CVE-2022-30190
CVEs:CVE-2022-30190
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 8 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
CVEs:CVE-2022-30190
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling applicat...
CVEs:CVE-2022-30190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_10_21h1 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_11_21h2 | affected | microsoft | — | — |
| windows_7 | affected | microsoft | — | — |
| windows_8.1 | affected | microsoft | — | — |
| windows_rt_8.1 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
| windows_server_20h2 | affected | microsoft | — | — |
ASB-A-220741611
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-26925
Windows LSA Spoofing Vulnerability
CVEs:CVE-2022-26925
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_1909 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_10_21h1 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_11_21h2 | affected | microsoft | — | — |
| windows_7 | affected | microsoft | — | — |
| windows_8.1 | affected | microsoft | — | — |
| windows_rt_8.1 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
| windows_server_20h2 | affected | microsoft | — | — |
Windows LSA Spoofing Vulnerability
CVEs:CVE-2022-26925
ASB-A-213464034
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
GHSA-v98w-p8f7-9qqf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
| firefox | affected | wolfi | firefox | — |
| firefox | affected | chainguard | firefox | — |
GHSA-rhch-pcq2-7gp3
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
| firefox | affected | chainguard | firefox | — |
| firefox | affected | wolfi | firefox | — |
| openjdk-11-openj9 | affected | chainguard | openjdk-11-openj9 | — |
| openjdk-17-openj9 | affected | chainguard | openjdk-17-openj9 | — |
| openjdk-21-openj9 | affected | chainguard | openjdk-21-openj9 | — |
| openjdk-25-openj9 | affected | chainguard | openjdk-25-openj9 | — |
| openjdk-26-openj9 | affected | chainguard | openjdk-26-openj9 | — |
| openjdk-8-openj9 | affected | chainguard | openjdk-8-openj9 | — |
android-gif-drawable Double Free vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| pl.droidsonroids.gif:android-gif-drawable | affected | Maven | pl.droidsonroids.gif:android-gif-drawable | — |
android-gif-drawable Double Free vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| pl.droidsonroids.gif:android-gif-drawable | affected | Maven | pl.droidsonroids.gif:android-gif-drawable | — |
GHSA-348j-44v2-vwfr
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
| firefox | affected | wolfi | firefox | — |
| firefox | affected | chainguard | firefox | — |
Panic on invalid DSA public keys in crypto/dsa
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
google-oauth-java-client improperly verifies cryptographic signature
CVEs:CVE-2021-22573
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.oauth-client:google-oauth-client | affected | Maven | com.google.oauth-client:google-oauth-client | — |
DEBIAN-CVE-2021-22573
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-oauth-client-java | affected | Debian:11 | google-oauth-client-java | — |
| google-oauth-client-java | affected | Debian:12 | google-oauth-client-java | — |
| google-oauth-client-java | affected | Debian:13 | google-oauth-client-java | — |
| google-oauth-client-java | affected | Debian:14 | google-oauth-client-java | — |
The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An attacker can provide a compromised token with custom...
CVEs:CVE-2021-22573
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| oauth_client_library_for_java | affected | — | — |
golang.org/x/net/http vulnerable to a reset flood
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/http vulnerable to a reset flood
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| hey | affected | wolfi | hey | — |
| hey | affected | chainguard | hey | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| x/net | affected | golang.org | golang.org/x/net | — |
| x/net | affected | golang.org | — | — |
golang.org/x/net/http vulnerable to ping floods
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| hey | affected | wolfi | hey | — |
| hey | affected | chainguard | hey | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| x/net | affected | golang.org | — | — |
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/http vulnerable to ping floods
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
google-gson security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-gson | affected | openEuler:20.03-LTS-SP1 | google-gson | — |
| google-gson | affected | openEuler:20.03-LTS-SP3 | google-gson | — |
| google-gson | affected | openEuler:22.03-LTS | google-gson | — |
libgoogle-gson-java - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libgoogle-gson-java | affected | Debian:9 | libgoogle-gson-java | — |
Deserialization of Untrusted Data in Gson
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.code.gson:gson | affected | Maven | com.google.code.gson:gson | — |
| com.google.code.gson:gson | affected | Maven | — | — |
| trino | affected | chainguard | trino | — |
| trino | affected | wolfi | trino | — |
Deserialization of Untrusted Data in Gson
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.code.gson:gson | affected | Maven | com.google.code.gson:gson | — |
DEBIAN-CVE-2022-25647
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libgoogle-gson-java | affected | Debian:11 | libgoogle-gson-java | — |
| libgoogle-gson-java | affected | Debian:12 | libgoogle-gson-java | — |
| libgoogle-gson-java | affected | Debian:13 | libgoogle-gson-java | — |
| libgoogle-gson-java | affected | Debian:14 | libgoogle-gson-java | — |
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
CVEs:CVE-2022-25647
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| active_iq_unified_manager | affected | netapp | — | — |
| debian_linux | affected | debian | — | — |
| financial_services_crime_and_compliance_management_studio | affected | oracle | — | — |
| graalvm | affected | oracle | — | — |
| gson | affected | — | — | |
| gson | affected | — | — | |
| retail_order_broker | affected | oracle | — | — |
Deserialization of Untrusted Data in Gson
CVEs:CVE-2022-25647
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.code.gson:gson | affected | Maven | com.google.code.gson:gson | — |
Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:8::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Moderate: go-toolset:rhel8 security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | AlmaLinux:8 | delve | — |
| golang | affected | AlmaLinux:8 | golang | — |
| golang-bin | affected | AlmaLinux:8 | golang-bin | — |
| golang-docs | affected | AlmaLinux:8 | golang-docs | — |
| golang-misc | affected | AlmaLinux:8 | golang-misc | — |
| golang-race | affected | AlmaLinux:8 | golang-race | — |
| golang-src | affected | AlmaLinux:8 | golang-src | — |
| golang-tests | affected | AlmaLinux:8 | golang-tests | — |
| go-toolset | affected | AlmaLinux:8 | go-toolset | — |
Moderate: go-toolset:rhel8 security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
Kubernetes DoS Vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kubernetes DoS Vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Stack overflow from a large amount of PEM data in encoding/pem
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
| golang | affected | openEuler:22.03-LTS | golang | — |
Updated golang packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:8 | golang | — |
Red Hat Security Advisory: maven:3.5 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | Red Hat:enterprise_linux:8::appstream | aopalliance | — |
| apache-commons-cli | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-cli | — |
| apache-commons-codec | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-codec | — |
| apache-commons-io | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-io | — |
| apache-commons-lang3 | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-lang3 | — |
| apache-commons-logging | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-logging | — |
| atinject | affected | Red Hat:enterprise_linux:8::appstream | atinject | — |
| cdi-api | affected | Red Hat:enterprise_linux:8::appstream | cdi-api | — |
| geronimo-annotation | affected | Red Hat:enterprise_linux:8::appstream | geronimo-annotation | — |
| glassfish-el | affected | Red Hat:enterprise_linux:8::appstream | glassfish-el | — |
| glassfish-el-api | affected | Red Hat:enterprise_linux:8::appstream | glassfish-el-api | — |
| google-guice | affected | Red Hat:enterprise_linux:8::appstream | google-guice | — |
| guava20 | affected | Red Hat:enterprise_linux:8::appstream | guava20 | — |
| hawtjni | affected | Red Hat:enterprise_linux:8::appstream | hawtjni | — |
| hawtjni-runtime | affected | Red Hat:enterprise_linux:8::appstream | hawtjni-runtime | — |
| httpcomponents-client | affected | Red Hat:enterprise_linux:8::appstream | httpcomponents-client | — |
| httpcomponents-core | affected | Red Hat:enterprise_linux:8::appstream | httpcomponents-core | — |
| jansi | affected | Red Hat:enterprise_linux:8::appstream | jansi | — |
| jansi-native | affected | Red Hat:enterprise_linux:8::appstream | jansi-native | — |
| jboss-interceptors-1.2-api | affected | Red Hat:enterprise_linux:8::appstream | jboss-interceptors-1.2-api | — |
| jcl-over-slf4j | affected | Red Hat:enterprise_linux:8::appstream | jcl-over-slf4j | — |
| jsoup | affected | Red Hat:enterprise_linux:8::appstream | jsoup | — |
| maven | affected | Red Hat:enterprise_linux:8::appstream | maven | — |
| maven-lib | affected | Red Hat:enterprise_linux:8::appstream | maven-lib | — |
| maven-resolver | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver | — |
| maven-resolver-api | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-api | — |
| maven-resolver-connector-basic | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-connector-basic | — |
| maven-resolver-impl | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-impl | — |
| maven-resolver-spi | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-spi | — |
| maven-resolver-transport-wagon | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-transport-wagon | — |
| maven-resolver-util | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-util | — |
| maven-shared-utils | affected | Red Hat:enterprise_linux:8::appstream | maven-shared-utils | — |
| maven-wagon | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon | — |
| maven-wagon-file | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon-file | — |
| maven-wagon-http | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon-http | — |
| maven-wagon-http-shared | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon-http-shared | — |
| maven-wagon-provider-api | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon-provider-api | — |
| plexus-cipher | affected | Red Hat:enterprise_linux:8::appstream | plexus-cipher | — |
| plexus-classworlds | affected | Red Hat:enterprise_linux:8::appstream | plexus-classworlds | — |
| plexus-containers | affected | Red Hat:enterprise_linux:8::appstream | plexus-containers | — |
| plexus-containers-component-annotations | affected | Red Hat:enterprise_linux:8::appstream | plexus-containers-component-annotations | — |
| plexus-interpolation | affected | Red Hat:enterprise_linux:8::appstream | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | Red Hat:enterprise_linux:8::appstream | plexus-sec-dispatcher | — |
| plexus-utils | affected | Red Hat:enterprise_linux:8::appstream | plexus-utils | — |
| sisu | affected | Red Hat:enterprise_linux:8::appstream | sisu | — |
| sisu-inject | affected | Red Hat:enterprise_linux:8::appstream | sisu-inject | — |
| sisu-plexus | affected | Red Hat:enterprise_linux:8::appstream | sisu-plexus | — |
| slf4j | affected | Red Hat:enterprise_linux:8::appstream | slf4j | — |
Red Hat Security Advisory: maven:3.6 security and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | Red Hat:enterprise_linux:8::appstream | aopalliance | — |
| apache-commons-cli | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-cli | — |
| apache-commons-codec | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-codec | — |
