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
Updated golang packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:8 | golang | — |
Security update for protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | SUSE:Linux Enterprise Installer Updates 15 SP2 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Basesystem 15 SP3 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Development Tools 15 SP3 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Package Hub 15 SP3 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Package Hub 15 SP4 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | protobuf | — |
| protobuf | affected | SUSE:Manager Server Module 4.1 | protobuf | — |
| protobuf | affected | SUSE:Manager Server Module 4.2 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Real Time 15 SP2 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Micro 5.0 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Micro 5.1 | protobuf | — |
Security update for protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openSUSE:Leap 15.3 | protobuf | — |
Security update for protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openSUSE:Leap 15.3 | protobuf | — |
PUB-A-192972537
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2021-39706
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39706
ASB-A-210292376
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
ASB-A-174738029
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2021-39698
In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...
CVEs:CVE-2021-39698
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-185125206
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2021-39713
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
CVEs:CVE-2021-39713
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| debian_linux | affected | debian | — | — |
PUB-A-173788806
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2021-39749
In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2021-39749
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39704
In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service without user notification due to a permissions bypass. This could lead to local escalation of privilege with no additional execution...
CVEs:CVE-2021-39704
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2021-39690
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39690
Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1134
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1134
Improper Input Validation in GoGo Protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ctop | affected | chainguard | ctop | — |
| ctop | affected | wolfi | ctop | — |
| gogo/protobuf | affected | github.com | github.com/gogo/protobuf | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| protobuf-c | affected | wolfi | protobuf-c | — |
| protobuf-c | affected | chainguard | protobuf-c | — |
Improper Input Validation in GoGo Protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| gogo/protobuf | affected | github.com | github.com/gogo/protobuf | — |
Updated golang packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:8 | golang | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP2 | golang | — |
CVE-2022-24921 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVE-2022-24921 affecting package golang for versions less than 1.17.8-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
CVEs:CVE-2022-24921
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| astra_trident | affected | netapp | — | — |
| debian_linux | affected | debian | — | — |
| go | affected | golang | — | — |
CVEs:CVE-2022-24921
DEBIAN-CVE-2022-24921
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
Arbitrary file read vulnerability in Jenkins kubernetes-cd Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
Arbitrary file read vulnerability in Jenkins kubernetes-cd Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
Arbitrary file read vulnerability in Jenkins kubernetes-cd Plugin
CVEs:CVE-2022-27208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller.
CVEs:CVE-2022-27208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes_continuous_deploy | affected | jenkins | — | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
CVEs:CVE-2022-0797
Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
CVEs:CVE-2022-0797
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
.NET Remote Code Execution Vulnerability
CVEs:CVE-2022-24512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x86 | — |
| Microsoft.NETCore.App.Runtime.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
.NET and Visual Studio Remote Code Execution Vulnerability
CVEs:CVE-2022-24512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| fedora | affected | fedoraproject | — | — |
| .net | affected | microsoft | — | — |
| .net_core | affected | microsoft | — | — |
| powershell | affected | microsoft | — | — |
| visual_studio_2019 | affected | microsoft | — | — |
| visual_studio_2022 | affected | microsoft | — | — |
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which result...
CVEs:CVE-2022-24726
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio | — | — |
The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against ad...
CVEs:CVE-2022-0230
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| bwp-google-xml-sitemaps | affected | bwp-google-xml-sitemaps_project | — | — |
CVEs:CVE-2022-0230
The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard
CVEs:CVE-2021-25068
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| sync_woocommerce_product_feed_to_google_shopping | affected | dpl | — | — |
CVEs:CVE-2021-25068
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
CVEs:CVE-2022-0971
Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0971
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Denial of Service via reachable assertion
CVEs:CVE-2022-24777
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc/grpc-swift | affected | github.com | github.com/grpc/grpc-swift | — |
grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is due to incorrect logic when han...
CVEs:CVE-2022-24777
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc_swift | affected | linuxfoundation | — | — |
Heap buffer overflow in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0789
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0789
CVEs:CVE-2022-0809
Out of bounds memory access in WebXR in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0809
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0800
Heap buffer overflow in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0800
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0796
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0796
CVEs:CVE-2022-0976
Heap buffer overflow in GPU in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0976
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0799
Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file.
