Google Security Advisories · April 2022 — Google Security Advisories
382 advisories 232 CVEs 17 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2022-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 17 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DEBIAN-CVE-2022-0609

Open SourceExploitedCISA KEV listedCRITICAL2022-04-05

DEBIAN-CVE-2022-0609

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

MGASA-2022-0146

Open SourceExploitedCISA KEV listedCRITICAL2022-04-18

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

openSUSE-SU-2022:0114-1

Open SourceExploitedCISA KEV listed2022-04-19

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

CVE-2022-1364

Project ZeroExploitedCISA KEV listed2022-04-18

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1364

Upstream advisory

CVE-2022-1364

GoogleExploitedCISA KEV listedHIGH2022-04-18

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1364

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DSA-5121-1

Open SourceExploitedCISA KEV listed2022-04-16

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-22675

Project ZeroExploitedCISA KEV listed2022-04-01

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CVEs:CVE-2022-22675

Upstream advisory

CVE-2022-22675

GoogleExploitedCISA KEV listedCRITICAL2022-04-01

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code wit...

CVEs:CVE-2022-22675

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-24521

GoogleExploitedCISA KEV listedCRITICAL2022-04-12

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVEs:CVE-2022-24521

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_10_21h2 affected microsoft
windows_11_21h2 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

CVE-2022-22674

GoogleExploitedCISA KEV listedMEDIUM2022-04-01

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may ...

CVEs:CVE-2022-22674

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2022-22674

Project ZeroExploitedCISA KEV listed2022-04-01

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.

CVEs:CVE-2022-22674

Upstream advisory

DEBIAN-CVE-2022-0456

Open SourceExploitedVulnCheck KEV listedCRITICAL2022-04-05

DEBIAN-CVE-2022-0456

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-1483

GoogleActive exploitation (sightings)CRITICAL2022-04-27

Heap buffer overflow in WebGPU in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1483

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DSA-5125-1

Open SourceActive exploitation (sightings)2022-04-27

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-1487

GoogleActive exploitation (sightings)CRITICAL2022-04-29

Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via running a Wayland test.

CVEs:CVE-2022-1487

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1484

GoogleActive exploitation (sightings)CRITICAL2022-04-27

Heap buffer overflow in Web UI Settings in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1484

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1477

GoogleActive exploitation (sightings)CRITICAL2022-04-27

Use after free in Vulkan in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1477

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1481

GoogleActive exploitation (sightings)HIGH2022-04-27

Use after free in Sharing in Google Chrome on Mac prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1481

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-29146

Open SourceActive exploitation (sightings)CRITICAL2022-04-12

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-29146

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-1479

GoogleActive exploitation (sightings)CRITICAL2022-04-27

Use after free in ANGLE in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1479

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1486

GoogleActive exploitation (sightings)HIGH2022-04-27

Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2022-1486

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1485

GoogleActive exploitation (sightings)CRITICAL2022-04-27

Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1485

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1490

GoogleActive exploitation (sightings)HIGH2022-04-29

Use after free in Browser Switcher in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1490

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1491

GoogleActive exploitation (sightings)HIGH2022-04-29

Use after free in Bookmarks in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.

CVEs:CVE-2022-1491

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1493

GoogleActive exploitation (sightings)HIGH2022-04-29

Use after free in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.

CVEs:CVE-2022-1493

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1501

GoogleActive exploitation (sightings)MEDIUM2022-04-29

Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-1501

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1482

GoogleActive exploitation (sightings)MEDIUM2022-04-27

Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1482

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1498

GoogleActive exploitation (sightings)MEDIUM2022-04-29

Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-1498

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1494

GoogleActive exploitation (sightings)MEDIUM2022-04-29

Insufficient data validation in Trusted Types in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass trusted types policy via a crafted HTML page.

CVEs:CVE-2022-1494

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1492

GoogleActive exploitation (sightings)MEDIUM2022-04-29

Insufficient data validation in Blink Editing in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page.

CVEs:CVE-2022-1492

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1499

GoogleActive exploitation (sightings)MEDIUM2022-04-29

Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVEs:CVE-2022-1499

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1500

GoogleActive exploitation (sightings)MEDIUM2022-04-29

Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2022-1500

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1495

GoogleActive exploitation (sightings)MEDIUM2022-04-29

Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a remote attacker to spoof the APK downloads dialog via a crafted HTML page.

