Advisories
Open SourceExploitedCISA KEV listedCRITICAL2022-04-05
DEBIAN-CVE-2022-0609
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceExploitedCISA KEV listedCRITICAL2022-04-18
Updated chromium-browser-stable packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:8 |
chromium-browser-stable |
— |
Open SourceExploitedCISA KEV listed2022-04-19
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
Project ZeroExploitedCISA KEV listed2022-04-18
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1364
GoogleExploitedCISA KEV listedHIGH2022-04-18
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1364
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleExploitedCISA KEV listedHIGH2022-04-18
CVEs:CVE-2022-1364
Open SourceExploitedCISA KEV listed2022-04-16
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
Project ZeroExploitedCISA KEV listed2022-04-01
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
CVEs:CVE-2022-22675
GoogleExploitedCISA KEV listedCRITICAL2022-04-01
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code wit...
CVEs:CVE-2022-22675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
GoogleExploitedCISA KEV listedHIGH2022-04-01
CVEs:CVE-2022-22675
GoogleExploitedCISA KEV listedHIGH2022-04-13
CVEs:CVE-2022-24521
GoogleExploitedCISA KEV listedCRITICAL2022-04-12
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVEs:CVE-2022-24521
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1507 |
affected |
microsoft |
— |
— |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_10_1909 |
affected |
microsoft |
— |
— |
| windows_10_20h2 |
affected |
microsoft |
— |
— |
| windows_10_21h1 |
affected |
microsoft |
— |
— |
| windows_10_21h2 |
affected |
microsoft |
— |
— |
| windows_11_21h2 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
| windows_server_2022 |
affected |
microsoft |
— |
— |
| windows_server_20h2 |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2022-04-12
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVEs:CVE-2022-24521
GoogleExploitedCISA KEV listedMEDIUM2022-04-01
CVEs:CVE-2022-22674
GoogleExploitedCISA KEV listedMEDIUM2022-04-01
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may ...
CVEs:CVE-2022-22674
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2022-04-01
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.
CVEs:CVE-2022-22674
Open SourceExploitedVulnCheck KEV listedCRITICAL2022-04-05
DEBIAN-CVE-2022-0456
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2022-04-27
Heap buffer overflow in WebGPU in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1483
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-04-27
CVEs:CVE-2022-1483
Open SourceActive exploitation (sightings)2022-04-27
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2022-04-29
CVEs:CVE-2022-1487
GoogleActive exploitation (sightings)CRITICAL2022-04-29
Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via running a Wayland test.
CVEs:CVE-2022-1487
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)CRITICAL2022-04-27
Heap buffer overflow in Web UI Settings in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1484
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-04-27
CVEs:CVE-2022-1484
GoogleActive exploitation (sightings)CRITICAL2022-04-27
Use after free in Vulkan in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1477
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-04-27
CVEs:CVE-2022-1477
GoogleActive exploitation (sightings)HIGH2022-04-27
Use after free in Sharing in Google Chrome on Mac prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-04-27
CVEs:CVE-2022-1481
GoogleActive exploitation (sightings)HIGH2022-04-29
CVEs:CVE-2022-29146
Open SourceActive exploitation (sightings)CRITICAL2022-04-12
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-29146
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-04-27
CVEs:CVE-2022-1479
GoogleActive exploitation (sightings)CRITICAL2022-04-27
Use after free in ANGLE in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1479
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-04-27
Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2022-1486
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-04-27
CVEs:CVE-2022-1486
GoogleActive exploitation (sightings)HIGH2022-04-27
CVEs:CVE-2022-1485
GoogleActive exploitation (sightings)CRITICAL2022-04-27
Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1485
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-04-29
Use after free in Browser Switcher in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1490
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-04-29
CVEs:CVE-2022-1490
GoogleActive exploitation (sightings)HIGH2022-04-29
Use after free in Bookmarks in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.
CVEs:CVE-2022-1491
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-04-29
CVEs:CVE-2022-1491
GoogleActive exploitation (sightings)HIGH2022-04-29
CVEs:CVE-2022-1493
GoogleActive exploitation (sightings)HIGH2022-04-29
Use after free in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.