CVEs:CVE-2022-0799
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0795
Type confusion in Blink Layout in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0795
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0792
Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0792
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0794
Use after free in WebShare in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0794
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-0806
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0806
Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions.
CVEs:CVE-2022-0791
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0791
Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.
CVEs:CVE-2022-0805
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0805
Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2022-0790
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0790
Missing permission checks in Jenkins kubernetes-cd Plugin allow enumerating credentials IDs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
Missing permission checks in Jenkins kubernetes-cd Plugin allow enumerating credentials IDs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
CSRF vulnerability and missing permission checks in Jenkins kubernetes-cd Plugin allow capturing credentials
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
CSRF vulnerability and missing permission checks in Jenkins kubernetes-cd Plugin allow capturing credentials
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
Missing permission checks in Jenkins kubernetes-cd Plugin allow enumerating credentials IDs
CVEs:CVE-2022-27209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVEs:CVE-2022-27209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes_continuous_deploy | affected | jenkins | — | — |
CSRF vulnerability and missing permission checks in Jenkins kubernetes-cd Plugin allow capturing credentials
CVEs:CVE-2022-27211
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another m...
CVEs:CVE-2022-27211
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes_continuous_deploy | affected | jenkins | — | — |
Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in a series of user interaction to potentially exploit heap corruption via user interactions.
CVEs:CVE-2022-0808
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0808
Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0977
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0977
Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2022-0807
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0807
CVEs:CVE-2022-1125
Use after free in Portals in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.
CVEs:CVE-2022-1125
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-1139
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1139
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2022-0802
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0802
CVEs:CVE-2022-0804
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2022-0804
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-1146
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1146
CVEs:CVE-2022-1133
Use after free in WebRTC Perf in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1133
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0973
Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0973
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0978
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0978
CVEs:CVE-2022-0803
Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2022-0803
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0974
Use after free in Splitscreen in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0974
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0975
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0975
Use after free in Shopping Cart in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via standard feature user interaction.
CVEs:CVE-2022-1135
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1135
Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0979
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0979
Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.
CVEs:CVE-2022-1141
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1141
CVEs:CVE-2022-1130
Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to send arbitrary intents from any app via a malicious app.
CVEs:CVE-2022-1130
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2022-1129
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1129
CVEs:CVE-2022-0972
Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-0972
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1142
Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
CVEs:CVE-2022-1142
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2021-39762
In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...
CVEs:CVE-2021-39762
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-0793
Use after free in Cast in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted Chrome Extension.
CVEs:CVE-2022-0793
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CSRF vulnerability in Jenkins kubernetes-cd Plugin allow capturing credentials
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
CSRF vulnerability in Jenkins kubernetes-cd Plugin allow capturing credentials
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method,...
CVEs:CVE-2022-27210
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes_continuous_deploy | affected | jenkins | — | — |
CSRF vulnerability in Jenkins kubernetes-cd Plugin allow capturing credentials
CVEs:CVE-2022-27210
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:kubernetes-cd | affected | Maven | org.jenkins-ci.plugins:kubernetes-cd | — |
CVEs:CVE-2022-26899
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-26899
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
CVEs:CVE-2022-0798
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0798
Use after free in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interaction and profile destruction.
CVEs:CVE-2022-1145
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1145
CVEs:CVE-2022-1137
Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially sensitive information via a crafted HTML page.
CVEs:CVE-2022-1137
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0980
Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interactions.
CVEs:CVE-2022-0980
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users cou...
CVEs:CVE-2022-0229
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_authenticator | affected | miniorange | — | — |
CVEs:CVE-2022-0229
PUB-A-207093880
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-214309660
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-214309790
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass XSS preventions via a crafted HTML page. (Chrome security severity: Medium)
CVEs:CVE-2022-0801
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-0801
Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A
CVEs:CVE-2021-39723
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39723
Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A
CVEs:CVE-2021-39737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39737
PUB-A-208229524
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-209014813
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-197850306
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-25818
Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.
CVEs:CVE-2022-25818
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-202511260
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2021-39716
Product: AndroidVersions: Android kernelAndroid ID: A-206977562References: N/A
CVEs:CVE-2021-39716
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-206977562
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-195082947
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: ...