CVEs:CVE-2022-1495

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-29147

Open SourceActive exploitation (sightings)LOW2022-04-12

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2022-29147

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-1488

GoogleActive exploitation (sightings)MEDIUM2022-04-29

Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.

CVEs:CVE-2022-1488

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1497

GoogleActive exploitation (sightings)MEDIUM2022-04-29

Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.

CVEs:CVE-2022-1497

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

AZL-9527

Open SourcePoC exploitCRITICAL2022-04-20

CVE-2022-24675 affecting package golang for versions less than 1.18.3-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

CVE-2022-24675

Open SourcePoC exploitCRITICAL2022-04-20

encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.

CVEs:CVE-2022-24675

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
kubernetes_monitoring_operator affected netapp
Upstream advisory

RHSA-2022:1276

Open SourcePoC exploitCRITICAL2022-04-07

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.0.9 security update

Affected products

ProductStatusVendorPackageEcosystem
kiali affected Red Hat:service_mesh:2.0::el8 kiali
servicemesh affected Red Hat:service_mesh:2.0::el8 servicemesh
servicemesh-istioctl affected Red Hat:service_mesh:2.0::el8 servicemesh-istioctl
servicemesh-mixc affected Red Hat:service_mesh:2.0::el8 servicemesh-mixc
servicemesh-mixs affected Red Hat:service_mesh:2.0::el8 servicemesh-mixs
servicemesh-pilot-agent affected Red Hat:service_mesh:2.0::el8 servicemesh-pilot-agent
servicemesh-pilot-discovery affected Red Hat:service_mesh:2.0::el8 servicemesh-pilot-discovery
servicemesh-prometheus affected Red Hat:service_mesh:2.0::el8 servicemesh-prometheus
servicemesh-proxy affected Red Hat:service_mesh:2.0::el8 servicemesh-proxy
Upstream advisory

SUSE-SU-2022:1435-1

Open SourcePoC exploitHIGH2022-04-27

Security update for firewalld, golang-github-prometheus-prometheus

Affected products

ProductStatusVendorPackageEcosystem
firewalld affected SUSE:Linux Enterprise Micro 5.1 firewalld
firewalld affected openSUSE:Leap 15.3 firewalld
firewalld affected SUSE:Linux Enterprise Module for Basesystem 15 SP3 firewalld
firewalld affected SUSE:Linux Enterprise Module for Desktop Applications 15 SP3 firewalld
firewalld affected SUSE:Linux Enterprise Micro 5.2 firewalld
golang-github-prometheus-prometheus affected openSUSE:Leap 15.4 golang-github-prometheus-prometheus
golang-github-prometheus-prometheus affected SUSE:Manager Proxy Module 4.1 golang-github-prometheus-prometheus
golang-github-prometheus-prometheus affected SUSE:Manager Proxy Module 4.2 golang-github-prometheus-prometheus
golang-github-prometheus-prometheus affected SUSE:Enterprise Storage 6 golang-github-prometheus-prometheus
golang-github-prometheus-prometheus affected openSUSE:Leap 15.3 golang-github-prometheus-prometheus
Upstream advisory

SUSE-SU-2022:1434-1

Open SourcePoC exploitHIGH2022-04-27

Security update for golang-github-prometheus-prometheus

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 15 golang-github-prometheus-prometheus
Upstream advisory

SUSE-SU-2022:1433-1

Open SourcePoC exploitHIGH2022-04-27

Security update for golang-github-prometheus-prometheus

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 12 golang-github-prometheus-prometheus
Upstream advisory

DEBIAN-CVE-2022-1227

Open SourcePoC exploitHIGH2022-04-29

DEBIAN-CVE-2022-1227

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-psgo affected Debian:11 golang-github-containers-psgo
golang-github-containers-psgo affected Debian:12 golang-github-containers-psgo
golang-github-containers-psgo affected Debian:13 golang-github-containers-psgo
golang-github-containers-psgo affected Debian:14 golang-github-containers-psgo
libpod affected Debian:11 libpod
libpod affected Debian:12 libpod
Upstream advisory