CVEs:CVE-2022-1493
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-29
Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-1501
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-29
CVEs:CVE-2022-1501
GoogleActive exploitation (sightings)MEDIUM2022-04-27
Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1482
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-27
CVEs:CVE-2022-1482
GoogleActive exploitation (sightings)MEDIUM2022-04-29
CVEs:CVE-2022-1498
GoogleActive exploitation (sightings)MEDIUM2022-04-29
Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-1498
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-29
Insufficient data validation in Trusted Types in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass trusted types policy via a crafted HTML page.
CVEs:CVE-2022-1494
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-29
CVEs:CVE-2022-1494
GoogleActive exploitation (sightings)MEDIUM2022-04-29
CVEs:CVE-2022-1492
GoogleActive exploitation (sightings)MEDIUM2022-04-29
Insufficient data validation in Blink Editing in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page.
CVEs:CVE-2022-1492
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-29
CVEs:CVE-2022-1499
GoogleActive exploitation (sightings)MEDIUM2022-04-29
Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
CVEs:CVE-2022-1499
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-29
CVEs:CVE-2022-1500
GoogleActive exploitation (sightings)MEDIUM2022-04-29
Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVEs:CVE-2022-1500
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-29
CVEs:CVE-2022-1495
GoogleActive exploitation (sightings)MEDIUM2022-04-29
Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a remote attacker to spoof the APK downloads dialog via a crafted HTML page.
CVEs:CVE-2022-1495
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2022-04-29
CVEs:CVE-2022-29147
Open SourceActive exploitation (sightings)LOW2022-04-12
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2022-29147
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-29
Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.
CVEs:CVE-2022-1488
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-29
CVEs:CVE-2022-1488
GoogleActive exploitation (sightings)MEDIUM2022-04-29
Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.
CVEs:CVE-2022-1497
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-04-29
CVEs:CVE-2022-1497
Open SourcePoC exploitCRITICAL2022-04-20
CVE-2022-24675 affecting package golang for versions less than 1.18.3-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2022-04-20
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
CVEs:CVE-2022-24675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
| kubernetes_monitoring_operator |
affected |
netapp |
— |
— |
GooglePoC exploitHIGH2022-04-20
CVEs:CVE-2022-24675
Open SourcePoC exploitCRITICAL2022-04-07
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.0.9 security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kiali |
affected |
Red Hat:service_mesh:2.0::el8 |
kiali |
— |
| servicemesh |
affected |
Red Hat:service_mesh:2.0::el8 |
servicemesh |
— |
| servicemesh-istioctl |
affected |
Red Hat:service_mesh:2.0::el8 |
servicemesh-istioctl |
— |
| servicemesh-mixc |
affected |
Red Hat:service_mesh:2.0::el8 |
servicemesh-mixc |
— |
| servicemesh-mixs |
affected |
Red Hat:service_mesh:2.0::el8 |
servicemesh-mixs |
— |
| servicemesh-pilot-agent |
affected |
Red Hat:service_mesh:2.0::el8 |
servicemesh-pilot-agent |
— |
| servicemesh-pilot-discovery |
affected |
Red Hat:service_mesh:2.0::el8 |
servicemesh-pilot-discovery |
— |
| servicemesh-prometheus |
affected |
Red Hat:service_mesh:2.0::el8 |
servicemesh-prometheus |
— |
| servicemesh-proxy |
affected |
Red Hat:service_mesh:2.0::el8 |
servicemesh-proxy |
— |
Open SourcePoC exploitHIGH2022-04-27
Security update for firewalld, golang-github-prometheus-prometheus
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| firewalld |
affected |
SUSE:Linux Enterprise Micro 5.1 |
firewalld |
— |
| firewalld |
affected |
openSUSE:Leap 15.3 |
firewalld |
— |
| firewalld |
affected |
SUSE:Linux Enterprise Module for Basesystem 15 SP3 |
firewalld |
— |
| firewalld |
affected |
SUSE:Linux Enterprise Module for Desktop Applications 15 SP3 |
firewalld |
— |
| firewalld |
affected |
SUSE:Linux Enterprise Micro 5.2 |
firewalld |
— |
| golang-github-prometheus-prometheus |
affected |
openSUSE:Leap 15.4 |
golang-github-prometheus-prometheus |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Proxy Module 4.1 |
golang-github-prometheus-prometheus |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Proxy Module 4.2 |
golang-github-prometheus-prometheus |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Enterprise Storage 6 |