CVEs:CVE-2021-39787
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39787
In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead to local escalation of privilege via app spoofing with no additional execution privileges needed. User interaction is needed for exp...
CVEs:CVE-2021-39764
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39764
CVEs:CVE-2021-39771
In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for...
CVEs:CVE-2021-39771
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
DEBIAN-CVE-2021-3602
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-containers-buildah | affected | Debian:11 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:12 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:13 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:14 | golang-github-containers-buildah | — |
CVEs:CVE-2021-39780
In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...
CVEs:CVE-2021-39780
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Prod...
CVEs:CVE-2021-39742
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39742
CVEs:CVE-2021-39790
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.P...
CVEs:CVE-2021-39790
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-197154735
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-1132
Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation restrictions via physical access to the device.
CVEs:CVE-2022-1132
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Incomplete validation in `SparseSparseMinimum`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Incomplete validation in `SparseSparseMinimum`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CVEs:CVE-2021-39714
In ion_buffer_kmap_get of ion.c, there is a possible use-after-free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2021-39714
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS...
CVEs:CVE-2022-20054
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20054
In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2021-39772
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39772
CVEs:CVE-2021-22571
A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.
CVEs:CVE-2021-22571
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| sa360_webquery_to_bigquery_exporter | affected | — | — |
In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2021-39686
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39686
In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2021-39711
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39711
ASB-A-200688826
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-154175781
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-20060
In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges nee...
CVEs:CVE-2022-20060
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0633...
CVEs:CVE-2022-20050
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20050
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User int...
CVEs:CVE-2022-20059
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20059
CVEs:CVE-2022-20058
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User int...
CVEs:CVE-2022-20058
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20056
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User int...
CVEs:CVE-2022-20056
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to bypass Factory Reset Protections. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...
CVEs:CVE-2021-0957
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0957
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User int...
CVEs:CVE-2022-20055
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20055
CVEs:CVE-2021-22572
On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files in the the system temporary directory with world readable permissions. Any sensitive information writte...
CVEs:CVE-2021-22572
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| data_transfer_project | affected | — | — |
In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User i...
CVEs:CVE-2021-39693
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39693
Possible filesystem space exhaustion by local users
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
Possible filesystem space exhaustion by local users
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| github.com/google/fscrypt | affected | Go | github.com/google/fscrypt | — |
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
CVEs:CVE-2022-20057
In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06271186; Issue ID: ALP...
CVEs:CVE-2022-20057
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missing permission check. This could lead to local escalation of privilege with User execution privileges ne...
CVEs:CVE-2021-39697
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39697
In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndr...
CVEs:CVE-2021-39765
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39765
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS059...
CVEs:CVE-2022-20047
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20047
CVEs:CVE-2022-20048
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS059...
CVEs:CVE-2022-20048
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-213116796
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-213120685
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-24931
Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbitrary activity without a proper permission
CVEs:CVE-2022-24931
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2021-39768
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39768
In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A...
CVEs:CVE-2022-20053
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20053
ASB-A-213120689
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-24928
Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP.
CVEs:CVE-2022-24928
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20049
In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05954679; Is...
CVEs:CVE-2022-20049
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In SmsController, there is a possible information disclosure due to a permissions bypass. This could lead to local escalation of privilege and sending sms with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2021-39781
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39781
In Bubbles, there is a possible way to interfere with Bubbles due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVEs:CVE-2021-39752
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39752
In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2021-39763
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39763
In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2021-39767
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39767
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1...
CVEs:CVE-2021-39786
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39786
In Keymaster, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2021-39741
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39741
CVEs:CVE-2021-39746
In PermissionController, there is a possible way to delete some local files due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product:...
CVEs:CVE-2021-39746
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...
CVEs:CVE-2021-39759
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39759
CVEs:CVE-2021-39717
In iaxxx_btp_write_words of iaxxx-btp.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2021-39717
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ProtocolStkProactiveCommandAdapter::Init of protocolstkadapter.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction ...
CVEs:CVE-2021-39718
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39718
CVEs:CVE-2021-39719
In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2021-39719
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In TBD of TBD, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr...