GO-2021-0356

Open SourcePoC exploitHIGH2022-04-25

Denial of service via crafted Signer in golang.org/x/crypto/ssh

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
k3d affected wolfi k3d
k3d affected chainguard k3d
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CLSA-2022-1649348075

Open SourcePoC exploitHIGH2022-04-07

Fix CVE(s): CVE-2021-4189

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

CLSA-2022-1649170553

Open SourcePoC exploitHIGH2022-04-05

Fix CVE(s): CVE-2021-4189

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

DLA-2985-1

Open SourcePoC exploit2022-04-28

golang-1.7 - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-1.7 affected Debian:9 golang-1.7
Upstream advisory

DLA-2986-1

Open SourcePoC exploit2022-04-28

golang-1.8 - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-1.8 affected Debian:9 golang-1.8
Upstream advisory

SUSE-SU-2022:1040-2

Open SourcePoC exploit2022-04-19

Security update for protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected SUSE:Linux Enterprise Micro 5.2 protobuf
Upstream advisory

OESA-2022-1606

Open SourcePoC exploit2022-04-08

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler
golang affected openEuler:20.03-LTS-SP2 golang
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP3 golang
Upstream advisory

PUB-A-217307370

GooglePoC exploitHIGH2022-04-01

PUB-A-217307370

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2020-23349

Open SourcePoC exploitHIGH2022-04-05

An intent redirection issue was doscovered in Sina Weibo Android SDK 4.2.7 (com.sina.weibo.sdk.share.WbShareTransActivity), any unexported Activities could be started by the com.sina.weibo.sdk.share.WbShareTransActivity.

CVEs:CVE-2020-23349

Affected products

ProductStatusVendorPackageEcosystem
android_software_development_kit affected weibo
Upstream advisory

PUB-A-216607118

GooglePoC exploitMEDIUM2022-04-01

PUB-A-216607118

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20368

Open SourcePoC exploitHIGH2022-04-07

Product: AndroidVersions: Android kernelAndroid ID: A-224546354References: Upstream kernel

CVEs:CVE-2022-20368

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2022-0130

Open SourceCoalition ESS 30-63%CRITICAL2022-04-05

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

DSA-5112-1

Open SourceCoalition ESS 30-63%2022-04-03

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

DSA-5114-1

Open SourceCoalition ESS < 30%2022-04-07

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-1232

GoogleCoalition ESS < 30%HIGH2022-04-05

Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1232

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

AZL-9547

Open SourceCoalition ESS < 30%HIGH2022-04-20

CVE-2022-28327 affecting package golang for versions less than 1.18.3-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

CVE-2022-28327

GoogleCoalition ESS < 30%HIGH2022-04-20

The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.

CVEs:CVE-2022-28327

Affected products

ProductStatusVendorPackageEcosystem
extra_packages_for_enterprise_linux affected fedoraproject
fedora affected fedoraproject
go affected golang
Upstream advisory

CVE-2022-24475

Open SourceCoalition ESS < 30%CRITICAL2022-04-04

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-24475

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-26891

Open SourceCoalition ESS < 30%CRITICAL2022-04-04

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-26891

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-26894

Open SourceCoalition ESS < 30%CRITICAL2022-04-04

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-26894

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-26895

Open SourceCoalition ESS < 30%CRITICAL2022-04-04

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-26895

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-26900

Open SourceCoalition ESS < 30%CRITICAL2022-04-04

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-26900

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-26908

Open SourceCoalition ESS < 30%CRITICAL2022-04-04

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-26908

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-26909

Open SourceCoalition ESS < 30%CRITICAL2022-04-04

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-26909

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-26912

Open SourceCoalition ESS < 30%CRITICAL2022-04-04

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-26912

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2022-0797

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0797

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

AZL-78958

Open SourceCoalition ESS < 30%HIGH2022-04-20

CVE-2022-27536 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2022-27536

GoogleCoalition ESS < 30%HIGH2022-04-20

Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.

CVEs:CVE-2022-27536

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2022-26098

Open SourceCoalition ESS < 30%HIGH2022-04-11

Heap-based buffer overflow vulnerability in sheifd_create function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.

CVEs:CVE-2022-26098

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27568

Open SourceCoalition ESS < 30%HIGH2022-04-11

Heap-based buffer overflow vulnerability in parser_iloc function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.