golang-github-prometheus-prometheus |
— |
| golang-github-prometheus-prometheus |
affected |
openSUSE:Leap 15.3 |
golang-github-prometheus-prometheus |
— |
Open SourcePoC exploitHIGH2022-04-27
Security update for golang-github-prometheus-prometheus
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 15 |
golang-github-prometheus-prometheus |
— |
Open SourcePoC exploitHIGH2022-04-27
Security update for golang-github-prometheus-prometheus
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 12 |
golang-github-prometheus-prometheus |
— |
Open SourcePoC exploitHIGH2022-04-29
DEBIAN-CVE-2022-1227
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-containers-psgo |
affected |
Debian:11 |
golang-github-containers-psgo |
— |
| golang-github-containers-psgo |
affected |
Debian:12 |
golang-github-containers-psgo |
— |
| golang-github-containers-psgo |
affected |
Debian:13 |
golang-github-containers-psgo |
— |
| golang-github-containers-psgo |
affected |
Debian:14 |
golang-github-containers-psgo |
— |
| libpod |
affected |
Debian:11 |
libpod |
— |
| libpod |
affected |
Debian:12 |
libpod |
— |
Open SourcePoC exploitHIGH2022-04-25
Denial of service via crafted Signer in golang.org/x/crypto/ssh
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| dynamic-localpv-provisioner |
affected |
wolfi |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner |
affected |
chainguard |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| prometheus-postgres-exporter-0.10 |
affected |
chainguard |
prometheus-postgres-exporter-0.10 |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| x/crypto |
affected |
golang.org |
golang.org/x/crypto |
— |
Open SourcePoC exploitHIGH2022-04-07
Fix CVE(s): CVE-2021-4189
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python3.5 |
— |
| libpython3.5 |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5 |
— |
| libpython3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-dev |
— |
| libpython3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-minimal |
— |
| libpython3.5-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-stdlib |
— |
| libpython3.5-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-testsuite |
— |
| python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
python3.5 |
— |
| python3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-dev |
— |
| python3.5-doc |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-doc |
— |
| python3.5-examples |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-examples |
— |
| python3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-minimal |
— |
| python3.5-venv |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-venv |
— |
Open SourcePoC exploitHIGH2022-04-05
Fix CVE(s): CVE-2021-4189
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python2.7 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python2.7 |
— |
| libpython2.7 |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7 |
— |
| libpython2.7-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-dev |
— |
| libpython2.7-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-minimal |
— |
| libpython2.7-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-stdlib |
— |
| libpython2.7-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-testsuite |
— |
| python2.7 |
affected |
TuxCare:Ubuntu:16.04 |
python2.7 |
— |
| python2.7-dev |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-dev |
— |
| python2.7-doc |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-doc |
— |
| python2.7-examples |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-examples |
— |
| python2.7-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-minimal |
— |
Open SourcePoC exploit2022-04-28
golang-1.7 - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.7 |
affected |
Debian:9 |
golang-1.7 |
— |
Open SourcePoC exploit2022-04-28
golang-1.8 - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.8 |
affected |
Debian:9 |
golang-1.8 |
— |
Open SourcePoC exploit2022-04-19
Security update for protobuf
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
SUSE:Linux Enterprise Micro 5.2 |
protobuf |
— |
Open SourcePoC exploit2022-04-08
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler |
— |
— |
| golang |
affected |
openEuler:20.03-LTS-SP2 |
golang |
— |
| golang |
affected |
openEuler:20.03-LTS-SP1 |
golang |
— |
| golang |
affected |
openEuler:20.03-LTS-SP3 |
golang |
— |
GooglePoC exploitHIGH2022-04-01
PUB-A-217307370
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourcePoC exploitHIGH2022-04-05
An intent redirection issue was doscovered in Sina Weibo Android SDK 4.2.7 (com.sina.weibo.sdk.share.WbShareTransActivity), any unexported Activities could be started by the com.sina.weibo.sdk.share.WbShareTransActivity.