CVEs:CVE-2021-39730
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39730
CVEs:CVE-2021-39731
In ProtocolStkProactiveCommandAdapter::Init of protocolstkadapter.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction ...
CVEs:CVE-2021-39731
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39732
In copy_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2021-39732
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39736
In prepare_io_entry and prepare_response of lwis_ioctl.c and lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interact...
CVEs:CVE-2021-39736
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-198653629
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-205035540
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-205036834
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-205992503
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-205995178
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-205995773
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-206472503
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-39778
In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction...
CVEs:CVE-2021-39778
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2021-39740
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39740
In PermissionController, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2021-39757
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39757
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.
CVEs:CVE-2022-23729
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-23729
Denial of service via insufficient metadata validation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
Denial of service via insufficient metadata validation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| github.com/google/fscrypt | affected | Go | github.com/google/fscrypt | — |
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile...
CVEs:CVE-2021-39788
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39788
CVEs:CVE-2021-39791
In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges...
CVEs:CVE-2021-39791
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39766
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User i...
CVEs:CVE-2021-39766
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2021-39773
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39773
CVEs:CVE-2021-39775
In People, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User int...
CVEs:CVE-2021-39775
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In NFC, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ...
CVEs:CVE-2021-39776
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39776
In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interacti...
CVEs:CVE-2021-39777
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39777
CVEs:CVE-2021-39744
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...
CVEs:CVE-2021-39744
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39745
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...
CVEs:CVE-2021-39745
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39754
In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. Use...
CVEs:CVE-2021-39754
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution pr...
CVEs:CVE-2021-39755
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39755
CVEs:CVE-2021-39756
In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User ...
CVEs:CVE-2021-39756
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In AudioService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. Us...
CVEs:CVE-2021-39760
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39760
CVEs:CVE-2021-39761
In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User inte...
CVEs:CVE-2021-39761
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2021-39739
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39739
Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.
CVEs:CVE-2022-25821
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-25821
CVEs:CVE-2021-39624
In PackageManager, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2021-39624
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication
CVEs:CVE-2022-25816
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-25816
CVEs:CVE-2022-25819
OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.
CVEs:CVE-2022-25819
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-24932
Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.
CVEs:CVE-2022-24932
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| cloud | affected | samsung | — | — |
Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.
CVEs:CVE-2022-25817
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-25817
In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andro...
CVEs:CVE-2022-20002
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20002
CVEs:CVE-2021-39774
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2021-39774
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2021-39747
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39747
CVEs:CVE-2021-1000
In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...
CVEs:CVE-2021-1000
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...
CVEs:CVE-2021-1033
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-1033
In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch...
CVEs:CVE-2022-20051
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20051
CVEs:CVE-2021-39689
In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2021-39689
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39789
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVEs:CVE-2021-39789
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39769
In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User inter...
CVEs:CVE-2021-39769
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39770
In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2021-39770
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call state with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2021-39779
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39779
In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2021-39782
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39782
CVEs:CVE-2021-39783
In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andro...
CVEs:CVE-2021-39783
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2021-39784
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39784
CVEs:CVE-2021-39743
In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...
CVEs:CVE-2021-39743
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39748
In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2021-39748
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39750
In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2021-39750
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39751
In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2021-39751
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39753
In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is n...
CVEs:CVE-2021-39753
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee...
CVEs:CVE-2021-39758
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39758
CVEs:CVE-2022-25820
A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.
CVEs:CVE-2022-25820
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-24929
Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.
CVEs:CVE-2022-24929
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
CVEs:CVE-2022-25815
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-25815
PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
CVEs:CVE-2022-25814
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-25814
In gasket_alloc_coherent_memory of gasket_page_table.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2021-39735
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39735
PUB-A-151455484
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-0343
A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typically a developer) manually invoked the ./tools/run-dev-server script. It is recommended to upgrade to any version beyond 24.2
CVEs:CVE-2022-0343
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| perfetto | affected | — | — |
An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.
CVEs:CVE-2022-25822
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-25822
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
Possible privilege escalation via bash completion script
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| github.com/google/fscrypt | affected | Go | github.com/google/fscrypt | — |
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
Possible privilege escalation via bash completion script
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google/fscrypt | affected | github.com | github.com/google/fscrypt | — |
PUB-A-214310168
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.