| apache-commons-io | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-io | — |
| apache-commons-lang3 | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-lang3 | — |
| atinject | affected | Red Hat:enterprise_linux:8::appstream | atinject | — |
| cdi-api | affected | Red Hat:enterprise_linux:8::appstream | cdi-api | — |
| geronimo-annotation | affected | Red Hat:enterprise_linux:8::appstream | geronimo-annotation | — |
| google-guice | affected | Red Hat:enterprise_linux:8::appstream | google-guice | — |
| guava | affected | Red Hat:enterprise_linux:8::appstream | guava | — |
| httpcomponents-client | affected | Red Hat:enterprise_linux:8::appstream | httpcomponents-client | — |
| httpcomponents-core | affected | Red Hat:enterprise_linux:8::appstream | httpcomponents-core | — |
| jansi | affected | Red Hat:enterprise_linux:8::appstream | jansi | — |
| jcl-over-slf4j | affected | Red Hat:enterprise_linux:8::appstream | jcl-over-slf4j | — |
| jsoup | affected | Red Hat:enterprise_linux:8::appstream | jsoup | — |
| jsr-305 | affected | Red Hat:enterprise_linux:8::appstream | jsr-305 | — |
| maven | affected | Red Hat:enterprise_linux:8::appstream | maven | — |
| maven-lib | affected | Red Hat:enterprise_linux:8::appstream | maven-lib | — |
| maven-openjdk11 | affected | Red Hat:enterprise_linux:8::appstream | maven-openjdk11 | — |
| maven-openjdk17 | affected | Red Hat:enterprise_linux:8::appstream | maven-openjdk17 | — |
| maven-openjdk8 | affected | Red Hat:enterprise_linux:8::appstream | maven-openjdk8 | — |
| maven-resolver | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver | — |
| maven-shared-utils | affected | Red Hat:enterprise_linux:8::appstream | maven-shared-utils | — |
| maven-wagon | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon | — |
| plexus-cipher | affected | Red Hat:enterprise_linux:8::appstream | plexus-cipher | — |
| plexus-classworlds | affected | Red Hat:enterprise_linux:8::appstream | plexus-classworlds | — |
| plexus-containers | affected | Red Hat:enterprise_linux:8::appstream | plexus-containers | — |
| plexus-containers-component-annotations | affected | Red Hat:enterprise_linux:8::appstream | plexus-containers-component-annotations | — |
| plexus-interpolation | affected | Red Hat:enterprise_linux:8::appstream | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | Red Hat:enterprise_linux:8::appstream | plexus-sec-dispatcher | — |
| plexus-utils | affected | Red Hat:enterprise_linux:8::appstream | plexus-utils | — |
| sisu | affected | Red Hat:enterprise_linux:8::appstream | sisu | — |
| slf4j | affected | Red Hat:enterprise_linux:8::appstream | slf4j | — |
Moderate: maven:3.5 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | AlmaLinux:8 | aopalliance | — |
| apache-commons-cli | affected | AlmaLinux:8 | apache-commons-cli | — |
| apache-commons-codec | affected | AlmaLinux:8 | apache-commons-codec | — |
| apache-commons-io | affected | AlmaLinux:8 | apache-commons-io | — |
| apache-commons-lang3 | affected | AlmaLinux:8 | apache-commons-lang3 | — |
| apache-commons-logging | affected | AlmaLinux:8 | apache-commons-logging | — |
| atinject | affected | AlmaLinux:8 | atinject | — |
| cdi-api | affected | AlmaLinux:8 | cdi-api | — |
| geronimo-annotation | affected | AlmaLinux:8 | geronimo-annotation | — |
| glassfish-el-api | affected | AlmaLinux:8 | glassfish-el-api | — |
| google-guice | affected | AlmaLinux:8 | google-guice | — |
| guava20 | affected | AlmaLinux:8 | guava20 | — |
| hawtjni-runtime | affected | AlmaLinux:8 | hawtjni-runtime | — |
| httpcomponents-client | affected | AlmaLinux:8 | httpcomponents-client | — |
| httpcomponents-core | affected | AlmaLinux:8 | httpcomponents-core | — |
| jansi | affected | AlmaLinux:8 | jansi | — |
| jansi-native | affected | AlmaLinux:8 | jansi-native | — |
| jboss-interceptors-1.2-api | affected | AlmaLinux:8 | jboss-interceptors-1.2-api | — |
| jcl-over-slf4j | affected | AlmaLinux:8 | jcl-over-slf4j | — |
| jsoup | affected | AlmaLinux:8 | jsoup | — |
| maven | affected | AlmaLinux:8 | maven | — |
| maven-lib | affected | AlmaLinux:8 | maven-lib | — |
| maven-resolver-api | affected | AlmaLinux:8 | maven-resolver-api | — |
| maven-resolver-connector-basic | affected | AlmaLinux:8 | maven-resolver-connector-basic | — |
| maven-resolver-impl | affected | AlmaLinux:8 | maven-resolver-impl | — |
| maven-resolver-spi | affected | AlmaLinux:8 | maven-resolver-spi | — |
| maven-resolver-transport-wagon | affected | AlmaLinux:8 | maven-resolver-transport-wagon | — |
| maven-resolver-util | affected | AlmaLinux:8 | maven-resolver-util | — |
| maven-shared-utils | affected | AlmaLinux:8 | maven-shared-utils | — |
| maven-wagon-file | affected | AlmaLinux:8 | maven-wagon-file | — |
| maven-wagon-http | affected | AlmaLinux:8 | maven-wagon-http | — |
| maven-wagon-http-shared | affected | AlmaLinux:8 | maven-wagon-http-shared | — |
| maven-wagon-provider-api | affected | AlmaLinux:8 | maven-wagon-provider-api | — |
| plexus-cipher | affected | AlmaLinux:8 | plexus-cipher | — |
| plexus-classworlds | affected | AlmaLinux:8 | plexus-classworlds | — |
| plexus-containers-component-annotations | affected | AlmaLinux:8 | plexus-containers-component-annotations | — |
| plexus-interpolation | affected | AlmaLinux:8 | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | AlmaLinux:8 | plexus-sec-dispatcher | — |
| plexus-utils | affected | AlmaLinux:8 | plexus-utils | — |
| sisu-inject | affected | AlmaLinux:8 | sisu-inject | — |
| sisu-plexus | affected | AlmaLinux:8 | sisu-plexus | — |
| slf4j | affected | AlmaLinux:8 | slf4j | — |
Moderate: maven:3.5 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | Rocky Linux:8 | aopalliance | — |
| apache-commons-cli | affected | Rocky Linux:8 | apache-commons-cli | — |
| apache-commons-codec | affected | Rocky Linux:8 | apache-commons-codec | — |
| apache-commons-io | affected | Rocky Linux:8 | apache-commons-io | — |
| apache-commons-lang3 | affected | Rocky Linux:8 | apache-commons-lang3 | — |
| apache-commons-logging | affected | Rocky Linux:8 | apache-commons-logging | — |
| atinject | affected | Rocky Linux:8 | atinject | — |
| cdi-api | affected | Rocky Linux:8 | cdi-api | — |
| geronimo-annotation | affected | Rocky Linux:8 | geronimo-annotation | — |
| glassfish-el | affected | Rocky Linux:8 | glassfish-el | — |
| google-guice | affected | Rocky Linux:8 | google-guice | — |
| guava20 | affected | Rocky Linux:8 | guava20 | — |
| hawtjni | affected | Rocky Linux:8 | hawtjni | — |
| httpcomponents-client | affected | Rocky Linux:8 | httpcomponents-client | — |
| httpcomponents-core | affected | Rocky Linux:8 | httpcomponents-core | — |
| jansi | affected | Rocky Linux:8 | jansi | — |
| jansi-native | affected | Rocky Linux:8 | jansi-native | — |
| jboss-interceptors-1.2-api | affected | Rocky Linux:8 | jboss-interceptors-1.2-api | — |
| jsoup | affected | Rocky Linux:8 | jsoup | — |
| maven | affected | Rocky Linux:8 | maven | — |
| maven-resolver | affected | Rocky Linux:8 | maven-resolver | — |
| maven-shared-utils | affected | Rocky Linux:8 | maven-shared-utils | — |
| maven-wagon | affected | Rocky Linux:8 | maven-wagon | — |
| plexus-cipher | affected | Rocky Linux:8 | plexus-cipher | — |
| plexus-classworlds | affected | Rocky Linux:8 | plexus-classworlds | — |
| plexus-containers | affected | Rocky Linux:8 | plexus-containers | — |
| plexus-interpolation | affected | Rocky Linux:8 | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | Rocky Linux:8 | plexus-sec-dispatcher | — |
| plexus-utils | affected | Rocky Linux:8 | plexus-utils | — |
| sisu | affected | Rocky Linux:8 | sisu | — |
| slf4j | affected | Rocky Linux:8 | slf4j | — |
Moderate: maven:3.6 security and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | AlmaLinux:8 | aopalliance | — |
| apache-commons-cli | affected | AlmaLinux:8 | apache-commons-cli | — |
| apache-commons-codec | affected | AlmaLinux:8 | apache-commons-codec | — |
| apache-commons-io | affected | AlmaLinux:8 | apache-commons-io | — |
| apache-commons-lang3 | affected | AlmaLinux:8 | apache-commons-lang3 | — |
| atinject | affected | AlmaLinux:8 | atinject | — |
| cdi-api | affected | AlmaLinux:8 | cdi-api | — |
| geronimo-annotation | affected | AlmaLinux:8 | geronimo-annotation | — |
| google-guice | affected | AlmaLinux:8 | google-guice | — |
| guava | affected | AlmaLinux:8 | guava | — |
| httpcomponents-client | affected | AlmaLinux:8 | httpcomponents-client | — |
| httpcomponents-core | affected | AlmaLinux:8 | httpcomponents-core | — |
| jansi | affected | AlmaLinux:8 | jansi | — |
| jcl-over-slf4j | affected | AlmaLinux:8 | jcl-over-slf4j | — |
| jsoup | affected | AlmaLinux:8 | jsoup | — |
| jsr-305 | affected | AlmaLinux:8 | jsr-305 | — |
| maven | affected | AlmaLinux:8 | maven | — |
| maven-lib | affected | AlmaLinux:8 | maven-lib | — |
| maven-openjdk11 | affected | AlmaLinux:8 | maven-openjdk11 | — |
| maven-openjdk17 | affected | AlmaLinux:8 | maven-openjdk17 | — |
| maven-openjdk8 | affected | AlmaLinux:8 | maven-openjdk8 | — |
| maven-resolver | affected | AlmaLinux:8 | maven-resolver | — |
| maven-shared-utils | affected | AlmaLinux:8 | maven-shared-utils | — |
| maven-wagon | affected | AlmaLinux:8 | maven-wagon | — |
| plexus-cipher | affected | AlmaLinux:8 | plexus-cipher | — |
| plexus-classworlds | affected | AlmaLinux:8 | plexus-classworlds | — |
| plexus-containers-component-annotations | affected | AlmaLinux:8 | plexus-containers-component-annotations | — |
| plexus-interpolation | affected | AlmaLinux:8 | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | AlmaLinux:8 | plexus-sec-dispatcher | — |
| plexus-utils | affected | AlmaLinux:8 | plexus-utils | — |
| sisu | affected | AlmaLinux:8 | sisu | — |
| slf4j | affected | AlmaLinux:8 | slf4j | — |
Moderate: maven:3.6 security and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | Rocky Linux:8 | aopalliance | — |
| apache-commons-cli | affected | Rocky Linux:8 | apache-commons-cli | — |
| apache-commons-codec | affected | Rocky Linux:8 | apache-commons-codec | — |
| apache-commons-io | affected | Rocky Linux:8 | apache-commons-io | — |
| apache-commons-lang3 | affected | Rocky Linux:8 | apache-commons-lang3 | — |
| atinject | affected | Rocky Linux:8 | atinject | — |
| cdi-api | affected | Rocky Linux:8 | cdi-api | — |
| geronimo-annotation | affected | Rocky Linux:8 | geronimo-annotation | — |
| google-guice | affected | Rocky Linux:8 | google-guice | — |
| guava | affected | Rocky Linux:8 | guava | — |
| httpcomponents-client | affected | Rocky Linux:8 | httpcomponents-client | — |
| httpcomponents-core | affected | Rocky Linux:8 | httpcomponents-core | — |
| jansi | affected | Rocky Linux:8 | jansi | — |
| jsoup | affected | Rocky Linux:8 | jsoup | — |
| jsr-305 | affected | Rocky Linux:8 | jsr-305 | — |
| maven | affected | Rocky Linux:8 | maven | — |
| maven-resolver | affected | Rocky Linux:8 | maven-resolver | — |
| maven-shared-utils | affected | Rocky Linux:8 | maven-shared-utils | — |
| maven-wagon | affected | Rocky Linux:8 | maven-wagon | — |
| plexus-cipher | affected | Rocky Linux:8 | plexus-cipher | — |
| plexus-classworlds | affected | Rocky Linux:8 | plexus-classworlds | — |
| plexus-containers | affected | Rocky Linux:8 | plexus-containers | — |
| plexus-interpolation | affected | Rocky Linux:8 | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | Rocky Linux:8 | plexus-sec-dispatcher | — |
| plexus-utils | affected | Rocky Linux:8 | plexus-utils | — |
| sisu | affected | Rocky Linux:8 | sisu | — |
| slf4j | affected | Rocky Linux:8 | slf4j | — |
golang.org/x/net/html Infinite Loop vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/html Infinite Loop vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpcurl | affected | chainguard | grpcurl | — |
| grpcurl | affected | wolfi | grpcurl | — |
| hey | affected | wolfi | hey | — |
| hey | affected | chainguard | hey | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| x/net | affected | golang.org | golang.org/x/net | — |
| x/net | affected | golang.org | — | — |
Panic due to crafted inputs in archive/zip
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
Updated golang-github-prometheus-client packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-prometheus-client | affected | Mageia:8 | golang-github-prometheus-client | — |