CVEs:CVE-2020-23349
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_software_development_kit |
affected |
weibo |
— |
— |
GooglePoC exploitHIGH2022-04-05
CVEs:CVE-2020-23349
GooglePoC exploitMEDIUM2022-04-01
PUB-A-216607118
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GooglePoC exploitCRITICAL2022-08-02
CVEs:CVE-2022-20368
Open SourcePoC exploitHIGH2022-04-07
Product: AndroidVersions: Android kernelAndroid ID: A-224546354References: Upstream kernel
CVEs:CVE-2022-20368
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS 30-63%CRITICAL2022-04-05
Updated chromium-browser-stable packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:8 |
chromium-browser-stable |
— |
Open SourceCoalition ESS 30-63%2022-04-03
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceCoalition ESS < 30%2022-04-07
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1232
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2022-1232
Open SourceCoalition ESS < 30%HIGH2022-04-20
CVE-2022-28327 affecting package golang for versions less than 1.18.3-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
GoogleCoalition ESS < 30%HIGH2022-04-20
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
CVEs:CVE-2022-28327
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| extra_packages_for_enterprise_linux |
affected |
fedoraproject |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-20
CVEs:CVE-2022-28327
Open SourceCoalition ESS < 30%CRITICAL2022-04-04
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-24475
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-24475
Open SourceCoalition ESS < 30%CRITICAL2022-04-04
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-26891
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-26891
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-26894
Open SourceCoalition ESS < 30%CRITICAL2022-04-04
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-26894
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-04
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-26895
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-26895
Open SourceCoalition ESS < 30%CRITICAL2022-04-04
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-26900
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-26900
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-26908
Open SourceCoalition ESS < 30%CRITICAL2022-04-04
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-26908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-26909
Open SourceCoalition ESS < 30%CRITICAL2022-04-04
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-26909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-04
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-26912
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-26912
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0797
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-20
CVE-2022-27536 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
GoogleCoalition ESS < 30%HIGH2022-04-20
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
CVEs:CVE-2022-27536
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-20
CVEs:CVE-2022-27536
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-26098
Open SourceCoalition ESS < 30%HIGH2022-04-11
Heap-based buffer overflow vulnerability in sheifd_create function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.
CVEs:CVE-2022-26098
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-27568
Open SourceCoalition ESS < 30%HIGH2022-04-11
Heap-based buffer overflow vulnerability in parser_iloc function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
CVEs:CVE-2022-27568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-27569
Open SourceCoalition ESS < 30%HIGH2022-04-11
Heap-based buffer overflow vulnerability in parser_infe function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
CVEs:CVE-2022-27569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
CVEs:CVE-2022-27570
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-27570
Open SourceCoalition ESS < 30%HIGH2022-04-11
Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
CVEs:CVE-2022-27571
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-27571
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-27572
Open SourceCoalition ESS < 30%HIGH2022-04-11
Heap-based buffer overflow vulnerability in parser_ipma function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.
CVEs:CVE-2022-27572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-04
CVEs:CVE-2022-24523
Open SourceCoalition ESS < 30%MEDIUM2022-04-04
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2022-24523
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-04
DEBIAN-CVE-2022-27651
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-containers-buildah |
affected |
Debian:11 |
golang-github-containers-buildah |
— |
| golang-github-containers-buildah |
affected |
Debian:12 |
golang-github-containers-buildah |
— |
| golang-github-containers-buildah |
affected |
Debian:13 |
golang-github-containers-buildah |
— |
| golang-github-containers-buildah |
affected |
Debian:14 |
golang-github-containers-buildah |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0789
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0608
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%2022-04-13
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-04-12
CVEs:CVE-2022-1310
GoogleCoalition ESS < 30%CRITICAL2022-04-12
Use after free in regular expressions in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1310
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0809
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-20
CVEs:CVE-2022-0567
Open SourceCoalition ESS < 30%CRITICAL2022-04-20
A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that shoul...
CVEs:CVE-2022-0567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ovn-kubernetes |
affected |
ovn |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0800
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0796
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-04-12
CVEs:CVE-2022-1308
GoogleCoalition ESS < 30%CRITICAL2022-04-12
Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1308
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0799
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-04-19
CVEs:CVE-2022-29144
Open SourceCoalition ESS < 30%CRITICAL2022-04-12
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-29144
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0795
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
DEBIAN-CVE-2022-0792
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0794
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0806
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0470
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0467
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-04-27
CVEs:CVE-2022-1478
GoogleCoalition ESS < 30%CRITICAL2022-04-27
Use after free in SwiftShader in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1478
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-12
Use after free in tab groups in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1313
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-12
CVEs:CVE-2022-1313
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0791
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-12
Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1305
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-12
CVEs:CVE-2022-1305
GoogleCoalition ESS < 30%HIGH2022-04-12
CVEs:CVE-2022-1314
GoogleCoalition ESS < 30%HIGH2022-04-12
Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1314
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0790
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0808
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
DEBIAN-CVE-2022-0807
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0454
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
DEBIAN-CVE-2022-0802
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
DEBIAN-CVE-2022-0804
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-04-04
Use after free in QR Code Generator in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.