CVEs:CVE-2022-27568

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27569

Open SourceCoalition ESS < 30%HIGH2022-04-11

Heap-based buffer overflow vulnerability in parser_infe function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.

CVEs:CVE-2022-27569

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27570

Open SourceCoalition ESS < 30%HIGH2022-04-11

Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.

CVEs:CVE-2022-27570

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27571

Open SourceCoalition ESS < 30%HIGH2022-04-11

Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.

CVEs:CVE-2022-27571

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27572

Open SourceCoalition ESS < 30%HIGH2022-04-11

Heap-based buffer overflow vulnerability in parser_ipma function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.

CVEs:CVE-2022-27572

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-24523

Open SourceCoalition ESS < 30%MEDIUM2022-04-04

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2022-24523

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2022-27651

Open SourceCoalition ESS < 30%MEDIUM2022-04-04

DEBIAN-CVE-2022-27651

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-buildah affected Debian:11 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:12 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:13 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:14 golang-github-containers-buildah
Upstream advisory

DEBIAN-CVE-2022-0789

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0789

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0608

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0608

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-5120-1

Open SourceCoalition ESS < 30%2022-04-13

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-1310

GoogleCoalition ESS < 30%CRITICAL2022-04-12

Use after free in regular expressions in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1310

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0809

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0809

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2022-0567

Open SourceCoalition ESS < 30%CRITICAL2022-04-20

A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that shoul...

CVEs:CVE-2022-0567

Affected products

ProductStatusVendorPackageEcosystem
ovn-kubernetes affected ovn
Upstream advisory

DEBIAN-CVE-2022-0800

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0800

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0796

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0796

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-1308

GoogleCoalition ESS < 30%CRITICAL2022-04-12

Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1308

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0799

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0799

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-29144

Open SourceCoalition ESS < 30%CRITICAL2022-04-12

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-29144

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2022-0795

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0795

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0792

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

DEBIAN-CVE-2022-0792

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0794

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0794

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0806

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0806

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0470

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0470

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0467

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0467

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-1478

GoogleCoalition ESS < 30%CRITICAL2022-04-27

Use after free in SwiftShader in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1478

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1313

GoogleCoalition ESS < 30%CRITICAL2022-04-12

Use after free in tab groups in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1313

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0805

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0805

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0791

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0791

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-1305

GoogleCoalition ESS < 30%CRITICAL2022-04-12

Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1305

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1314

GoogleCoalition ESS < 30%HIGH2022-04-12

Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1314

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0790

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0790

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0808

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0808

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0807

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

DEBIAN-CVE-2022-0807

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0454

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0454

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0802

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

DEBIAN-CVE-2022-0802

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0804

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

DEBIAN-CVE-2022-0804

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-1127

GoogleCoalition ESS < 30%HIGH2022-04-04

Use after free in QR Code Generator in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

CVEs:CVE-2022-1127

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1131

GoogleCoalition ESS < 30%CRITICAL2022-04-04

Use after free in Cast UI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1131

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1138

GoogleCoalition ESS < 30%MEDIUM2022-04-04

Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2022-1138

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-0431

GoogleCoalition ESS < 30%CRITICAL2022-04-04

The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting

CVEs:CVE-2022-0431

Affected products

ProductStatusVendorPackageEcosystem
insights_from_google_pagespeed affected insights_from_google_pagespeed_project
Upstream advisory

CVE-2022-1311

GoogleCoalition ESS < 30%CRITICAL2022-04-12

Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1311

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0803

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

DEBIAN-CVE-2022-0803

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0462

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

DEBIAN-CVE-2022-0462

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0461

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

DEBIAN-CVE-2022-0461

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-1309

GoogleCoalition ESS < 30%CRITICAL2022-04-12

Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2022-1309

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1143

GoogleCoalition ESS < 30%HIGH2022-04-04

Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.