Request smuggling due to accepting invalid headers in net/http via net/textproto
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
protobuf susceptible to buffer overflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.protobuf:protobuf-parent | affected | Maven | com.google.protobuf:protobuf-parent | — |
| Google.Protobuf | affected | NuGet | Google.Protobuf | — |
| Google.Protobuf | affected | NuGet | Google.Protobuf | — |
| protobuf | affected | google/protobuf | — | |
| protobuf | affected | google/protobuf | — | |
| protobuf | affected | PyPI | protobuf | — |
| protocolbuffers/protobuf | affected | github.com | github.com/protocolbuffers/protobuf | — |
RubyGems Link Following vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Link Following vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Infinite Loop vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Infinite Loop vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
Denial of service due to unchecked parameters in crypto/dsa
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
Important: rsyslog security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rsyslog | affected | AlmaLinux:8 | rsyslog | — |
| rsyslog-crypto | affected | AlmaLinux:8 | rsyslog-crypto | — |
| rsyslog-doc | affected | AlmaLinux:8 | rsyslog-doc | — |
| rsyslog-elasticsearch | affected | AlmaLinux:8 | rsyslog-elasticsearch | — |
| rsyslog-gnutls | affected | AlmaLinux:8 | rsyslog-gnutls | — |
| rsyslog-gssapi | affected | AlmaLinux:8 | rsyslog-gssapi | — |
| rsyslog-kafka | affected | AlmaLinux:8 | rsyslog-kafka | — |
| rsyslog-mmaudit | affected | AlmaLinux:8 | rsyslog-mmaudit | — |
| rsyslog-mmfields | affected | AlmaLinux:8 | rsyslog-mmfields | — |
| rsyslog-mmjsonparse | affected | AlmaLinux:8 | rsyslog-mmjsonparse | — |
| rsyslog-mmkubernetes | affected | AlmaLinux:8 | rsyslog-mmkubernetes | — |
| rsyslog-mmnormalize | affected | AlmaLinux:8 | rsyslog-mmnormalize | — |
| rsyslog-mmsnmptrapd | affected | AlmaLinux:8 | rsyslog-mmsnmptrapd | — |
| rsyslog-mysql | affected | AlmaLinux:8 | rsyslog-mysql | — |
| rsyslog-omamqp1 | affected | AlmaLinux:8 | rsyslog-omamqp1 | — |
| rsyslog-openssl | affected | AlmaLinux:8 | rsyslog-openssl | — |
| rsyslog-pgsql | affected | AlmaLinux:8 | rsyslog-pgsql | — |
| rsyslog-relp | affected | AlmaLinux:8 | rsyslog-relp | — |
| rsyslog-snmp | affected | AlmaLinux:8 | rsyslog-snmp | — |
| rsyslog-udpspoof | affected | AlmaLinux:8 | rsyslog-udpspoof | — |
Fixed CVE-2022-24903 in rsyslog
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rsyslog | affected | TuxCare:CentOS:8.5 | rsyslog | — |
| rsyslog-crypto | affected | TuxCare:CentOS:8.5 | rsyslog-crypto | — |
| rsyslog-doc | affected | TuxCare:CentOS:8.5 | rsyslog-doc | — |
| rsyslog-elasticsearch | affected | TuxCare:CentOS:8.5 | rsyslog-elasticsearch | — |
| rsyslog-gnutls | affected | TuxCare:CentOS:8.5 | rsyslog-gnutls | — |
| rsyslog-gssapi | affected | TuxCare:CentOS:8.5 | rsyslog-gssapi | — |
| rsyslog-kafka | affected | TuxCare:CentOS:8.5 | rsyslog-kafka | — |
| rsyslog-mmaudit | affected | TuxCare:CentOS:8.5 | rsyslog-mmaudit | — |
| rsyslog-mmjsonparse | affected | TuxCare:CentOS:8.5 | rsyslog-mmjsonparse | — |
| rsyslog-mmkubernetes | affected | TuxCare:CentOS:8.5 | rsyslog-mmkubernetes | — |
| rsyslog-mmnormalize | affected | TuxCare:CentOS:8.5 | rsyslog-mmnormalize | — |
| rsyslog-mmsnmptrapd | affected | TuxCare:CentOS:8.5 | rsyslog-mmsnmptrapd | — |
| rsyslog-mysql | affected | TuxCare:CentOS:8.5 | rsyslog-mysql | — |
| rsyslog-omamqp1 | affected | TuxCare:CentOS:8.5 | rsyslog-omamqp1 | — |
| rsyslog-openssl | affected | TuxCare:CentOS:8.5 | rsyslog-openssl | — |
| rsyslog-pgsql | affected | TuxCare:CentOS:8.5 | rsyslog-pgsql | — |
| rsyslog-relp | affected | TuxCare:CentOS:8.5 | rsyslog-relp | — |
| rsyslog-snmp | affected | TuxCare:CentOS:8.5 | rsyslog-snmp | — |
| rsyslog-udpspoof | affected | TuxCare:CentOS:8.5 | rsyslog-udpspoof | — |
Fixed CVE-2022-24903 in rsyslog
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rsyslog | affected | TuxCare:CentOS:8.4 | rsyslog | — |
| rsyslog-crypto | affected | TuxCare:CentOS:8.4 | rsyslog-crypto | — |
| rsyslog-doc | affected | TuxCare:CentOS:8.4 | rsyslog-doc | — |
| rsyslog-elasticsearch | affected | TuxCare:CentOS:8.4 | rsyslog-elasticsearch | — |
| rsyslog-gnutls | affected | TuxCare:CentOS:8.4 | rsyslog-gnutls | — |
| rsyslog-gssapi | affected | TuxCare:CentOS:8.4 | rsyslog-gssapi | — |
| rsyslog-kafka | affected | TuxCare:CentOS:8.4 | rsyslog-kafka | — |
| rsyslog-mmaudit | affected | TuxCare:CentOS:8.4 | rsyslog-mmaudit | — |
| rsyslog-mmjsonparse | affected | TuxCare:CentOS:8.4 | rsyslog-mmjsonparse | — |
| rsyslog-mmkubernetes | affected | TuxCare:CentOS:8.4 | rsyslog-mmkubernetes | — |
| rsyslog-mmnormalize | affected | TuxCare:CentOS:8.4 | rsyslog-mmnormalize | — |
| rsyslog-mmsnmptrapd | affected | TuxCare:CentOS:8.4 | rsyslog-mmsnmptrapd | — |
| rsyslog-mysql | affected | TuxCare:CentOS:8.4 | rsyslog-mysql | — |
| rsyslog-omamqp1 | affected | TuxCare:CentOS:8.4 | rsyslog-omamqp1 | — |
| rsyslog-pgsql | affected | TuxCare:CentOS:8.4 | rsyslog-pgsql | — |
| rsyslog-relp | affected | TuxCare:CentOS:8.4 | rsyslog-relp | — |
| rsyslog-snmp | affected | TuxCare:CentOS:8.4 | rsyslog-snmp | — |
| rsyslog-udpspoof | affected | TuxCare:CentOS:8.4 | rsyslog-udpspoof | — |
RubyGems Improper Input Validation vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Improper Input Validation vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
Incorrect computation for some invalid field elements in crypto/elliptic
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
RubyGems Improper Verification of Cryptographic Signature vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Improper Verification of Cryptographic Signature vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Deserialization of Untrusted Data vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Deserialization of Untrusted Data vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
Uncontrolled memory consumption in math/big
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
RubyGems Path Traversal vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Path Traversal vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Cross-site Scripting vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Cross-site Scripting vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
Incorrect Default Permissions in JetBrains Kotlin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jetbrains.kotlin:kotlin-stdlib | affected | Maven | org.jetbrains.kotlin:kotlin-stdlib | — |
Incorrect Default Permissions in JetBrains Kotlin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jetbrains.kotlin:kotlin-stdlib | affected | Maven | org.jetbrains.kotlin:kotlin-stdlib | — |
| thingsboard | affected | chainguard | thingsboard | — |
| thingsboard | affected | wolfi | thingsboard | — |
Kubernetes kube-apiserver unauthorized access
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apiextensions-apiserver | affected | k8s.io | k8s.io/apiextensions-apiserver | — |
Kubernetes kube-apiserver unauthorized access
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apiextensions-apiserver | affected | k8s.io | k8s.io/apiextensions-apiserver | — |
Kubernetes client-go library logs may disclose credentials to unauthorized users
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| client-go | affected | k8s.io | k8s.io/client-go | — |
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
Kubernetes client-go library logs may disclose credentials to unauthorized users
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| client-go | affected | k8s.io | k8s.io/client-go | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kubernetes did not effectively clear service account credentials
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kubernetes did not effectively clear service account credentials
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A
CVEs:CVE-2022-20120
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20120
PUB-A-203213034
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-25746
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx...
CVEs:CVE-2021-25746
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ingress-nginx | affected | kubernetes | — | — |
Angular vulnerable to Cross-site Scripting
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| core | affected | angular | @angular/core | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| solr | affected | chainguard | solr | — |
| solr | affected | wolfi | solr | — |
Angular vulnerable to Cross-site Scripting
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| core | affected | angular | @angular/core | — |
Angular vulnerable to Cross-site Scripting
CVEs:CVE-2021-4231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| core | affected | angular | @angular/core | — |
Angular vulnerable to Cross-site Scripting
CVEs:CVE-2021-4231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| core | affected | angular | @angular/core | — |
A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might requ...
CVEs:CVE-2021-4231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | angular | — | — |
| angularjs | affected | angularjs | — | — |
Kubernetes arbitrary file overwrite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kubernetes arbitrary file overwrite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Improper Neutralization of Input During Web Page Generation in Google Web Toolkit
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.gwt:gwt | affected | Maven | com.google.gwt:gwt | — |
Improper Neutralization of Input During Web Page Generation in Google Web Toolkit
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.gwt:gwt | affected | Maven | com.google.gwt:gwt | — |
ingress-nginx component for Kubernetes allows file overwrite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ingress-nginx | affected | k8s.io | k8s.io/ingress-nginx | — |
| ingress-nginx-controller | affected | wolfi | ingress-nginx-controller | — |
| ingress-nginx-controller | affected | chainguard | ingress-nginx-controller | — |
| ingress-nginx-controller-1.9 | affected | chainguard | ingress-nginx-controller-1.9 | — |
| ingress-nginx-controller-fips | affected | chainguard | ingress-nginx-controller-fips | — |
| ingress-nginx-controller-fips-1.9 | affected | chainguard | ingress-nginx-controller-fips-1.9 | — |
ingress-nginx component for Kubernetes allows file overwrite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ingress-nginx | affected | k8s.io | k8s.io/ingress-nginx | — |
ASB-A-218337595
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2022-20008
In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution privileges ne...
CVEs:CVE-2022-20008
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-216481035
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-20009
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20009
ASB-A-213172319
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-216408350
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-20005
In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and a parsed APK . This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...
CVEs:CVE-2022-20005
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20004
In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2022-20004
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege ...
CVEs:CVE-2022-20007
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20007
In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2021-39670
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39670
angular vulnerable to regular expression denial of service (ReDoS)
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
angular vulnerable to regular expression denial of service (ReDoS)
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
| solr | affected | wolfi | solr | — |
| solr | affected | chainguard | solr | — |
angular vulnerable to regular expression denial of service (ReDoS)
CVEs:CVE-2022-25844
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very hig...
CVEs:CVE-2022-25844
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angularjs | affected | angularjs | — | — |
| fedora | affected | fedoraproject | — | — |
| ontap_select_deploy_administration_utility | affected | netapp | — | — |
angular vulnerable to regular expression denial of service (ReDoS)
CVEs:CVE-2022-25844
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
DEBIAN-CVE-2022-25844
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular.js | affected | Debian:12 | angular.js | — |
| angular.js | affected | Debian:11 | angular.js | — |
| angular.js | affected | Debian:13 | angular.js | — |
| angular.js | affected | Debian:14 | angular.js | — |
Important: maven:3.6 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | AlmaLinux:8 | aopalliance | — |
| apache-commons-cli | affected | AlmaLinux:8 | apache-commons-cli | — |
| apache-commons-codec | affected | AlmaLinux:8 | apache-commons-codec | — |
| apache-commons-io | affected | AlmaLinux:8 | apache-commons-io | — |
| apache-commons-lang3 | affected | AlmaLinux:8 | apache-commons-lang3 | — |
| atinject | affected | AlmaLinux:8 | atinject | — |
| cdi-api | affected | AlmaLinux:8 | cdi-api | — |
| geronimo-annotation | affected | AlmaLinux:8 | geronimo-annotation | — |
| google-guice | affected | AlmaLinux:8 | google-guice | — |
| guava | affected | AlmaLinux:8 | guava | — |
| httpcomponents-client | affected | AlmaLinux:8 | httpcomponents-client | — |
| httpcomponents-core | affected | AlmaLinux:8 | httpcomponents-core | — |
| jansi | affected | AlmaLinux:8 | jansi | — |
| jcl-over-slf4j | affected | AlmaLinux:8 | jcl-over-slf4j | — |
| jsoup | affected | AlmaLinux:8 | jsoup | — |
| jsr-305 | affected | AlmaLinux:8 | jsr-305 | — |
| maven | affected | AlmaLinux:8 | maven | — |
| maven-lib | affected | AlmaLinux:8 | maven-lib | — |
| maven-openjdk11 | affected | AlmaLinux:8 | maven-openjdk11 | — |
| maven-openjdk17 | affected | AlmaLinux:8 | maven-openjdk17 | — |
| maven-openjdk8 | affected | AlmaLinux:8 | maven-openjdk8 | — |
| maven-resolver | affected | AlmaLinux:8 | maven-resolver | — |
| maven-shared-utils | affected | AlmaLinux:8 | maven-shared-utils | — |
| maven-wagon | affected | AlmaLinux:8 | maven-wagon | — |
| plexus-cipher | affected | AlmaLinux:8 | plexus-cipher | — |
| plexus-classworlds | affected | AlmaLinux:8 | plexus-classworlds | — |
| plexus-containers-component-annotations | affected | AlmaLinux:8 | plexus-containers-component-annotations | — |
| plexus-interpolation | affected | AlmaLinux:8 | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | AlmaLinux:8 | plexus-sec-dispatcher | — |
| plexus-utils | affected | AlmaLinux:8 | plexus-utils | — |
| sisu | affected | AlmaLinux:8 | sisu | — |
| slf4j | affected | AlmaLinux:8 | slf4j | — |
Important: maven:3.6 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | Rocky Linux:8 | aopalliance | — |
| apache-commons-cli | affected | Rocky Linux:8 | apache-commons-cli | — |
| apache-commons-codec | affected | Rocky Linux:8 | apache-commons-codec | — |
| apache-commons-io | affected | Rocky Linux:8 | apache-commons-io | — |
| apache-commons-lang3 | affected | Rocky Linux:8 | apache-commons-lang3 | — |
| atinject | affected | Rocky Linux:8 | atinject | — |
| cdi-api | affected | Rocky Linux:8 | cdi-api | — |
| geronimo-annotation | affected | Rocky Linux:8 | geronimo-annotation | — |
| google-guice | affected | Rocky Linux:8 | google-guice | — |
| guava | affected | Rocky Linux:8 | guava | — |
| httpcomponents-client | affected | Rocky Linux:8 | httpcomponents-client | — |
| httpcomponents-core | affected | Rocky Linux:8 | httpcomponents-core | — |
| jansi | affected | Rocky Linux:8 | jansi | — |
| jsoup | affected | Rocky Linux:8 | jsoup | — |
| jsr-305 | affected | Rocky Linux:8 | jsr-305 | — |
| maven | affected | Rocky Linux:8 | maven | — |
| maven-resolver | affected | Rocky Linux:8 | maven-resolver | — |
| maven-shared-utils | affected | Rocky Linux:8 | maven-shared-utils | — |
| maven-wagon | affected | Rocky Linux:8 | maven-wagon | — |
| plexus-cipher | affected | Rocky Linux:8 | plexus-cipher | — |
| plexus-classworlds | affected | Rocky Linux:8 | plexus-classworlds | — |
| plexus-containers | affected | Rocky Linux:8 | plexus-containers | — |
| plexus-interpolation | affected | Rocky Linux:8 | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | Rocky Linux:8 | plexus-sec-dispatcher | — |
| plexus-utils | affected | Rocky Linux:8 | plexus-utils | — |
| sisu | affected | Rocky Linux:8 | sisu | — |
| slf4j | affected | Rocky Linux:8 | slf4j | — |
Important: maven:3.5 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | AlmaLinux:8 | aopalliance | — |
| apache-commons-cli | affected | AlmaLinux:8 | apache-commons-cli | — |
| apache-commons-codec | affected | AlmaLinux:8 | apache-commons-codec | — |
| apache-commons-io | affected | AlmaLinux:8 | apache-commons-io | — |
| apache-commons-lang3 | affected | AlmaLinux:8 | apache-commons-lang3 | — |
| apache-commons-logging | affected | AlmaLinux:8 | apache-commons-logging | — |
| atinject | affected | AlmaLinux:8 | atinject | — |
| cdi-api | affected | AlmaLinux:8 | cdi-api | — |
| geronimo-annotation | affected | AlmaLinux:8 | geronimo-annotation | — |
| glassfish-el-api | affected | AlmaLinux:8 | glassfish-el-api | — |
| google-guice | affected | AlmaLinux:8 | google-guice | — |
| guava20 | affected | AlmaLinux:8 | guava20 | — |
| hawtjni-runtime | affected | AlmaLinux:8 | hawtjni-runtime | — |
| httpcomponents-client | affected | AlmaLinux:8 | httpcomponents-client | — |
| httpcomponents-core | affected | AlmaLinux:8 | httpcomponents-core | — |
| jansi | affected | AlmaLinux:8 | jansi | — |
| jansi-native | affected | AlmaLinux:8 | jansi-native | — |
| jboss-interceptors-1.2-api | affected | AlmaLinux:8 | jboss-interceptors-1.2-api | — |
| jcl-over-slf4j | affected | AlmaLinux:8 | jcl-over-slf4j | — |
| jsoup | affected | AlmaLinux:8 | jsoup | — |
| maven | affected | AlmaLinux:8 | maven | — |
| maven-lib | affected | AlmaLinux:8 | maven-lib | — |
| maven-resolver-api | affected | AlmaLinux:8 | maven-resolver-api | — |
| maven-resolver-connector-basic | affected | AlmaLinux:8 | maven-resolver-connector-basic | — |
| maven-resolver-impl | affected | AlmaLinux:8 | maven-resolver-impl | — |
| maven-resolver-spi | affected | AlmaLinux:8 | maven-resolver-spi | — |
| maven-resolver-transport-wagon | affected | AlmaLinux:8 | maven-resolver-transport-wagon | — |
| maven-resolver-util | affected | AlmaLinux:8 | maven-resolver-util | — |
| maven-shared-utils | affected | AlmaLinux:8 | maven-shared-utils | — |
| maven-wagon-file | affected | AlmaLinux:8 | maven-wagon-file | — |
| maven-wagon-http | affected | AlmaLinux:8 | maven-wagon-http | — |
| maven-wagon-http-shared | affected | AlmaLinux:8 | maven-wagon-http-shared | — |
| maven-wagon-provider-api | affected | AlmaLinux:8 | maven-wagon-provider-api | — |
| plexus-cipher | affected | AlmaLinux:8 | plexus-cipher | — |
| plexus-classworlds | affected | AlmaLinux:8 | plexus-classworlds | — |
| plexus-containers-component-annotations | affected | AlmaLinux:8 | plexus-containers-component-annotations | — |
| plexus-interpolation | affected | AlmaLinux:8 | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | AlmaLinux:8 | plexus-sec-dispatcher | — |
| plexus-utils | affected | AlmaLinux:8 | plexus-utils | — |
| sisu-inject | affected | AlmaLinux:8 | sisu-inject | — |
| sisu-plexus | affected | AlmaLinux:8 | sisu-plexus | — |
| slf4j | affected | AlmaLinux:8 | slf4j | — |
Important: maven:3.5 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | Rocky Linux:8 | aopalliance | — |
| apache-commons-cli | affected | Rocky Linux:8 | apache-commons-cli | — |
| apache-commons-codec | affected | Rocky Linux:8 | apache-commons-codec | — |
| apache-commons-io | affected | Rocky Linux:8 | apache-commons-io | — |
| apache-commons-lang3 | affected | Rocky Linux:8 | apache-commons-lang3 | — |
| apache-commons-logging | affected | Rocky Linux:8 | apache-commons-logging | — |
| atinject | affected | Rocky Linux:8 | atinject | — |
| cdi-api | affected | Rocky Linux:8 | cdi-api | — |
| geronimo-annotation | affected | Rocky Linux:8 | geronimo-annotation | — |
| glassfish-el | affected | Rocky Linux:8 | glassfish-el | — |
| google-guice | affected | Rocky Linux:8 | google-guice | — |
| guava20 | affected | Rocky Linux:8 | guava20 | — |
| hawtjni | affected | Rocky Linux:8 | hawtjni | — |
| httpcomponents-client | affected | Rocky Linux:8 | httpcomponents-client | — |
| httpcomponents-core | affected | Rocky Linux:8 | httpcomponents-core | — |
| jansi | affected | Rocky Linux:8 | jansi | — |
| jansi-native | affected | Rocky Linux:8 | jansi-native | — |
| jboss-interceptors-1.2-api | affected | Rocky Linux:8 | jboss-interceptors-1.2-api | — |
| jsoup | affected | Rocky Linux:8 | jsoup | — |
| maven | affected | Rocky Linux:8 | maven | — |
| maven-resolver | affected | Rocky Linux:8 | maven-resolver | — |
| maven-shared-utils | affected | Rocky Linux:8 | maven-shared-utils | — |
| maven-wagon | affected | Rocky Linux:8 | maven-wagon | — |
| plexus-cipher | affected | Rocky Linux:8 | plexus-cipher | — |
| plexus-classworlds | affected | Rocky Linux:8 | plexus-classworlds | — |
| plexus-containers | affected | Rocky Linux:8 | plexus-containers | — |
| plexus-interpolation | affected | Rocky Linux:8 | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | Rocky Linux:8 | plexus-sec-dispatcher | — |
| plexus-utils | affected | Rocky Linux:8 | plexus-utils | — |
| sisu | affected | Rocky Linux:8 | sisu | — |
| slf4j | affected | Rocky Linux:8 | slf4j | — |
Denial of service affecting P-521 and P-384 curves in crypto/elliptic
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
Panic due to large inputs affecting P-256 curves in crypto/elliptic
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
gopkg.in/yaml.v3 Denial of Service
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| yaml.v3 | affected | gopkg.in | gopkg.in/yaml.v3 | — |
gopkg.in/yaml.v3 Denial of Service
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| kubernetes-csi-external-snapshotter-6.0 | affected | chainguard | kubernetes-csi-external-snapshotter-6.0 | — |
| kube-state-metrics-2.2.0 | affected | chainguard | kube-state-metrics-2.2.0 | — |
| nfs-subdir-external-provisioner | affected | chainguard | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner | affected | wolfi | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner-fips | affected | chainguard | nfs-subdir-external-provisioner-fips | — |
| thanos-operator | affected | chainguard | thanos-operator | — |
| thanos-operator | affected | wolfi | thanos-operator | — |
| thanos-operator-fips | affected | chainguard | thanos-operator-fips | — |
| yaml.v3 | affected | gopkg.in | — | — |
| yaml.v3 | affected | gopkg.in | gopkg.in/yaml.v3 | — |
DEBIAN-CVE-2022-28948
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-gopkg-yaml.v3 | affected | Debian:11 | golang-gopkg-yaml.v3 | — |
| golang-gopkg-yaml.v3 | affected | Debian:12 | golang-gopkg-yaml.v3 | — |
| golang-gopkg-yaml.v3 | affected | Debian:13 | golang-gopkg-yaml.v3 | — |
| golang-gopkg-yaml.v3 | affected | Debian:14 | golang-gopkg-yaml.v3 | — |
golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpcurl | affected | chainguard | grpcurl | — |
| grpcurl | affected | wolfi | grpcurl | — |
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| x/net | affected | golang.org | golang.org/x/net | — |
| x/net | affected | golang.org | — | — |
golang.org/x/crypto/salsa20/salsa uses insufficiently random values
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
golang.org/x/crypto/salsa20/salsa uses insufficiently random values
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
Denial of service in .NET core
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| Microsoft.NETCore.App | affected | NuGet | Microsoft.NETCore.App | — |
| Microsoft.NETCore.App | affected | NuGet | Microsoft.NETCore.App | — |
| Microsoft.NETCore.App.Host.linux-arm | affected | NuGet | Microsoft.NETCore.App.Host.linux-arm | — |
| Microsoft.NETCore.App.Host.linux-arm | affected | NuGet | Microsoft.NETCore.App.Host.linux-arm | — |
| Microsoft.NETCore.App.Host.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-arm64 | — |
| Microsoft.NETCore.App.Host.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-arm64 | — |
| Microsoft.NETCore.App.Host.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Host.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Host.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-musl-x64 | — |
| Microsoft.NETCore.App.Host.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-musl-x64 | — |
| Microsoft.NETCore.App.Host.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-x64 | — |
| Microsoft.NETCore.App.Host.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-x64 | — |
| Microsoft.NETCore.App.Host.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Host.osx-x64 | — |
| Microsoft.NETCore.App.Host.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Host.osx-x64 | — |
| Microsoft.NETCore.App.Host.rhel.6-x64 | affected | NuGet | Microsoft.NETCore.App.Host.rhel.6-x64 | — |
| Microsoft.NETCore.App.Host.rhel.6-x64 | affected | NuGet | Microsoft.NETCore.App.Host.rhel.6-x64 | — |
| Microsoft.NETCore.App.Host.win-arm | affected | NuGet | Microsoft.NETCore.App.Host.win-arm | — |
| Microsoft.NETCore.App.Host.win-arm | affected | NuGet | Microsoft.NETCore.App.Host.win-arm | — |
| Microsoft.NETCore.App.Host.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.win-arm64 | — |
| Microsoft.NETCore.App.Host.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.win-arm64 | — |
| Microsoft.NETCore.App.Host.win-x64 | affected | NuGet | Microsoft.NETCore.App.Host.win-x64 | — |
| Microsoft.NETCore.App.Host.win-x64 | affected | NuGet | Microsoft.NETCore.App.Host.win-x64 | — |
| Microsoft.NETCore.App.Host.win-x86 | affected | NuGet | Microsoft.NETCore.App.Host.win-x86 | — |
| Microsoft.NETCore.App.Host.win-x86 | affected | NuGet | Microsoft.NETCore.App.Host.win-x86 | — |
| Microsoft.NETCore.App.Runtime.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.android-arm | — |
| Microsoft.NETCore.App.Runtime.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.android-arm | — |
| Microsoft.NETCore.App.Runtime.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-x64 | — |
| Microsoft.NETCore.App.Runtime.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-x64 | — |
| Microsoft.NETCore.App.Runtime.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-x86 | — |
| Microsoft.NETCore.App.Runtime.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-x86 | — |
| Microsoft.NETCore.App.Runtime.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-arm | — |
| Microsoft.NETCore.App.Runtime.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-arm | — |
| Microsoft.NETCore.App.Runtime.ios-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-x64 | — |
| Microsoft.NETCore.App.Runtime.ios-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-x64 | — |
| Microsoft.NETCore.App.Runtime.ios-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-x86 | — |
| Microsoft.NETCore.App.Runtime.ios-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-x86 | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.rhel.6-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.rhel.6-x64 | — |
| Microsoft.NETCore.App.Runtime.rhel.6-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.rhel.6-x64 | — |
| Microsoft.NETCore.App.Runtime.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.tvos-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.tvos-x64 | — |
| Microsoft.NETCore.App.Runtime.tvos-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.tvos-x64 | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
Denial of service in .NET core
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| Microsoft.NETCore.App | affected | NuGet | Microsoft.NETCore.App | — |
| Microsoft.NETCore.App.Host.linux-arm | affected | NuGet | Microsoft.NETCore.App.Host.linux-arm | — |
| Microsoft.NETCore.App.Host.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-arm64 | — |
| Microsoft.NETCore.App.Host.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Host.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-musl-x64 | — |
| Microsoft.NETCore.App.Host.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Host.linux-x64 | — |
| Microsoft.NETCore.App.Host.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Host.osx-x64 | — |
| Microsoft.NETCore.App.Host.rhel.6-x64 | affected | NuGet | Microsoft.NETCore.App.Host.rhel.6-x64 | — |
| Microsoft.NETCore.App.Host.win-arm | affected | NuGet | Microsoft.NETCore.App.Host.win-arm | — |
| Microsoft.NETCore.App.Host.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Host.win-arm64 | — |
| Microsoft.NETCore.App.Host.win-x64 | affected | NuGet | Microsoft.NETCore.App.Host.win-x64 | — |
| Microsoft.NETCore.App.Host.win-x86 | affected | NuGet | Microsoft.NETCore.App.Host.win-x86 | — |
| Microsoft.NETCore.App.Runtime.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.android-arm | — |
| Microsoft.NETCore.App.Runtime.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-x64 | — |
| Microsoft.NETCore.App.Runtime.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.android-x86 | — |
| Microsoft.NETCore.App.Runtime.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-arm | — |
| Microsoft.NETCore.App.Runtime.ios-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-x64 | — |
| Microsoft.NETCore.App.Runtime.ios-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.ios-x86 | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.rhel.6-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.rhel.6-x64 | — |
| Microsoft.NETCore.App.Runtime.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.tvos-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.tvos-x64 | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
DEBIAN-CVE-2022-30321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-hashicorp-go-getter | affected | Debian:11 | golang-github-hashicorp-go-getter | — |
| golang-github-hashicorp-go-getter | affected | Debian:12 | golang-github-hashicorp-go-getter | — |
Integer overflow in the bundled Brotli C library
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| brotli | affected | PyPI | brotli | — |
| compu-brotli-sys | affected | crates.io | compu-brotli-sys | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x86 | — |
| Microsoft.NETCore.App.Runtime.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
Integer overflow in the bundled Brotli C library
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| brotli | affected | chainguard | brotli | — |
| brotli | affected | PyPI | brotli | — |
| brotli | affected | wolfi | brotli | — |
| compu-brotli-sys | affected | crates.io | compu-brotli-sys | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-arm64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x64 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x86 | — |
| Microsoft.NETCore.App.Runtime.Mono.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.Mono.win-x86 | — |
| Microsoft.NETCore.App.Runtime.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.osx-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-arm64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.osx-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.osx-x64 | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-arm64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-arm64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x64 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x64 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
| Microsoft.NETCore.App.Runtime.win-x86 | affected | NuGet | Microsoft.NETCore.App.Runtime.win-x86 | — |
Stack exhaustion when compiling deeply nested expressions in regexp
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
DLL injection on Windows in runtime and syscall
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
Updated golang packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:8 | golang | — |
| golang | affected | golang | — | — |
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
CVEs:CVE-2022-29526
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| beegfs_csi_driver | affected | netapp | — | — |
| fedora | affected | fedoraproject | — | — |
| go | affected | golang | — | — |
golang.org/x/sys/unix has Incorrect privilege reporting in syscall
CVEs:CVE-2022-29526
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/sys | affected | golang.org | golang.org/x/sys | — |
RCE vulnerability in Google Kubernetes Engine Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-kubernetes-engine | affected | Maven | org.jenkins-ci.plugins:google-kubernetes-engine | — |
RCE vulnerability in Google Kubernetes Engine Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-kubernetes-engine | affected | Maven | org.jenkins-ci.plugins:google-kubernetes-engine | — |
Prototype Pollution in protobufjs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobufjs | affected | npm | protobufjs | — |
Prototype Pollution in protobufjs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobufjs | affected | npm | protobufjs | — |
Prototype Pollution in protobufjs
CVEs:CVE-2022-25878
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobufjs | affected | npm | protobufjs | — |
Prototype Pollution in protobufjs
CVEs:CVE-2022-25878
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobufjs | affected | npm | protobufjs | — |
The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProp...
CVEs:CVE-2022-25878
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobufjs | affected | protobufjs_project | — | — |
Istio ReDoS Vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cert-manager-istio-csr | affected | wolfi | cert-manager-istio-csr | — |
| cert-manager-istio-csr | affected | chainguard | cert-manager-istio-csr | — |
| cert-manager-istio-csr-fips | affected | chainguard | cert-manager-istio-csr-fips | — |
| istio | affected | istio.io | istio.io/istio | — |
| istio-cni-1.21 | affected | chainguard | istio-cni-1.21 | — |
| istio-cni-1.21 | affected | wolfi | istio-cni-1.21 | — |
| istio-cni-1.22 | affected | wolfi | istio-cni-1.22 | — |
| istio-cni-1.22 | affected | chainguard | istio-cni-1.22 | — |
| istio-fips-1.21 | affected | chainguard | istio-fips-1.21 | — |
| istio-operator-1.20 | affected | wolfi | istio-operator-1.20 | — |
| istio-operator-1.20 | affected | chainguard | istio-operator-1.20 | — |
| istio-operator-1.21 | affected | wolfi | istio-operator-1.21 | — |
| istio-operator-1.21 | affected | chainguard | istio-operator-1.21 | — |
| istio-operator-1.22 | affected | chainguard | istio-operator-1.22 | — |
| istio-operator-1.22 | affected | wolfi | istio-operator-1.22 | — |
| istio-pilot-agent-1.21 | affected | wolfi | istio-pilot-agent-1.21 | — |
| istio-pilot-agent-1.21 | affected | chainguard | istio-pilot-agent-1.21 | — |
| istio-pilot-agent-1.22 | affected | wolfi | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22 | affected | chainguard | istio-pilot-agent-1.22 | — |
| istio-pilot-discovery-1.21 | affected | chainguard | istio-pilot-discovery-1.21 | — |
| istio-pilot-discovery-1.21 | affected | wolfi | istio-pilot-discovery-1.21 | — |
| istio-pilot-discovery-1.22 | affected | wolfi | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22 | affected | chainguard | istio-pilot-discovery-1.22 | — |
| kgateway-2.3 | affected | chainguard | kgateway-2.3 | — |
| kgateway-2.4 | affected | chainguard | kgateway-2.4 | — |
| kgateway-fips-2.3 | affected | chainguard | kgateway-fips-2.3 | — |
| kgateway-fips-2.4 | affected | chainguard | kgateway-fips-2.4 | — |
Istio ReDoS Vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio.io | istio.io/istio | — |
RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.elasticbox.jenkins-ci.plugins:kubernetes-ci | affected | Maven | com.elasticbox.jenkins-ci.plugins:kubernetes-ci | — |
RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.elasticbox.jenkins-ci.plugins:kubernetes-ci | affected | Maven | com.elasticbox.jenkins-ci.plugins:kubernetes-ci | — |
Golang/x/crypto message forgery vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
Golang/x/crypto message forgery vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aws-ebs-csi-driver | affected | chainguard | aws-ebs-csi-driver | — |
| aws-ebs-csi-driver | affected | wolfi | aws-ebs-csi-driver | — |
| aws-ebs-csi-driver-1.18 | affected | chainguard | aws-ebs-csi-driver-1.18 | — |
| aws-ebs-csi-driver-1.19 | affected | chainguard | aws-ebs-csi-driver-1.19 | — |
| aws-efs-csi-driver | affected | wolfi | aws-efs-csi-driver | — |
| aws-efs-csi-driver | affected | chainguard | aws-efs-csi-driver | — |
| calico | affected | wolfi | calico | — |
| calico | affected | chainguard | calico | — |
| cri-tools | affected | chainguard | cri-tools | — |
| cri-tools | affected | wolfi | cri-tools | — |
| kubernetes-1.26 | affected | chainguard | kubernetes-1.26 | — |
| kubernetes-1.26 | affected | wolfi | kubernetes-1.26 | — |
| kubernetes-1.27 | affected | chainguard | kubernetes-1.27 | — |
| kubernetes-1.27 | affected | wolfi | kubernetes-1.27 | — |
| kubernetes-1.28 | affected | chainguard | kubernetes-1.28 | — |
| kubernetes-1.28 | affected | wolfi | kubernetes-1.28 | — |
| kubernetes-csi-external-provisioner | affected | wolfi | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-external-provisioner | affected | chainguard | kubernetes-csi-external-provisioner | — |
| kubernetes-csi/external-provisioner | affected | github.com | github.com/kubernetes-csi/external-provisioner | — |
| kubernetes-csi/external-resizer | affected | github.com | github.com/kubernetes-csi/external-resizer | — |
| kubernetes-csi/external-snapshotter/v6 | affected | github.com | github.com/kubernetes-csi/external-snapshotter/v6 | — |
| kubernetes-dns-node-cache | affected | wolfi | kubernetes-dns-node-cache | — |
| kubernetes-dns-node-cache | affected | chainguard | kubernetes-dns-node-cache | — |
| nodetaint | affected | wolfi | nodetaint | — |
| nodetaint | affected | chainguard | nodetaint | — |
Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-csi/external-provisioner | affected | github.com | github.com/kubernetes-csi/external-provisioner | — |
| kubernetes-csi/external-resizer | affected | github.com | github.com/kubernetes-csi/external-resizer | — |
| kubernetes-csi/external-snapshotter/v6 | affected | github.com | github.com/kubernetes-csi/external-snapshotter/v6 | — |
Misdirected I/O in syscall
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | — | — |
| stdlib | affected | Go | stdlib | — |
CVEs:CVE-2022-30127
CVEs:CVE-2022-30128
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-30127
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-30128
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2022-26905
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2022-26905
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
kube-state-metrics may expose secret content in metrics
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-state-metrics | affected | k8s.io | k8s.io/kube-state-metrics | — |
kube-state-metrics may expose secret content in metrics
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-state-metrics | affected | k8s.io | k8s.io/kube-state-metrics | — |
DEBIAN-CVE-2022-26945
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-hashicorp-go-getter | affected | Debian:11 | golang-github-hashicorp-go-getter | — |
| golang-github-hashicorp-go-getter | affected | Debian:12 | golang-github-hashicorp-go-getter | — |
GHSA-5rvp-q2j7-h9rj
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
Panic during certificate parsing on Darwin in crypto/x509
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
DEBIAN-CVE-2022-30322
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-hashicorp-go-getter | affected | Debian:12 | golang-github-hashicorp-go-getter | — |
| golang-github-hashicorp-go-getter | affected | Debian:11 | golang-github-hashicorp-go-getter | — |
DEBIAN-CVE-2022-30323
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-hashicorp-go-getter | affected | Debian:12 | golang-github-hashicorp-go-getter | — |
| golang-github-hashicorp-go-getter | affected | Debian:11 | golang-github-hashicorp-go-getter | — |
Kubernetes Secrets Store CSI Driver plugins arbitrary file write
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| Azure/secrets-store-csi-driver-provider-azure | affected | github.com | github.com/Azure/secrets-store-csi-driver-provider-azure | — |
| GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp | affected | github.com | github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp | — |
| hashicorp/vault-csi-provider | affected | github.com | github.com/hashicorp/vault-csi-provider | — |
Kubernetes Secrets Store CSI Driver plugins arbitrary file write
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| Azure/secrets-store-csi-driver-provider-azure | affected | github.com | github.com/Azure/secrets-store-csi-driver-provider-azure | — |
| GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp | affected | github.com | github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp | — |
| hashicorp/vault-csi-provider | affected | github.com | github.com/hashicorp/vault-csi-provider | — |
| secrets-store-csi-driver-provider-azure | affected | wolfi | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-azure | affected | chainguard | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-azure-fips | affected | chainguard | secrets-store-csi-driver-provider-azure-fips | — |
| vault-csi-provider | affected | chainguard | vault-csi-provider | — |
| vault-csi-provider-fips | affected | chainguard | vault-csi-provider-fips | — |
CVEs:CVE-2022-1919
Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1919
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| io.fabric8:kubernetes-client | affected | Maven | io.fabric8:kubernetes-client | — |
Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| io.fabric8:kubernetes-client | affected | Maven | io.fabric8:kubernetes-client | — |
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes | affected | Maven | org.csanchez.jenkins.plugins:kubernetes | — |
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes | affected | Maven | org.csanchez.jenkins.plugins:kubernetes | — |
Istio vulnerable to denial of service
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio.io | istio.io/istio | — |
Istio vulnerable to denial of service
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio.io | istio.io/istio | — |
Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| io.fabric8.pipeline:kubernetes-pipeline-steps | affected | Maven | io.fabric8.pipeline:kubernetes-pipeline-steps | — |
Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| io.fabric8.pipeline:kubernetes-pipeline-steps | affected | Maven | io.fabric8.pipeline:kubernetes-pipeline-steps | — |
Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps | affected | Maven | io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps | — |
Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps | affected | Maven | io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps | — |
Improper Input Validation in k8s.io/ingress-nginx
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ingress-nginx | affected | k8s.io | k8s.io/ingress-nginx | — |
Improper Input Validation in k8s.io/ingress-nginx
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ingress-nginx | affected | k8s.io | k8s.io/ingress-nginx | — |
| ingress-nginx-controller | affected | wolfi | ingress-nginx-controller | — |
| ingress-nginx-controller | affected | chainguard | ingress-nginx-controller | — |
| ingress-nginx-controller-1.9 | affected | chainguard | ingress-nginx-controller-1.9 | — |
| ingress-nginx-controller-fips | affected | chainguard | ingress-nginx-controller-fips | — |
| ingress-nginx-controller-fips-1.9 | affected | chainguard | ingress-nginx-controller-fips-1.9 | — |
Improper Input Validation in k8s.io/ingress-nginx
CVEs:CVE-2021-25745
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ingress-nginx | affected | k8s.io | k8s.io/ingress-nginx | — |
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials o...
CVEs:CVE-2021-25745
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ingress-nginx | affected | kubernetes | — | — |
Missing Authorization in Jenkins Kubernetes Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes | affected | Maven | org.csanchez.jenkins.plugins:kubernetes | — |
Missing Authorization in Jenkins Kubernetes Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes | affected | Maven | org.csanchez.jenkins.plugins:kubernetes | — |
Missing authorization in Jenkins Kubernetes Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes | affected | Maven | org.csanchez.jenkins.plugins:kubernetes | — |
Missing authorization in Jenkins Kubernetes Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes | affected | Maven | org.csanchez.jenkins.plugins:kubernetes | — |
CVEs:CVE-2022-1489
Out of bounds memory access in UI Shelf in Google Chrome on Chrome OS, Lacros prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific user interactions.
CVEs:CVE-2022-1489
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Improper Limitation of a Pathname to a Restricted Directory in Jenkins Google OAuth Credentials Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-oauth-plugin | affected | Maven | org.jenkins-ci.plugins:google-oauth-plugin | — |
Improper Limitation of a Pathname to a Restricted Directory in Jenkins Google OAuth Credentials Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-oauth-plugin | affected | Maven | org.jenkins-ci.plugins:google-oauth-plugin | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interaction.
CVEs:CVE-2022-1641
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1641
CVEs:CVE-2022-1639
Use after free in ANGLE in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1639
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1640
Use after free in Sharing in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1640
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in File Manager in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.
CVEs:CVE-2022-1496
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1496
Jenkins Google Compute Engine Plugin does not verify SSH host keys when connecting agents created by the plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-compute-engine | affected | Maven | org.jenkins-ci.plugins:google-compute-engine | — |
Jenkins Google Compute Engine Plugin does not verify SSH host keys when connecting agents created by the plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-compute-engine | affected | Maven | org.jenkins-ci.plugins:google-compute-engine | — |
Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| io.alauda.jenkins.plugins:alauda-kubernetes-support | affected | Maven | io.alauda.jenkins.plugins:alauda-kubernetes-support | — |
Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| io.alauda.jenkins.plugins:alauda-kubernetes-support | affected | Maven | io.alauda.jenkins.plugins:alauda-kubernetes-support | — |
CVEs:CVE-2022-1636
Use after free in Performance APIs in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1636
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Improper Authorization in Jenkins Alauda Kubernetes Suport Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| io.alauda.jenkins.plugins:alauda-kubernetes-support | affected | Maven | io.alauda.jenkins.plugins:alauda-kubernetes-support | — |
Improper Authorization in Jenkins Alauda Kubernetes Suport Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| io.alauda.jenkins.plugins:alauda-kubernetes-support | affected | Maven | io.alauda.jenkins.plugins:alauda-kubernetes-support | — |
Jenkins Kubernetes CI/CD Plugin vulnerable to Credential Enumeration
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.elasticbox.jenkins-ci.plugins:kubernetes-ci | affected | Maven | com.elasticbox.jenkins-ci.plugins:kubernetes-ci | — |
Jenkins Kubernetes CI/CD Plugin vulnerable to Credential Enumeration
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.elasticbox.jenkins-ci.plugins:kubernetes-ci | affected | Maven | com.elasticbox.jenkins-ci.plugins:kubernetes-ci | — |
Jenkins Kubernetes CI/CD Plugin vulnerable to Improper Authorization
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.elasticbox.jenkins-ci.plugins:kubernetes-ci | affected | Maven | com.elasticbox.jenkins-ci.plugins:kubernetes-ci | — |
Jenkins Kubernetes CI/CD Plugin vulnerable to Improper Authorization
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.elasticbox.jenkins-ci.plugins:kubernetes-ci | affected | Maven | com.elasticbox.jenkins-ci.plugins:kubernetes-ci | — |
Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-1637
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1637
Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.
CVEs:CVE-2022-1633
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1633
CVEs:CVE-2022-1634
Use after free in Browser UI in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who had convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific user interactions.
CVEs:CVE-2022-1634
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in Permission Prompts in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.
CVEs:CVE-2022-1635
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1635
Stored XSS vulnerability in android-lint Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jvnet.hudson.plugins:android-lint | affected | Maven | org.jvnet.hudson.plugins:android-lint | — |
Stored XSS vulnerability in android-lint Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jvnet.hudson.plugins:android-lint | affected | Maven | org.jvnet.hudson.plugins:android-lint | — |
Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1638
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1638
Jenkins Google Compute Engine Plugin Missing Authorization vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-compute-engine | affected | Maven | org.jenkins-ci.plugins:google-compute-engine | — |
Jenkins Google Compute Engine Plugin Missing Authorization vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-compute-engine | affected | Maven | org.jenkins-ci.plugins:google-compute-engine | — |
Jenkins Google Compute Engine Plugin Cross-Site Request Forgery vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-compute-engine | affected | Maven | org.jenkins-ci.plugins:google-compute-engine | — |
Jenkins Google Compute Engine Plugin Cross-Site Request Forgery vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-compute-engine | affected | Maven | org.jenkins-ci.plugins:google-compute-engine | — |
Missing permission checks in Google Kubernetes Engine Jenkins Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-kubernetes-engine | affected | Maven | org.jenkins-ci.plugins:google-kubernetes-engine | — |
Missing permission checks in Google Kubernetes Engine Jenkins Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-kubernetes-engine | affected | Maven | org.jenkins-ci.plugins:google-kubernetes-engine | — |
Jenkins Kubernetes CI/CD Plugin vulnerable to Cross-Site Request Forgery
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.elasticbox.jenkins-ci.plugins:kubernetes-ci | affected | Maven | com.elasticbox.jenkins-ci.plugins:kubernetes-ci | — |
Jenkins Kubernetes CI/CD Plugin vulnerable to Cross-Site Request Forgery
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.elasticbox.jenkins-ci.plugins:kubernetes-ci | affected | Maven | com.elasticbox.jenkins-ci.plugins:kubernetes-ci | — |
Logic error in Matrix SDK for Android
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.matrix.android:matrix-android-sdk2 | affected | Maven | org.matrix.android:matrix-android-sdk2 | — |
Logic error in Matrix SDK for Android
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.matrix.android:matrix-android-sdk2 | affected | Maven | org.matrix.android:matrix-android-sdk2 | — |
CVEs:CVE-2022-27875
On F5 Access for Android 3.x versions prior to 3.0.8, a Task Hijacking vulnerability exists in the F5 Access for Android application, which may allow an attacker to steal sensitive user information. Note: Software versions which have reached End of Tec...
CVEs:CVE-2022-27875
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| access_for_android | affected | f5 | — | — |
CVEs:CVE-2021-36912
Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role.
CVEs:CVE-2021-36912
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-news-sitemap | affected | google-news-sitemap_project | — | — |
Code injection in `saved_model_cli` in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Code injection in `saved_model_cli` in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Code injection in `saved_model_cli` in TensorFlow
CVEs:CVE-2022-29216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shell. This code path was maintained...
CVEs:CVE-2022-29216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Code injection in `saved_model_cli` in TensorFlow
CVEs:CVE-2022-29216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Type confusion leading to `CHECK`-failure based denial of service in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Type confusion leading to `CHECK`-failure based denial of service in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the macros that TensorFlow uses for writing assertions (e.g., `CHECK_LT`, `CHECK_GT`, etc.) have an incorrect logic when comparing `size_t` an...
CVEs:CVE-2022-29209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Type confusion leading to `CHECK`-failure based denial of service in TensorFlow
CVEs:CVE-2022-29209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Type confusion leading to `CHECK`-failure based denial of service in TensorFlow
CVEs:CVE-2022-29209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault and OOB write due to incomplete validation in `EditDistance` in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault and OOB write due to incomplete validation in `EditDistance` in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.EditDistance` has incomplete validation. Users can pass negative values to cause a segmentation fault based ...
CVEs:CVE-2022-29208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Segfault and OOB write due to incomplete validation in `EditDistance` in TensorFlow
CVEs:CVE-2022-29208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault and OOB write due to incomplete validation in `EditDistance` in TensorFlow
CVEs:CVE-2022-29208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Information leak in Gerrit
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.gerrit:gerrit-plugin-api | affected | Maven | com.google.gerrit:gerrit-plugin-api | — |
Information leak in Gerrit
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.gerrit:gerrit-plugin-api | affected | Maven | com.google.gerrit:gerrit-plugin-api | — |
Missing validation causes denial of service via `GetSessionTensor`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `GetSessionTensor`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.GetSessionTensor` does not fully validate the input arguments. This results in a `CHECK`-failure which can b...
CVEs:CVE-2022-29191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation causes denial of service via `GetSessionTensor`
CVEs:CVE-2022-29191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `GetSessionTensor`
CVEs:CVE-2022-29191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `Conv3DBackpropFilterV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `Conv3DBackpropFilterV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.UnsortedSegmentJoin` does not fully validate the input arguments. This results in a `CHECK`-failure which ca...
CVEs:CVE-2022-29204
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation causes denial of service via `Conv3DBackpropFilterV2`
CVEs:CVE-2022-29204
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `Conv3DBackpropFilterV2`
CVEs:CVE-2022-29204
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Jenkins Google Kubernetes Engine Plugin vulnerable to Exposure of Resource to Wrong Sphere
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-kubernetes-engine | affected | Maven | org.jenkins-ci.plugins:google-kubernetes-engine | — |
Jenkins Google Kubernetes Engine Plugin vulnerable to Exposure of Resource to Wrong Sphere
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-kubernetes-engine | affected | Maven | org.jenkins-ci.plugins:google-kubernetes-engine | — |
Missing validation crashes `QuantizeAndDequantizeV4Grad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation crashes `QuantizeAndDequantizeV4Grad`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` does not fully validate the input arguments. This results in a `CHECK`-failure ...
CVEs:CVE-2022-29192
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation crashes `QuantizeAndDequantizeV4Grad`
CVEs:CVE-2022-29192
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation crashes `QuantizeAndDequantizeV4Grad`
CVEs:CVE-2022-29192
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation results in undefined behavior in `SparseTensorDenseAdd
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation results in undefined behavior in `SparseTensorDenseAdd
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation results in undefined behavior in `SparseTensorDenseAdd
CVEs:CVE-2022-29206
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.SparseTensorDenseAdd` does not fully validate the input arguments. In this case, a reference gets bound to a...
CVEs:CVE-2022-29206
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation results in undefined behavior in `SparseTensorDenseAdd
CVEs:CVE-2022-29206
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer overflow in `SpaceToBatchND`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer overflow in `SpaceToBatchND`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation results in undefined behavior in `QuantizedConv2D`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation results in undefined behavior in `QuantizedConv2D`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation results in undefined behavior in `QuantizedConv2D`
CVEs:CVE-2022-29201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.QuantizedConv2D` does not fully validate the input arguments. In this case, references get bound to `nullptr...
CVEs:CVE-2022-29201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation results in undefined behavior in `QuantizedConv2D`
CVEs:CVE-2022-29201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer overflow in `SpaceToBatchND`
CVEs:CVE-2022-29203
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Integer overflow in `SpaceToBatchND`
CVEs:CVE-2022-29203
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.SpaceToBatchND` (in all backends such as XLA and handwritten kernels) is vulnerable to an integer overflow: ...
CVEs:CVE-2022-29203
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation causes denial of service via `DeleteSessionTensor`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `DeleteSessionTensor`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `DeleteSessionTensor`
CVEs:CVE-2022-29194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `DeleteSessionTensor`
CVEs:CVE-2022-29194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.DeleteSessionTensor` does not fully validate the input arguments. This results in a `CHECK`-failure which ca...
CVEs:CVE-2022-29194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Undefined behavior when users supply invalid resource handles
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior when users supply invalid resource handles
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault due to missing support for quantized types
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault due to missing support for quantized types
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `LSTMBlockCell`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `LSTMBlockCell`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `LoadAndRemapMatrix`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `LoadAndRemapMatrix`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `UnsortedSegmentJoin`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `UnsortedSegmentJoin`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `Conv3DBackpropFilterV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `Conv3DBackpropFilterV2`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `StagePeek`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `StagePeek`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes `TensorSummaryV2` to crash
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes `TensorSummaryV2` to crash
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.TensorSummaryV2` does not fully validate the input arguments. This results in a `CHECK`-failure which can be...
CVEs:CVE-2022-29193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation causes `TensorSummaryV2` to crash
CVEs:CVE-2022-29193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes `TensorSummaryV2` to crash
CVEs:CVE-2022-29193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `StagePeek`
CVEs:CVE-2022-29195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.StagePeek` does not fully validate the input arguments. This results in a `CHECK`-failure which can be used ...
CVEs:CVE-2022-29195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation causes denial of service via `StagePeek`
CVEs:CVE-2022-29195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `Conv3DBackpropFilterV2`
CVEs:CVE-2022-29196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.Conv3DBackpropFilterV2` does not fully validate the input arguments. This results in a `CHECK`-failure which...
CVEs:CVE-2022-29196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation causes denial of service via `Conv3DBackpropFilterV2`
CVEs:CVE-2022-29196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `UnsortedSegmentJoin`
CVEs:CVE-2022-29197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.UnsortedSegmentJoin` does not fully validate the input arguments. This results in a `CHECK`-failure which ca...
CVEs:CVE-2022-29197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation causes denial of service via `UnsortedSegmentJoin`
CVEs:CVE-2022-29197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.SparseTensorToCSRSparseMatrix` does not fully validate the input arguments. This results in a `CHECK`-failur...
CVEs:CVE-2022-29198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`
CVEs:CVE-2022-29198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`
CVEs:CVE-2022-29198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `LoadAndRemapMatrix`
CVEs:CVE-2022-29199
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Missing validation causes denial of service via `LoadAndRemapMatrix`
CVEs:CVE-2022-29199
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.LoadAndRemapMatrix does not fully validate the input arguments. This results in a `CHECK`-failure which can ...
CVEs:CVE-2022-29199
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation causes denial of service via `LSTMBlockCell`
CVEs:CVE-2022-29200
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.LSTMBlockCell` does not fully validate the input arguments. This results in a `CHECK`-failure which can be u...
CVEs:CVE-2022-29200
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Missing validation causes denial of service via `LSTMBlockCell`
CVEs:CVE-2022-29200
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault due to missing support for quantized types
CVEs:CVE-2022-29205
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, there is a potential for segfault / denial of service in TensorFlow by calling `tf.compat.v1.*` ops which don't yet have support for quantized...
CVEs:CVE-2022-29205
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Segfault due to missing support for quantized types
CVEs:CVE-2022-29205
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Undefined behavior when users supply invalid resource handles
CVEs:CVE-2022-29207
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, multiple TensorFlow operations misbehave in eager mode when the resource handle provided to them is invalid. In graph mode, it would have been...
CVEs:CVE-2022-29207
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Undefined behavior when users supply invalid resource handles
CVEs:CVE-2022-29207
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Core dump when loading TFLite models with quantization in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Core dump when loading TFLite models with quantization in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of service in `tf.ragged.constant` due to lack of validation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of service in `tf.ragged.constant` due to lack of validation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Core dump when loading TFLite models with quantization in TensorFlow
CVEs:CVE-2022-29212
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, certain TFLite models that were created using TFLite model converter would crash when loaded in the TFLite interpreter. The culprit is that du...
CVEs:CVE-2022-29212
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Core dump when loading TFLite models with quantization in TensorFlow
CVEs:CVE-2022-29212
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Denial of service in `tf.ragged.constant` due to lack of validation
CVEs:CVE-2022-29202
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.ragged.constant` does not fully validate the input arguments. This results in a denial of service by consuming all a...
CVEs:CVE-2022-29202
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Denial of service in `tf.ragged.constant` due to lack of validation
CVEs:CVE-2022-29202
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.histogram_fixed_width` is vulnerable to a crash when the values array contain `Not a Number` (`NaN`) elements. The i...
CVEs:CVE-2022-29211
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow
CVEs:CVE-2022-29211
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow
CVEs:CVE-2022-29211
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Incomplete validation in signal ops leads to crashes in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Incomplete validation in signal ops leads to crashes in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Incomplete validation in signal ops leads to crashes in TensorFlow
CVEs:CVE-2022-29213
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the `tf.compat.v1.signal.rfft2d` and `tf.compat.v1.signal.rfft3d` lack input validation and under certain condition can result in crashes (due...
CVEs:CVE-2022-29213
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
Incomplete validation in signal ops leads to crashes in TensorFlow
CVEs:CVE-2022-29213
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2022-20010
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20010
Heap buffer overflow due to incorrect hash function in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow due to incorrect hash function in TensorFlow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow due to incorrect hash function in TensorFlow
CVEs:CVE-2022-29210
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Heap buffer overflow due to incorrect hash function in TensorFlow
CVEs:CVE-2022-29210
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. In version 2.8.0, the `TensorKey` hash function used total estimated `AllocatedBytes()`, which (a) is an estimate per tensor, and (b) is a very poor hash function for constants (e.g. `int32_t`...
CVEs:CVE-2022-29210
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. ...
CVEs:CVE-2022-20113
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20113
ASB-A-218337596
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2021-22556
The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache invalidation operations on pages that they don’t own, allowing them to control kernel memory from userspace. We recommend upgrading...
CVEs:CVE-2021-22556
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| fuchsia | affected | — | — |
PUB-A-190503256
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
PUB-A-204909309
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
| vendor/qcom-opensource/data-kernel | affected | platform | platform/vendor/qcom-opensource/data-kernel | — |
Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.
CVEs:CVE-2022-28781
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-28781
In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's under the lockscreen due to a race condition. This could lead to local escalation of privilege if a Guest user is enabled, with no ad...
CVEs:CVE-2022-20006
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20006
In aee daemon, there is a possible information disclosure due to symbolic link following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; ...
CVEs:CVE-2022-20103
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20103
In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV0333046...
CVEs:CVE-2022-20105
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
CVEs:CVE-2022-20105
In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460...
CVEs:CVE-2022-20106
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
CVEs:CVE-2022-20106
CVEs:CVE-2022-20108
In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV0333...
CVEs:CVE-2022-20108
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
DEBIAN-CVE-2022-20011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android-platform-frameworks-base | affected | Debian:11 | android-platform-frameworks-base | — |
| android-platform-frameworks-base | affected | Debian:12 | android-platform-frameworks-base | — |
| android-platform-frameworks-base | affected | Debian:13 | android-platform-frameworks-base | — |
| android-platform-frameworks-base | affected | Debian:14 | android-platform-frameworks-base | — |
In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2022-20011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20011
In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; ...
CVEs:CVE-2022-20101
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20101
In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0641901...
CVEs:CVE-2022-20098
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20098
In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2021-39738
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39738
CVEs:CVE-2022-20085
In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0630887...
CVEs:CVE-2022-20085
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.
CVEs:CVE-2022-28784
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-28784
CVEs:CVE-2022-20107
In subtitle service, there is a possible application crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330673; Issue ID:...
CVEs:CVE-2022-20107
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privile...
CVEs:CVE-2022-20114
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20114
CVEs:CVE-2022-20116
In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2022-20116
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ion, there is a possible use after free due to incorrect error handling. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366069; Issue ...
CVEs:CVE-2022-20111
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20111
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater.
CVEs:CVE-2022-0882
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| fuchsia | affected | — | — |
CVEs:CVE-2022-0882
CVEs:CVE-2021-39700
In the policies of adbd.te, there was a logic error which caused the CTS Listening Ports Test to report invalid results. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2021-39700
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20087
In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06477970; Issue ID: ...
CVEs:CVE-2022-20087
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20094
In imgsensor, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479763; I...
CVEs:CVE-2022-20094
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479763; Issu...
CVEs:CVE-2022-20095
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20095
CVEs:CVE-2022-20096
In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06419003; Issue ID: ...
CVEs:CVE-2022-20096
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21743
In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06371108; Issue ID: A...
CVEs:CVE-2022-21743
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20089
In aee driver, there is a possible memory corruption due to active debug code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06240397; Issue ID: ...
CVEs:CVE-2022-20089
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In aee daemon, there is a possible information disclosure due to improper access control. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS064...
CVEs:CVE-2022-20104
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20104
CVEs:CVE-2022-20092
In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS063660...
CVEs:CVE-2022-20092
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20088
In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0620920...
CVEs:CVE-2022-20088
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; ...
CVEs:CVE-2022-20099
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20099
In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS063999...
CVEs:CVE-2022-20109
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20109
ASB-A-223071150
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-223072269
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20102
In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0629644...
CVEs:CVE-2022-20102
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0638394...
CVEs:CVE-2022-20100
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20100
In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2022-20119
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20119
PUB-A-213170715
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package before completion of Setup wizard. The patch blocks entry point of the vulnerability.
CVEs:CVE-2022-28782
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-28782
CVEs:CVE-2022-20115
In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due to a missing permission check. This could lead to local information disclosure with User execution priv...
CVEs:CVE-2022-20115
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20084
In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2022-20084
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-20093
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20093
CVEs:CVE-2022-20121
In getNodeValue of USCCDMPlugin.java, there is a possible disclosure of ICCID due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2022-20121
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-223071148
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-212573046
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-28783
Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.
CVEs:CVE-2022-28783
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-28785
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
CVEs:CVE-2022-28785
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
CVEs:CVE-2022-28786
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-28786
CVEs:CVE-2022-28787
Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
CVEs:CVE-2022-28787
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
CVEs:CVE-2022-28788
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-28788
CVEs:CVE-2022-20112
In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileg...
CVEs:CVE-2022-20112
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.
CVEs:CVE-2022-28780
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-28780
CVEs:CVE-2022-20118
In ion_ioctl and related functions of ion.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2022-20118
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-205707793
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20090
In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209197; Issue ID: ALPS...
CVEs:CVE-2022-20090
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20091
In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS...
CVEs:CVE-2022-20091
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS...
CVEs:CVE-2022-20110
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20110
In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; ...
CVEs:CVE-2022-20097
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20097
CVEs:CVE-2022-20117
In (TBD) of (TBD), there is a possible way to decrypt local data encrypted by the GSC due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2022-20117
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-217475903
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
GHSA-gj46-mfx7-2vwx
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
| firefox | affected | wolfi | firefox | — |
| firefox | affected | chainguard | firefox | — |
GHSA-64x6-q8pq-xjmg
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
| firefox | affected | chainguard | firefox | — |
| firefox | affected | wolfi | firefox | — |
golang.org/x/net/html NULL Pointer Dereference vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/html NULL Pointer Dereference vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/html NULL Pointer Dereference vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/html NULL Pointer Dereference vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/html Improper Validation of Array Index vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/html Improper Validation of Array Index vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| hey | affected | wolfi | hey | — |
| hey | affected | chainguard | hey | — |
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
GHSA-g4fh-wrxx-g83w
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
| firefox | affected | chainguard | firefox | — |
| firefox | affected | wolfi | firefox | — |
Kubernetes arbitrary file overwrite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kubernetes arbitrary file overwrite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
GHSA-x23w-pq92-wqgx
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
GHSA-7w66-j2r2-vm3p
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-1.19 | affected | chainguard | kubernetes-1.19 | — |
| kubernetes-1.20 | affected | chainguard | kubernetes-1.20 | — |
| kubernetes-1.21 | affected | chainguard | kubernetes-1.21 | — |
| kubernetes-1.22 | affected | chainguard | kubernetes-1.22 | — |
| kubernetes-1.23 | affected | chainguard | kubernetes-1.23 | — |
| kubernetes-1.24 | affected | wolfi | kubernetes-1.24 | — |
| kubernetes-1.24 | affected | chainguard | kubernetes-1.24 | — |
| kubernetes-1.25 | affected | chainguard | kubernetes-1.25 | — |
| kubernetes-1.25 | affected | wolfi | kubernetes-1.25 | — |
| kubernetes-1.26 | affected | chainguard | kubernetes-1.26 | — |
| kubernetes-1.26 | affected | wolfi | kubernetes-1.26 | — |
| kubernetes-1.27 | affected | wolfi | kubernetes-1.27 | — |
| kubernetes-1.27 | affected | chainguard | kubernetes-1.27 | — |
| kubernetes-1.28 | affected | chainguard | kubernetes-1.28 | — |
| kubernetes-1.28 | affected | wolfi | kubernetes-1.28 | — |
| kubernetes-1.29 | affected | wolfi | kubernetes-1.29 | — |
| kubernetes-1.29 | affected | chainguard | kubernetes-1.29 | — |
| kubernetes-1.30 | affected | chainguard | kubernetes-1.30 | — |
| kubernetes-1.30 | affected | wolfi | kubernetes-1.30 | — |
| kubernetes-1.31 | affected | wolfi | kubernetes-1.31 | — |
| kubernetes-1.31 | affected | chainguard | kubernetes-1.31 | — |
| kubernetes-1.32 | affected | wolfi | kubernetes-1.32 | — |
| kubernetes-1.32 | affected | chainguard | kubernetes-1.32 | — |
Jenkins Google Login Plugin Session Fixation vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-login | affected | Maven | org.jenkins-ci.plugins:google-login | — |
Jenkins Google Login Plugin Session Fixation vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-login | affected | Maven | org.jenkins-ci.plugins:google-login | — |
Kubernetes in OpenShift3 Access Control Misconfiguration
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kubernetes in OpenShift3 Access Control Misconfiguration
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-1.19 | affected | chainguard | kubernetes-1.19 | — |
| kubernetes-1.20 | affected | chainguard | kubernetes-1.20 | — |
| kubernetes-1.21 | affected | chainguard | kubernetes-1.21 | — |
| kubernetes-1.22 | affected | chainguard | kubernetes-1.22 | — |
| kubernetes-1.23 | affected | chainguard | kubernetes-1.23 | — |
| kubernetes-1.24 | affected | chainguard | kubernetes-1.24 | — |
| kubernetes-1.24 | affected | wolfi | kubernetes-1.24 | — |
| kubernetes-1.25 | affected | wolfi | kubernetes-1.25 | — |
| kubernetes-1.25 | affected | chainguard | kubernetes-1.25 | — |
| kubernetes-1.26 | affected | wolfi | kubernetes-1.26 | — |
| kubernetes-1.26 | affected | chainguard | kubernetes-1.26 | — |
| kubernetes-1.27 | affected | chainguard | kubernetes-1.27 | — |
| kubernetes-1.27 | affected | wolfi | kubernetes-1.27 | — |
| kubernetes-1.28 | affected | chainguard | kubernetes-1.28 | — |
| kubernetes-1.28 | affected | wolfi | kubernetes-1.28 | — |
| kubernetes-1.29 | affected | wolfi | kubernetes-1.29 | — |
| kubernetes-1.29 | affected | chainguard | kubernetes-1.29 | — |
| kubernetes-1.30 | affected | chainguard | kubernetes-1.30 | — |
| kubernetes-1.30 | affected | wolfi | kubernetes-1.30 | — |
| kubernetes-1.31 | affected | wolfi | kubernetes-1.31 | — |
| kubernetes-1.31 | affected | chainguard | kubernetes-1.31 | — |
| kubernetes-1.32 | affected | wolfi | kubernetes-1.32 | — |
| kubernetes-1.32 | affected | chainguard | kubernetes-1.32 | — |
Exposure of Sensitive Information in Jenkins Kubernetes Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes | affected | Maven | org.csanchez.jenkins.plugins:kubernetes | — |
Exposure of Sensitive Information in Jenkins Kubernetes Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes | affected | Maven | org.csanchez.jenkins.plugins:kubernetes | — |
Man-in-the-middle attack with SessionTicketsDisabled in crypto/tls
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
OWASP HTML Sanitizer allows redirecting to an arbitrary URL when JavaScript is disabled
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer | affected | Maven | com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer | — |
OWASP HTML Sanitizer allows redirecting to an arbitrary URL when JavaScript is disabled
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer | affected | Maven | com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer | — |
Jerome Gamez Firebase Admin SDK for PHP Incorrect Access Control vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firebase-php | affected | kreait | kreait/firebase-php | — |
| firebase-php | affected | kreait | kreait/firebase-php | — |
Jerome Gamez Firebase Admin SDK for PHP Incorrect Access Control vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firebase-php | affected | kreait | kreait/firebase-php | — |
Mishandled trust preferences for root certificates on Darwin in crypto/x509
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
Exposure of Sensitive Information in Jenkins Kubernetes Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes | affected | Maven | org.csanchez.jenkins.plugins:kubernetes | — |
Exposure of Sensitive Information in Jenkins Kubernetes Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.csanchez.jenkins.plugins:kubernetes | affected | Maven | org.csanchez.jenkins.plugins:kubernetes | — |
GHSA-7wj7-vv48-8jpg
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
Kubernetes ingress exposes sensitive information
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ingress-nginx | affected | k8s.io | k8s.io/ingress-nginx | — |
Kubernetes ingress exposes sensitive information
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ingress-nginx | affected | k8s.io | k8s.io/ingress-nginx | — |
| ingress-nginx-controller | affected | wolfi | ingress-nginx-controller | — |
| ingress-nginx-controller | affected | chainguard | ingress-nginx-controller | — |
| ingress-nginx-controller-1.9 | affected | chainguard | ingress-nginx-controller-1.9 | — |
| ingress-nginx-controller-fips | affected | chainguard | ingress-nginx-controller-fips | — |
| ingress-nginx-controller-fips-1.9 | affected | chainguard | ingress-nginx-controller-fips-1.9 | — |
Auth0 angular-jwt misinterprets allowlist as regex
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-jwt | affected | npm | angular-jwt | — |
Auth0 angular-jwt misinterprets allowlist as regex
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-jwt | affected | npm | angular-jwt | — |
Jenkins Google Login Plugin Open Redirect vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-login | affected | Maven | org.jenkins-ci.plugins:google-login | — |
Jenkins Google Login Plugin Open Redirect vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-login | affected | Maven | org.jenkins-ci.plugins:google-login | — |
Angular Redactor XSS Vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-redactor | affected | npm | angular-redactor | — |
Angular Redactor XSS Vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-redactor | affected | npm | angular-redactor | — |
Cross-site Scripting in wicket-jquery-ui
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent | affected | Maven | com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent | — |
Cross-site Scripting in wicket-jquery-ui
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent | affected | Maven | com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent | — |
XXE vulnerability in Jenkins Android Lint Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jvnet.hudson.plugins:android-lint | affected | Maven | org.jvnet.hudson.plugins:android-lint | — |
XXE vulnerability in Jenkins Android Lint Plugin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jvnet.hudson.plugins:android-lint | affected | Maven | org.jvnet.hudson.plugins:android-lint | — |
Cross-site Scripting in wicket-jquery-ui
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent | affected | Maven | com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent | — |
Cross-site Scripting in wicket-jquery-ui
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent | affected | Maven | com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent | — |
GHSA-h5rj-jwq2-3jp4
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
Minikube RCE via DNS Rebinding
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| minikube | affected | k8s.io | k8s.io/minikube | — |
Minikube RCE via DNS Rebinding
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| minikube | affected | k8s.io | k8s.io/minikube | — |
Jenkins Google Play Android Publisher Plugin allows attacker to obtain credential IDs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-play-android-publisher | affected | Maven | org.jenkins-ci.plugins:google-play-android-publisher | — |
Jenkins Google Play Android Publisher Plugin allows attacker to obtain credential IDs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-play-android-publisher | affected | Maven | org.jenkins-ci.plugins:google-play-android-publisher | — |
GHSA-h6cr-c397-vq66
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
GHSA-8ph5-wgc5-5jj9
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
| firefox | affected | chainguard | firefox | — |
| firefox | affected | wolfi | firefox | — |
GHSA-fm24-8vcm-jw5m
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
`CHECK` failure in depthwise ops via overflows
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
`CHECK` failure in depthwise ops via overflows
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
llvm-toolset:rhel8 bug fix and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| clang | affected | AlmaLinux:8 | clang | — |
| clang-analyzer | affected | AlmaLinux:8 | clang-analyzer | — |
| clang-devel | affected | AlmaLinux:8 | clang-devel | — |
| clang-libs | affected | AlmaLinux:8 | clang-libs | — |
| clang-resource-filesystem | affected | AlmaLinux:8 | clang-resource-filesystem | — |
| clang-tools-extra | affected | AlmaLinux:8 | clang-tools-extra | — |
| compiler-rt | affected | AlmaLinux:8 | compiler-rt | — |
| git-clang-format | affected | AlmaLinux:8 | git-clang-format | — |
| libomp | affected | AlmaLinux:8 | libomp | — |
| libomp-devel | affected | AlmaLinux:8 | libomp-devel | — |
| libomp-test | affected | AlmaLinux:8 | libomp-test | — |
| lld | affected | AlmaLinux:8 | lld | — |
| lldb | affected | AlmaLinux:8 | lldb | — |
| lldb-devel | affected | AlmaLinux:8 | lldb-devel | — |
| lld-devel | affected | AlmaLinux:8 | lld-devel | — |
| lld-libs | affected | AlmaLinux:8 | lld-libs | — |
| llvm | affected | AlmaLinux:8 | llvm | — |
| llvm-devel | affected | AlmaLinux:8 | llvm-devel | — |
| llvm-doc | affected | AlmaLinux:8 | llvm-doc | — |
| llvm-googletest | affected | AlmaLinux:8 | llvm-googletest | — |
| llvm-libs | affected | AlmaLinux:8 | llvm-libs | — |
| llvm-static | affected | AlmaLinux:8 | llvm-static | — |
| llvm-test | affected | AlmaLinux:8 | llvm-test | — |
| llvm-toolset | affected | AlmaLinux:8 | llvm-toolset | — |
| python3-clang | affected | AlmaLinux:8 | python3-clang | — |
| python3-lit | affected | AlmaLinux:8 | python3-lit | — |
| python3-lldb | affected | AlmaLinux:8 | python3-lldb | — |
rsyslog bug fix and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rsyslog | affected | AlmaLinux:8 | rsyslog | — |
| rsyslog-crypto | affected | AlmaLinux:8 | rsyslog-crypto | — |
| rsyslog-doc | affected | AlmaLinux:8 | rsyslog-doc | — |
| rsyslog-elasticsearch | affected | AlmaLinux:8 | rsyslog-elasticsearch | — |
| rsyslog-gnutls | affected | AlmaLinux:8 | rsyslog-gnutls | — |
| rsyslog-gssapi | affected | AlmaLinux:8 | rsyslog-gssapi | — |
| rsyslog-kafka | affected | AlmaLinux:8 | rsyslog-kafka | — |
| rsyslog-mmaudit | affected | AlmaLinux:8 | rsyslog-mmaudit | — |
| rsyslog-mmfields | affected | AlmaLinux:8 | rsyslog-mmfields | — |
| rsyslog-mmjsonparse | affected | AlmaLinux:8 | rsyslog-mmjsonparse | — |
| rsyslog-mmkubernetes | affected | AlmaLinux:8 | rsyslog-mmkubernetes | — |
| rsyslog-mmnormalize | affected | AlmaLinux:8 | rsyslog-mmnormalize | — |
| rsyslog-mmsnmptrapd | affected | AlmaLinux:8 | rsyslog-mmsnmptrapd | — |
| rsyslog-mysql | affected | AlmaLinux:8 | rsyslog-mysql | — |
| rsyslog-omamqp1 | affected | AlmaLinux:8 | rsyslog-omamqp1 | — |
| rsyslog-openssl | affected | AlmaLinux:8 | rsyslog-openssl | — |
| rsyslog-pgsql | affected | AlmaLinux:8 | rsyslog-pgsql | — |
| rsyslog-relp | affected | AlmaLinux:8 | rsyslog-relp | — |
| rsyslog-snmp | affected | AlmaLinux:8 | rsyslog-snmp | — |
| rsyslog-udpspoof | affected | AlmaLinux:8 | rsyslog-udpspoof | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.