CVEs:CVE-2022-1127
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-1127
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-1131
GoogleCoalition ESS < 30%CRITICAL2022-04-04
Use after free in Cast UI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-04
CVEs:CVE-2022-1138
GoogleCoalition ESS < 30%MEDIUM2022-04-04
Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2022-1138
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-04
CVEs:CVE-2022-0431
GoogleCoalition ESS < 30%CRITICAL2022-04-04
The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting
CVEs:CVE-2022-0431
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| insights_from_google_pagespeed |
affected |
insights_from_google_pagespeed_project |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-12
Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1311
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-12
CVEs:CVE-2022-1311
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
DEBIAN-CVE-2022-0803
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
DEBIAN-CVE-2022-0462
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
DEBIAN-CVE-2022-0461
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-12
CVEs:CVE-2022-1309
GoogleCoalition ESS < 30%CRITICAL2022-04-12
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2022-1309
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-04
Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
CVEs:CVE-2022-1143
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-1143
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0464
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0603
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0606
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0607
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-25
The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
CVEs:CVE-2021-46780
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| easy_google_maps |
affected |
supsystic |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-25
CVEs:CVE-2021-46780
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0459
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-12
Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2022-1306
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-12
CVEs:CVE-2022-1306
GoogleCoalition ESS < 30%MEDIUM2022-04-12
Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2022-1307
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-12
CVEs:CVE-2022-1307
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0610
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0457
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0460
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0452
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0453
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0465
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2021-39809
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39809
GoogleCoalition ESS < 30%MEDIUM2022-04-13
Private key stored in plain text by Jenkins Google Compute Engine Plugin
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-compute-engine |
affected |
Maven |
org.jenkins-ci.plugins:google-compute-engine |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-13
Private key stored in plain text by Jenkins Google Compute Engine Plugin
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-compute-engine |
affected |
Maven |
org.jenkins-ci.plugins:google-compute-engine |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-12
Private key stored in plain text by Jenkins Google Compute Engine Plugin
CVEs:CVE-2022-29052
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-compute-engine |
affected |
Maven |
org.jenkins-ci.plugins:google-compute-engine |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-12
Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file s...
CVEs:CVE-2022-29052
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_compute_engine |
affected |
jenkins |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0458
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0793
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0468
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0469
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0463
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-04
CVEs:CVE-2022-1128
GoogleCoalition ESS < 30%MEDIUM2022-04-04
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-1128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0798
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
DEBIAN-CVE-2022-0455
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0604
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Androi...
CVEs:CVE-2021-39803
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-05
CVEs:CVE-2021-39803
GoogleCoalition ESS < 30%HIGH2022-04-04
CVEs:CVE-2022-1136
GoogleCoalition ESS < 30%CRITICAL2022-04-04
Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific set of user gestures.
CVEs:CVE-2022-1136
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-12
Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVEs:CVE-2022-1312
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-12
CVEs:CVE-2022-1312
Open SourceCoalition ESS < 30%CRITICAL2022-04-05
DEBIAN-CVE-2022-0466
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
DEBIAN-CVE-2022-0605
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-05
CVEs:CVE-2022-20081
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A...
CVEs:CVE-2022-20081
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-01
ASB-A-218242055
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Null pointer dereference vulnerability in parser_irot function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
CVEs:CVE-2022-26093
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-26093
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
CVEs:CVE-2022-26094
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-26094
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-26095
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Null pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
CVEs:CVE-2022-26095
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Null pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
CVEs:CVE-2022-26096
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-26096
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Null pointer dereference vulnerability in parser_unknown_property function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
CVEs:CVE-2022-26097
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-26097
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.
CVEs:CVE-2022-26099
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-26099
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.
CVEs:CVE-2022-27567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-04-11
CVEs:CVE-2022-27567
GoogleCoalition ESS < 30%HIGH2022-04-01
ASB-A-220262213
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-05
CVEs:CVE-2021-39804
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persistent denial of service in the file picker with no additional execution privileges needed. User interaction is needed for exploitati...