CVEs:CVE-2022-1143

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0464

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0464

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2022-0603

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0603

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0606

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0606

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2022-0607

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0607

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-46780

GoogleCoalition ESS < 30%CRITICAL2022-04-25

The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVEs:CVE-2021-46780

Affected products

ProductStatusVendorPackageEcosystem
easy_google_maps affected supsystic
Upstream advisory

DEBIAN-CVE-2022-0459

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0459

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-1306

GoogleCoalition ESS < 30%MEDIUM2022-04-12

Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2022-1306

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1307

GoogleCoalition ESS < 30%MEDIUM2022-04-12

Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2022-1307

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0610

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0610

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0457

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0457

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0460

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0460

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0452

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0452

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0453

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0453

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0465

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0465

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-39809

Open SourceCoalition ESS < 30%HIGH2022-04-05

In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2021-39809

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-vhxq-9mpv-gj87

GoogleCoalition ESS < 30%MEDIUM2022-04-13

Private key stored in plain text by Jenkins Google Compute Engine Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

GHSA-vhxq-9mpv-gj87

GoogleCoalition ESS < 30%MEDIUM2022-04-13

Private key stored in plain text by Jenkins Google Compute Engine Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

CVE-2022-29052

GoogleCoalition ESS < 30%MEDIUM2022-04-12

Private key stored in plain text by Jenkins Google Compute Engine Plugin

CVEs:CVE-2022-29052

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

CVE-2022-29052

GoogleCoalition ESS < 30%MEDIUM2022-04-12

Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file s...

CVEs:CVE-2022-29052

Affected products

ProductStatusVendorPackageEcosystem
google_compute_engine affected jenkins
Upstream advisory

DEBIAN-CVE-2022-0458

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0458

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0793

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0793

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2022-0468

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0468

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0469

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0469

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0463

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0463

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-1128

GoogleCoalition ESS < 30%MEDIUM2022-04-04

Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-1128

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0798

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0798

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0455

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

DEBIAN-CVE-2022-0455

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-0604

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0604

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-39803

Open SourceCoalition ESS < 30%HIGH2022-04-05

In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Androi...

CVEs:CVE-2021-39803

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-1136

GoogleCoalition ESS < 30%CRITICAL2022-04-04

Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific set of user gestures.

CVEs:CVE-2022-1136

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1312

GoogleCoalition ESS < 30%CRITICAL2022-04-12

Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVEs:CVE-2022-1312

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-0466

Open SourceCoalition ESS < 30%CRITICAL2022-04-05

DEBIAN-CVE-2022-0466

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2022-0605

Open SourceCoalition ESS < 30%HIGH2022-04-05

DEBIAN-CVE-2022-0605

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-20081

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A...

CVEs:CVE-2022-20081

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-218242055

GoogleCoalition ESS < 30%MEDIUM2022-04-01

ASB-A-218242055

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-26093

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Null pointer dereference vulnerability in parser_irot function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVEs:CVE-2022-26093

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26094

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVEs:CVE-2022-26094

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26095

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Null pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVEs:CVE-2022-26095

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26096

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Null pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVEs:CVE-2022-26096

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26097

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Null pointer dereference vulnerability in parser_unknown_property function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVEs:CVE-2022-26097

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26099

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.

CVEs:CVE-2022-26099

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27567

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.

CVEs:CVE-2022-27567

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-220262213

GoogleCoalition ESS < 30%HIGH2022-04-01

ASB-A-220262213

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39804

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persistent denial of service in the file picker with no additional execution privileges needed. User interaction is needed for exploitati...

CVEs:CVE-2021-39804

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27574

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attacker.

CVEs:CVE-2022-27574

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27573

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attackers.

CVEs:CVE-2022-27573

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20072

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

In search engine service, there is a possible way to change the default search engine due to an incorrect comparison. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitati...

CVEs:CVE-2022-20072

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39794

Open SourceCoalition ESS < 30%HIGH2022-04-05

In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no additional execution ...

CVEs:CVE-2021-39794

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-28779

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code.

CVEs:CVE-2022-28779

Affected products

ProductStatusVendorPackageEcosystem
android_usb_driver_windows_installer affected samsung
Upstream advisory

CVE-2022-27835

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

CVEs:CVE-2022-27835

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27824

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file

CVEs:CVE-2022-27824

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27823

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

CVEs:CVE-2022-27823

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27821

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via crafted image file.

CVEs:CVE-2022-27821

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39805

Open SourceCoalition ESS < 30%MEDIUM2022-04-05

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2021-39805

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27576

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission

CVEs:CVE-2022-27576

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27575

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.

CVEs:CVE-2022-27575

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27652

GoogleCoalition ESS < 30%MEDIUM2022-04-18

Incorrect Default Permissions in CRI-O

CVEs:CVE-2022-27652

Affected products

ProductStatusVendorPackageEcosystem
cri-o/cri-o affected github.com github.com/cri-o/cri-o
Upstream advisory

CVE-2022-27652

GoogleCoalition ESS < 30%MEDIUM2022-04-18

Incorrect Default Permissions in CRI-O

CVEs:CVE-2022-27652

Affected products

ProductStatusVendorPackageEcosystem
cri-o/cri-o affected github.com github.com/cri-o/cri-o
Upstream advisory

CVE-2022-27652

GoogleCoalition ESS < 30%MEDIUM2022-04-18

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This ...

CVEs:CVE-2022-27652

Affected products

ProductStatusVendorPackageEcosystem
cri-o affected kubernetes
fedora affected fedoraproject
moby affected mobyproject
openshift_container_platform affected redhat
Upstream advisory

CVE-2022-27825

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

CVEs:CVE-2022-27825

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20073

Open SourceCoalition ESS < 30%HIGH2022-04-11

In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User intera...

CVEs:CVE-2022-20073

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-39796

Open SourceCoalition ESS < 30%HIGH2022-04-12

DEBIAN-CVE-2021-39796

Affected products

ProductStatusVendorPackageEcosystem
android-platform-frameworks-base affected Debian:11 android-platform-frameworks-base
android-platform-frameworks-base affected Debian:12 android-platform-frameworks-base
android-platform-frameworks-base affected Debian:13 android-platform-frameworks-base
android-platform-frameworks-base affected Debian:14 android-platform-frameworks-base
Upstream advisory

CVE-2021-39796

Open SourceCoalition ESS < 30%HIGH2022-04-05

In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. U...

CVEs:CVE-2021-39796

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-155756045

GoogleCoalition ESS < 30%HIGH2022-04-01

ASB-A-155756045

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-27826

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2022-27826

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-204905109

GoogleCoalition ESS < 30%2022-04-01

ASB-A-204905109

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-213239835

GoogleCoalition ESS < 30%2022-04-01

ASB-A-213239835

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/opensource/display-drivers affected platform platform/vendor/opensource/display-drivers
Upstream advisory

ASB-A-213240026

GoogleCoalition ESS < 30%2022-04-01

ASB-A-213240026

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-39802

Open SourceCoalition ESS < 30%HIGH2022-04-05

In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2021-39802

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-213339151

GoogleCoalition ESS < 30%MEDIUM2022-04-01

ASB-A-213339151

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-27836

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation...

CVEs:CVE-2022-27836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-204905206

GoogleCoalition ESS < 30%2022-04-01

ASB-A-204905206

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-39800

Open SourceCoalition ESS < 30%HIGH2022-04-05

In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2021-39800

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-208277166

GoogleCoalition ESS < 30%HIGH2022-04-01

ASB-A-208277166

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-26092

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.

CVEs:CVE-2022-26092

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27827

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2022-27827

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27828

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2022-27828

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20052

Open SourceCoalition ESS < 30%HIGH2022-04-11

In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS05836642; Issue ID: ALPS05836642.

CVEs:CVE-2022-20052

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27829

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2022-27829

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27830

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2022-27830

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-201574693

GoogleCoalition ESS < 30%2022-04-01

ASB-A-201574693

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-20063

Open SourceCoalition ESS < 30%HIGH2022-04-11

In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06171715; Issue ID...

CVEs:CVE-2022-20063

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20074

Open SourceCoalition ESS < 30%HIGH2022-04-11

In preloader (partition), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. Us...

CVEs:CVE-2022-20074

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20075

Open SourceCoalition ESS < 30%HIGH2022-04-11

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05838808; Issue ID: ALP...

CVEs:CVE-2022-20075

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20064

Open SourceCoalition ESS < 30%HIGH2022-04-11

In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108617; Issu...

CVEs:CVE-2022-20064

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20068

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06...

CVEs:CVE-2022-20068

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20069

Open SourceCoalition ESS < 30%HIGH2022-04-11

In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User intera...

CVEs:CVE-2022-20069

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20062

Open SourceCoalition ESS < 30%HIGH2022-04-11

In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836418; Issue ID: ALPS05836...

CVEs:CVE-2022-20062

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20066

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...

CVEs:CVE-2022-20066

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27822

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.

CVEs:CVE-2022-27822

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39799

Open SourceCoalition ESS < 30%HIGH2022-04-05

In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2021-39799

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39801

Open SourceCoalition ESS < 30%HIGH2022-04-05

In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2021-39801

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-209791720

GoogleCoalition ESS < 30%HIGH2022-04-01

ASB-A-209791720

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20065

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108658; Issue ID: A...

CVEs:CVE-2022-20065

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20067

Open SourceCoalition ESS < 30%HIGH2022-04-11

In mdp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836585; Issue ID: A...

CVEs:CVE-2022-20067

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39797

Open SourceCoalition ESS < 30%HIGH2022-04-05

In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2021-39797

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39798

Open SourceCoalition ESS < 30%HIGH2022-04-05

In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-39798

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39812

Open SourceCoalition ESS < 30%HIGH2022-04-05

In TBD of TBD, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...

CVEs:CVE-2021-39812

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39814

Open SourceCoalition ESS < 30%HIGH2022-04-05

In ppmp_validate_wsm of drm_fw.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2021-39814

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-205522359

GoogleCoalition ESS < 30%HIGH2022-04-01

PUB-A-205522359

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-216792660

GoogleCoalition ESS < 30%HIGH2022-04-01

PUB-A-216792660

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-25832

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication.

CVEs:CVE-2022-25832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20076

Open SourceCoalition ESS < 30%HIGH2022-04-11

In ged, there is a possible memory corruption due to an incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05838808; Issue ID...

CVEs:CVE-2022-20076

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20070

Open SourceCoalition ESS < 30%HIGH2022-04-11

In ssmr, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06362920; Issue ID: ...

CVEs:CVE-2022-20070

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20079

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

In vow, there is a possible read of uninitialized data due to a improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05837742; ...

CVEs:CVE-2022-20079

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0694

Open SourceCoalition ESS < 30%HIGH2022-04-05

In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could lead to local escalation of privilege with no addit...

CVEs:CVE-2021-0694

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39807

Open SourceCoalition ESS < 30%HIGH2022-04-05

In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. This could lead to local escalation of privilege from the Guest account with no additional execution priv...

CVEs:CVE-2021-39807

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39808

Open SourceCoalition ESS < 30%HIGH2022-04-05

In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to local escalation of privilege with no additional exec...

CVEs:CVE-2021-39808

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-25833

Open SourceCoalition ESS < 30%LOW2022-04-11

Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission.

CVEs:CVE-2022-25833

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27833

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.

CVEs:CVE-2022-27833

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26090

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

Improper access control vulnerability in SamsungContacts prior to SMR Apr-2022 Release 1 allows that attackers can access contact information without permission.

CVEs:CVE-2022-26090

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26091

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard.

CVEs:CVE-2022-26091

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20077

Open SourceCoalition ESS < 30%HIGH2022-04-11

In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05837742; Issue ID: ALPS05852...

CVEs:CVE-2022-20077

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20078

Open SourceCoalition ESS < 30%HIGH2022-04-11

In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05852819; Issue ID: ALPS05852...

CVEs:CVE-2022-20078

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20080

Open SourceCoalition ESS < 30%HIGH2022-04-11

In SUB2AF, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05881290; Issue ID: ALPS05...

CVEs:CVE-2022-20080

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27832

Open SourceCoalition ESS < 30%HIGH2022-04-11

Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.

CVEs:CVE-2022-27832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-25831

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access secured data in certain conditions.

CVEs:CVE-2022-25831

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27831

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read out of bounds memory.

CVEs:CVE-2022-27831

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-27834

Open SourceCoalition ESS < 30%CRITICAL2022-04-11

Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions.

CVEs:CVE-2022-27834

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20071

Open SourceCoalition ESS < 30%MEDIUM2022-04-11

In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS0618331...

CVEs:CVE-2022-20071

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-mqf3-28j7-3mj6

Open SourceEPSS <= 49%HIGH2022-04-12

Information Exposure in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-mqf3-28j7-3mj6

Open SourceEPSS <= 49%HIGH2022-04-12

Information Exposure in Kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.