CVEs:CVE-2021-39804
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27574
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attacker.
CVEs:CVE-2022-27574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27573
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attackers.
CVEs:CVE-2022-27573
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
In search engine service, there is a possible way to change the default search engine due to an incorrect comparison. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitati...
CVEs:CVE-2022-20072
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20072
Open SourceCoalition ESS < 30%HIGH2022-04-05
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no additional execution ...
CVEs:CVE-2021-39794
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39794
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code.
CVEs:CVE-2022-28779
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_usb_driver_windows_installer |
affected |
samsung |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-28779
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27835
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.
CVEs:CVE-2022-27835
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file
CVEs:CVE-2022-27824
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27824
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27823
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.
CVEs:CVE-2022-27823
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via crafted image file.
CVEs:CVE-2022-27821
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-27821
GoogleCoalition ESS < 30%MEDIUM2022-04-05
CVEs:CVE-2021-39805
Open SourceCoalition ESS < 30%MEDIUM2022-04-05
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2021-39805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-04-11
CVEs:CVE-2022-27576
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission
CVEs:CVE-2022-27576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.
CVEs:CVE-2022-27575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-04-11
CVEs:CVE-2022-27575
GoogleCoalition ESS < 30%MEDIUM2022-04-18
Incorrect Default Permissions in CRI-O
CVEs:CVE-2022-27652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cri-o/cri-o |
affected |
github.com |
github.com/cri-o/cri-o |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-18
Incorrect Default Permissions in CRI-O
CVEs:CVE-2022-27652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cri-o/cri-o |
affected |
github.com |
github.com/cri-o/cri-o |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-18
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This ...
CVEs:CVE-2022-27652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cri-o |
affected |
kubernetes |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| moby |
affected |
mobyproject |
— |
— |
| openshift_container_platform |
affected |
redhat |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27825
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.
CVEs:CVE-2022-27825
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User intera...
CVEs:CVE-2022-20073
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20073
Open SourceCoalition ESS < 30%HIGH2022-04-12
DEBIAN-CVE-2021-39796
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android-platform-frameworks-base |
affected |
Debian:11 |
android-platform-frameworks-base |
— |
| android-platform-frameworks-base |
affected |
Debian:12 |
android-platform-frameworks-base |
— |
| android-platform-frameworks-base |
affected |
Debian:13 |
android-platform-frameworks-base |
— |
| android-platform-frameworks-base |
affected |
Debian:14 |
android-platform-frameworks-base |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. U...
CVEs:CVE-2021-39796
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39796
GoogleCoalition ESS < 30%HIGH2022-04-01
ASB-A-155756045
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27826
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-27826
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-04-01
ASB-A-204905109
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2022-04-01
ASB-A-213239835
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
| vendor/opensource/display-drivers |
affected |
platform |
platform/vendor/opensource/display-drivers |
— |
GoogleCoalition ESS < 30%2022-04-01
ASB-A-213240026
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2021-39802
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39802
GoogleCoalition ESS < 30%MEDIUM2022-04-01
ASB-A-213339151
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation...
CVEs:CVE-2022-27836
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27836
GoogleCoalition ESS < 30%2022-04-01
ASB-A-204905206
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2021-39800
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-05
CVEs:CVE-2021-39800
GoogleCoalition ESS < 30%HIGH2022-04-01
ASB-A-208277166
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-26092
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.
CVEs:CVE-2022-26092
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-27827
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27827
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-27828
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27828
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20052
Open SourceCoalition ESS < 30%HIGH2022-04-11
In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS05836642; Issue ID: ALPS05836642.
CVEs:CVE-2022-20052
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27829
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-27829
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27830
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-27830
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-04-01
ASB-A-201574693
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20063
Open SourceCoalition ESS < 30%HIGH2022-04-11
In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06171715; Issue ID...
CVEs:CVE-2022-20063
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
In preloader (partition), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. Us...
CVEs:CVE-2022-20074
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20074
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-20075
Open SourceCoalition ESS < 30%HIGH2022-04-11
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05838808; Issue ID: ALP...
CVEs:CVE-2022-20075
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108617; Issu...
CVEs:CVE-2022-20064
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-20064
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06...
CVEs:CVE-2022-20068
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20068
Open SourceCoalition ESS < 30%HIGH2022-04-11
In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User intera...
CVEs:CVE-2022-20069
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20069
Open SourceCoalition ESS < 30%HIGH2022-04-11
In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836418; Issue ID: ALPS05836...
CVEs:CVE-2022-20062
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-20062
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20066
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...
CVEs:CVE-2022-20066
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.
CVEs:CVE-2022-27822
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-27822
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39799
Open SourceCoalition ESS < 30%HIGH2022-04-05
In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2021-39799
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39801
Open SourceCoalition ESS < 30%HIGH2022-04-05
In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2021-39801
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-01
ASB-A-209791720
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20065
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108658; Issue ID: A...
CVEs:CVE-2022-20065
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
In mdp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836585; Issue ID: A...
CVEs:CVE-2022-20067
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20067
Open SourceCoalition ESS < 30%HIGH2022-04-05
In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2021-39797
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39797
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39798
Open SourceCoalition ESS < 30%HIGH2022-04-05
In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-39798
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39812
Open SourceCoalition ESS < 30%HIGH2022-04-05
In TBD of TBD, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...
CVEs:CVE-2021-39812
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-05
In ppmp_validate_wsm of drm_fw.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2021-39814
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39814
GoogleCoalition ESS < 30%HIGH2022-04-01
PUB-A-205522359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-04-01
PUB-A-216792660
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-25832
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication.
CVEs:CVE-2022-25832
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20076
Open SourceCoalition ESS < 30%HIGH2022-04-11
In ged, there is a possible memory corruption due to an incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05838808; Issue ID...
CVEs:CVE-2022-20076
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
In ssmr, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06362920; Issue ID: ...
CVEs:CVE-2022-20070
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20070
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
In vow, there is a possible read of uninitialized data due to a improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05837742; ...
CVEs:CVE-2022-20079
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20079
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-0694
Open SourceCoalition ESS < 30%HIGH2022-04-05
In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could lead to local escalation of privilege with no addit...
CVEs:CVE-2021-0694
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39807
Open SourceCoalition ESS < 30%HIGH2022-04-05
In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. This could lead to local escalation of privilege from the Guest account with no additional execution priv...
CVEs:CVE-2021-39807
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-05
CVEs:CVE-2021-39808
Open SourceCoalition ESS < 30%HIGH2022-04-05
In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to local escalation of privilege with no additional exec...
CVEs:CVE-2021-39808
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-04-11
CVEs:CVE-2022-25833
Open SourceCoalition ESS < 30%LOW2022-04-11
Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission.
CVEs:CVE-2022-25833
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.
CVEs:CVE-2022-27833
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27833
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
Improper access control vulnerability in SamsungContacts prior to SMR Apr-2022 Release 1 allows that attackers can access contact information without permission.
CVEs:CVE-2022-26090
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-04-11
CVEs:CVE-2022-26090
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-26091
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard.
CVEs:CVE-2022-26091
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20077
Open SourceCoalition ESS < 30%HIGH2022-04-11
In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05837742; Issue ID: ALPS05852...
CVEs:CVE-2022-20077
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-04-11
In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05852819; Issue ID: ALPS05852...
CVEs:CVE-2022-20078
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20078
Open SourceCoalition ESS < 30%HIGH2022-04-11
In SUB2AF, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05881290; Issue ID: ALPS05...
CVEs:CVE-2022-20080
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20080
GoogleCoalition ESS < 30%LOW2022-04-11
CVEs:CVE-2022-27832
Open SourceCoalition ESS < 30%HIGH2022-04-11
Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.
CVEs:CVE-2022-27832
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access secured data in certain conditions.
CVEs:CVE-2022-25831
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-25831
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-27831
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read out of bounds memory.
CVEs:CVE-2022-27831
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-04-11
Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions.
CVEs:CVE-2022-27834
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-04-11
CVEs:CVE-2022-27834
GoogleCoalition ESS < 30%MEDIUM2022-04-11
CVEs:CVE-2022-20071
Open SourceCoalition ESS < 30%MEDIUM2022-04-11
In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS0618331...
CVEs:CVE-2022-20071
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2022-04-12
Information Exposure in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourceEPSS <= 49%HIGH2022-04-12
Information Exposure in Kubernetes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |