Google Security Advisories · May 2022 — Google Security Advisories
546 advisories 302 CVEs 8 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2022-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 8 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2022-30190

GoogleExploitedCISA KEV listedHIGH2022-05-10

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling applicat...

CVEs:CVE-2022-30190

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_10_21h2 affected microsoft
windows_11_21h2 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

ASB-A-220741611

GoogleExploitedCISA KEV listedHIGH2022-05-01

ASB-A-220741611

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-26925

GoogleExploitedCISA KEV listedHIGH2022-05-10

Windows LSA Spoofing Vulnerability

CVEs:CVE-2022-26925

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_1909 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_10_21h2 affected microsoft
windows_11_21h2 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_20h2 affected microsoft
Upstream advisory

ASB-A-213464034

GoogleExploitedCISA KEV listedHIGH2022-05-01

ASB-A-213464034

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

GHSA-v98w-p8f7-9qqf

Open SourceWeaponized exploitLOW2022-05-13

GHSA-v98w-p8f7-9qqf

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
firefox affected wolfi firefox
firefox affected chainguard firefox
Upstream advisory

GHSA-rhch-pcq2-7gp3

Open SourceWeaponized exploitNONE2022-05-13

GHSA-rhch-pcq2-7gp3

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
firefox affected chainguard firefox
firefox affected wolfi firefox
openjdk-11-openj9 affected chainguard openjdk-11-openj9
openjdk-17-openj9 affected chainguard openjdk-17-openj9
openjdk-21-openj9 affected chainguard openjdk-21-openj9
openjdk-25-openj9 affected chainguard openjdk-25-openj9
openjdk-26-openj9 affected chainguard openjdk-26-openj9
openjdk-8-openj9 affected chainguard openjdk-8-openj9
Upstream advisory

GHSA-x534-j49x-mqvj

Open SourceWeaponized exploitCRITICAL2022-05-24

android-gif-drawable Double Free vulnerability

Affected products

ProductStatusVendorPackageEcosystem
pl.droidsonroids.gif:android-gif-drawable affected Maven pl.droidsonroids.gif:android-gif-drawable
Upstream advisory

GHSA-x534-j49x-mqvj

Open SourceWeaponized exploitCRITICAL2022-05-24

android-gif-drawable Double Free vulnerability

Affected products

ProductStatusVendorPackageEcosystem
pl.droidsonroids.gif:android-gif-drawable affected Maven pl.droidsonroids.gif:android-gif-drawable
Upstream advisory

GHSA-348j-44v2-vwfr

Open SourceWeaponized exploit2022-05-14

GHSA-348j-44v2-vwfr

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
firefox affected wolfi firefox
firefox affected chainguard firefox
Upstream advisory

GO-2022-0213

Open SourceActive exploitation (sightings)HIGH2022-05-24

Panic on invalid DSA public keys in crypto/dsa

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

openSUSE-SU-2022:0125-1

Open SourceActive exploitation (sightings)CRITICAL2022-05-06

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

MGASA-2022-0158

Open SourceActive exploitation (sightings)CRITICAL2022-05-02

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

CVE-2021-22573

GoogleActive exploitation (sightings)HIGH2022-05-03

google-oauth-java-client improperly verifies cryptographic signature

CVEs:CVE-2021-22573

Affected products

ProductStatusVendorPackageEcosystem
com.google.oauth-client:google-oauth-client affected Maven com.google.oauth-client:google-oauth-client
Upstream advisory

DEBIAN-CVE-2021-22573

GoogleActive exploitation (sightings)HIGH2022-05-03

DEBIAN-CVE-2021-22573

Affected products

ProductStatusVendorPackageEcosystem
google-oauth-client-java affected Debian:11 google-oauth-client-java
google-oauth-client-java affected Debian:12 google-oauth-client-java
google-oauth-client-java affected Debian:13 google-oauth-client-java
google-oauth-client-java affected Debian:14 google-oauth-client-java
Upstream advisory

CVE-2021-22573

GoogleActive exploitation (sightings)HIGH2022-05-03

The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An attacker can provide a compromised token with custom...

CVEs:CVE-2021-22573

Affected products

ProductStatusVendorPackageEcosystem
oauth_client_library_for_java affected google
Upstream advisory

GHSA-39qc-96h7-956f

Open SourcePoC exploitHIGH2022-05-24

golang.org/x/net/http vulnerable to a reset flood

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-39qc-96h7-956f

Open SourcePoC exploitHIGH2022-05-24

golang.org/x/net/http vulnerable to a reset flood

Affected products

ProductStatusVendorPackageEcosystem
hey affected wolfi hey
hey affected chainguard hey
k3d affected chainguard k3d
k3d affected wolfi k3d
x/net affected golang.org golang.org/x/net
x/net affected golang.org
Upstream advisory

GHSA-hgr8-6h9x-f7q9

Open SourcePoC exploitHIGH2022-05-24

golang.org/x/net/http vulnerable to ping floods

Affected products

ProductStatusVendorPackageEcosystem
hey affected wolfi hey
hey affected chainguard hey
k3d affected chainguard k3d
k3d affected wolfi k3d
x/net affected golang.org
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-hgr8-6h9x-f7q9

Open SourcePoC exploitHIGH2022-05-24

golang.org/x/net/http vulnerable to ping floods

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

OESA-2022-1663

GooglePoC exploitCRITICAL2022-05-20

google-gson security update

Affected products

ProductStatusVendorPackageEcosystem
google-gson affected openEuler:20.03-LTS-SP1 google-gson
google-gson affected openEuler:20.03-LTS-SP3 google-gson
google-gson affected openEuler:22.03-LTS google-gson
Upstream advisory

DLA-3001-1

GooglePoC exploit2022-05-13

libgoogle-gson-java - security update

Affected products

ProductStatusVendorPackageEcosystem
libgoogle-gson-java affected Debian:9 libgoogle-gson-java
Upstream advisory

GHSA-4jrv-ppp4-jm57

GooglePoC exploitHIGH2022-05-03

Deserialization of Untrusted Data in Gson

Affected products

ProductStatusVendorPackageEcosystem
com.google.code.gson:gson affected Maven com.google.code.gson:gson
com.google.code.gson:gson affected Maven
trino affected chainguard trino
trino affected wolfi trino
Upstream advisory

GHSA-4jrv-ppp4-jm57

GooglePoC exploitHIGH2022-05-03

Deserialization of Untrusted Data in Gson

Affected products

ProductStatusVendorPackageEcosystem
com.google.code.gson:gson affected Maven com.google.code.gson:gson
Upstream advisory

DEBIAN-CVE-2022-25647

GooglePoC exploitHIGH2022-05-01

DEBIAN-CVE-2022-25647

Affected products

ProductStatusVendorPackageEcosystem
libgoogle-gson-java affected Debian:11 libgoogle-gson-java
libgoogle-gson-java affected Debian:12 libgoogle-gson-java
libgoogle-gson-java affected Debian:13 libgoogle-gson-java
libgoogle-gson-java affected Debian:14 libgoogle-gson-java
Upstream advisory

CVE-2022-25647

GooglePoC exploitHIGH2022-05-01

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVEs:CVE-2022-25647

Affected products

ProductStatusVendorPackageEcosystem
active_iq_unified_manager affected netapp
debian_linux affected debian
financial_services_crime_and_compliance_management_studio affected oracle
graalvm affected oracle
gson affected google
gson affected google
retail_order_broker affected oracle
Upstream advisory

CVE-2022-25647

GooglePoC exploitHIGH2022-05-01

Deserialization of Untrusted Data in Gson

CVEs:CVE-2022-25647

Affected products

ProductStatusVendorPackageEcosystem
com.google.code.gson:gson affected Maven com.google.code.gson:gson
Upstream advisory

RHSA-2022:1819

Open SourcePoC exploitCRITICAL2022-05-10

Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

ALSA-2022:1819

Open SourcePoC exploitHIGH2022-05-10

Moderate: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected AlmaLinux:8 delve
golang affected AlmaLinux:8 golang
golang-bin affected AlmaLinux:8 golang-bin
golang-docs affected AlmaLinux:8 golang-docs
golang-misc affected AlmaLinux:8 golang-misc
golang-race affected AlmaLinux:8 golang-race
golang-src affected AlmaLinux:8 golang-src
golang-tests affected AlmaLinux:8 golang-tests
go-toolset affected AlmaLinux:8 go-toolset
Upstream advisory

RLSA-2022:1819

Open SourcePoC exploitCRITICAL2022-05-10

Moderate: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

GHSA-q4rr-64r9-fwgf

Open SourcePoC exploitCRITICAL2022-05-13

Kubernetes DoS Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-q4rr-64r9-fwgf

Open SourcePoC exploitCRITICAL2022-05-13

Kubernetes DoS Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GO-2022-0433

Open SourcePoC exploitCRITICAL2022-05-20

Stack overflow from a large amount of PEM data in encoding/pem

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

OESA-2022-1661

Open SourcePoC exploitCRITICAL2022-05-20

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP3 golang
golang affected openEuler:22.03-LTS golang
Upstream advisory

MGASA-2022-0171

Open SourcePoC exploitCRITICAL2022-05-12

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

RHSA-2022:1861

GooglePoC exploitMEDIUM2022-05-10

Red Hat Security Advisory: maven:3.5 security update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected Red Hat:enterprise_linux:8::appstream aopalliance
apache-commons-cli affected Red Hat:enterprise_linux:8::appstream apache-commons-cli
apache-commons-codec affected Red Hat:enterprise_linux:8::appstream apache-commons-codec
apache-commons-io affected Red Hat:enterprise_linux:8::appstream apache-commons-io
apache-commons-lang3 affected Red Hat:enterprise_linux:8::appstream apache-commons-lang3
apache-commons-logging affected Red Hat:enterprise_linux:8::appstream apache-commons-logging
atinject affected Red Hat:enterprise_linux:8::appstream atinject
cdi-api affected Red Hat:enterprise_linux:8::appstream cdi-api
geronimo-annotation affected Red Hat:enterprise_linux:8::appstream geronimo-annotation
glassfish-el affected Red Hat:enterprise_linux:8::appstream glassfish-el
glassfish-el-api affected Red Hat:enterprise_linux:8::appstream glassfish-el-api
google-guice affected Red Hat:enterprise_linux:8::appstream google-guice
guava20 affected Red Hat:enterprise_linux:8::appstream guava20
hawtjni affected Red Hat:enterprise_linux:8::appstream hawtjni
hawtjni-runtime affected Red Hat:enterprise_linux:8::appstream hawtjni-runtime
httpcomponents-client affected Red Hat:enterprise_linux:8::appstream httpcomponents-client
httpcomponents-core affected Red Hat:enterprise_linux:8::appstream httpcomponents-core
jansi affected Red Hat:enterprise_linux:8::appstream jansi
jansi-native affected Red Hat:enterprise_linux:8::appstream jansi-native
jboss-interceptors-1.2-api affected Red Hat:enterprise_linux:8::appstream jboss-interceptors-1.2-api
jcl-over-slf4j affected Red Hat:enterprise_linux:8::appstream jcl-over-slf4j
jsoup affected Red Hat:enterprise_linux:8::appstream jsoup
maven affected Red Hat:enterprise_linux:8::appstream maven
maven-lib affected Red Hat:enterprise_linux:8::appstream maven-lib
maven-resolver affected Red Hat:enterprise_linux:8::appstream maven-resolver
maven-resolver-api affected Red Hat:enterprise_linux:8::appstream maven-resolver-api
maven-resolver-connector-basic affected Red Hat:enterprise_linux:8::appstream maven-resolver-connector-basic
maven-resolver-impl affected Red Hat:enterprise_linux:8::appstream maven-resolver-impl
maven-resolver-spi affected Red Hat:enterprise_linux:8::appstream maven-resolver-spi
maven-resolver-transport-wagon affected Red Hat:enterprise_linux:8::appstream maven-resolver-transport-wagon
maven-resolver-util affected Red Hat:enterprise_linux:8::appstream maven-resolver-util
maven-shared-utils affected Red Hat:enterprise_linux:8::appstream maven-shared-utils
maven-wagon affected Red Hat:enterprise_linux:8::appstream maven-wagon
maven-wagon-file affected Red Hat:enterprise_linux:8::appstream maven-wagon-file
maven-wagon-http affected Red Hat:enterprise_linux:8::appstream maven-wagon-http
maven-wagon-http-shared affected Red Hat:enterprise_linux:8::appstream maven-wagon-http-shared
maven-wagon-provider-api affected Red Hat:enterprise_linux:8::appstream maven-wagon-provider-api
plexus-cipher affected Red Hat:enterprise_linux:8::appstream plexus-cipher
plexus-classworlds affected Red Hat:enterprise_linux:8::appstream plexus-classworlds
plexus-containers affected Red Hat:enterprise_linux:8::appstream plexus-containers
plexus-containers-component-annotations affected Red Hat:enterprise_linux:8::appstream plexus-containers-component-annotations
plexus-interpolation affected Red Hat:enterprise_linux:8::appstream plexus-interpolation
plexus-sec-dispatcher affected Red Hat:enterprise_linux:8::appstream plexus-sec-dispatcher
plexus-utils affected Red Hat:enterprise_linux:8::appstream plexus-utils
sisu affected Red Hat:enterprise_linux:8::appstream sisu
sisu-inject affected Red Hat:enterprise_linux:8::appstream sisu-inject
sisu-plexus affected Red Hat:enterprise_linux:8::appstream sisu-plexus
slf4j affected Red Hat:enterprise_linux:8::appstream slf4j
Upstream advisory

RHSA-2022:1860

GooglePoC exploitMEDIUM2022-05-10

Red Hat Security Advisory: maven:3.6 security and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected Red Hat:enterprise_linux:8::appstream aopalliance
apache-commons-cli affected Red Hat:enterprise_linux:8::appstream apache-commons-cli
apache-commons-codec affected Red Hat:enterprise_linux:8::appstream apache-commons-codec
apache-commons-io affected Red Hat:enterprise_linux:8::appstream apache-commons-io
apache-commons-lang3 affected Red Hat:enterprise_linux:8::appstream apache-commons-lang3
atinject affected Red Hat:enterprise_linux:8::appstream atinject
cdi-api affected Red Hat:enterprise_linux:8::appstream cdi-api
geronimo-annotation affected Red Hat:enterprise_linux:8::appstream geronimo-annotation
google-guice affected Red Hat:enterprise_linux:8::appstream google-guice
guava affected Red Hat:enterprise_linux:8::appstream guava
httpcomponents-client affected Red Hat:enterprise_linux:8::appstream httpcomponents-client
httpcomponents-core affected Red Hat:enterprise_linux:8::appstream httpcomponents-core
jansi affected Red Hat:enterprise_linux:8::appstream jansi
jcl-over-slf4j affected Red Hat:enterprise_linux:8::appstream jcl-over-slf4j
jsoup affected Red Hat:enterprise_linux:8::appstream jsoup
jsr-305 affected Red Hat:enterprise_linux:8::appstream jsr-305
maven affected Red Hat:enterprise_linux:8::appstream maven
maven-lib affected Red Hat:enterprise_linux:8::appstream maven-lib
maven-openjdk11 affected Red Hat:enterprise_linux:8::appstream maven-openjdk11
maven-openjdk17 affected Red Hat:enterprise_linux:8::appstream maven-openjdk17
maven-openjdk8 affected Red Hat:enterprise_linux:8::appstream maven-openjdk8
maven-resolver affected Red Hat:enterprise_linux:8::appstream maven-resolver
maven-shared-utils affected Red Hat:enterprise_linux:8::appstream maven-shared-utils
maven-wagon affected Red Hat:enterprise_linux:8::appstream maven-wagon
plexus-cipher affected Red Hat:enterprise_linux:8::appstream plexus-cipher
plexus-classworlds affected Red Hat:enterprise_linux:8::appstream plexus-classworlds
plexus-containers affected Red Hat:enterprise_linux:8::appstream plexus-containers
plexus-containers-component-annotations affected Red Hat:enterprise_linux:8::appstream plexus-containers-component-annotations
plexus-interpolation affected Red Hat:enterprise_linux:8::appstream plexus-interpolation
plexus-sec-dispatcher affected Red Hat:enterprise_linux:8::appstream plexus-sec-dispatcher
plexus-utils affected Red Hat:enterprise_linux:8::appstream plexus-utils
sisu affected Red Hat:enterprise_linux:8::appstream sisu
slf4j affected Red Hat:enterprise_linux:8::appstream slf4j
Upstream advisory

ALSA-2022:1861

GooglePoC exploitHIGH2022-05-10

Moderate: maven:3.5 security update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected AlmaLinux:8 aopalliance
apache-commons-cli affected AlmaLinux:8 apache-commons-cli
apache-commons-codec affected AlmaLinux:8 apache-commons-codec
apache-commons-io affected AlmaLinux:8 apache-commons-io
apache-commons-lang3 affected AlmaLinux:8 apache-commons-lang3
apache-commons-logging affected AlmaLinux:8 apache-commons-logging
atinject affected AlmaLinux:8 atinject
cdi-api affected AlmaLinux:8 cdi-api
geronimo-annotation affected AlmaLinux:8 geronimo-annotation
glassfish-el-api affected AlmaLinux:8 glassfish-el-api
google-guice affected AlmaLinux:8 google-guice
guava20 affected AlmaLinux:8 guava20
hawtjni-runtime affected AlmaLinux:8 hawtjni-runtime
httpcomponents-client affected AlmaLinux:8 httpcomponents-client
httpcomponents-core affected AlmaLinux:8 httpcomponents-core
jansi affected AlmaLinux:8 jansi
jansi-native affected AlmaLinux:8 jansi-native
jboss-interceptors-1.2-api affected AlmaLinux:8 jboss-interceptors-1.2-api
jcl-over-slf4j affected AlmaLinux:8 jcl-over-slf4j
jsoup affected AlmaLinux:8 jsoup
maven affected AlmaLinux:8 maven
maven-lib affected AlmaLinux:8 maven-lib
maven-resolver-api affected AlmaLinux:8 maven-resolver-api
maven-resolver-connector-basic affected AlmaLinux:8 maven-resolver-connector-basic
maven-resolver-impl affected AlmaLinux:8 maven-resolver-impl
maven-resolver-spi affected AlmaLinux:8 maven-resolver-spi
maven-resolver-transport-wagon affected AlmaLinux:8 maven-resolver-transport-wagon
maven-resolver-util affected AlmaLinux:8 maven-resolver-util
maven-shared-utils affected AlmaLinux:8 maven-shared-utils
maven-wagon-file affected AlmaLinux:8 maven-wagon-file
maven-wagon-http affected AlmaLinux:8 maven-wagon-http
maven-wagon-http-shared affected AlmaLinux:8 maven-wagon-http-shared
maven-wagon-provider-api affected AlmaLinux:8 maven-wagon-provider-api
plexus-cipher affected AlmaLinux:8 plexus-cipher
plexus-classworlds affected AlmaLinux:8 plexus-classworlds
plexus-containers-component-annotations affected AlmaLinux:8 plexus-containers-component-annotations
plexus-interpolation affected AlmaLinux:8 plexus-interpolation
plexus-sec-dispatcher affected AlmaLinux:8 plexus-sec-dispatcher
plexus-utils affected AlmaLinux:8 plexus-utils
sisu-inject affected AlmaLinux:8 sisu-inject
sisu-plexus affected AlmaLinux:8 sisu-plexus
slf4j affected AlmaLinux:8 slf4j
Upstream advisory

RLSA-2022:1861

GooglePoC exploitHIGH2022-05-10

Moderate: maven:3.5 security update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected Rocky Linux:8 aopalliance
apache-commons-cli affected Rocky Linux:8 apache-commons-cli
apache-commons-codec affected Rocky Linux:8 apache-commons-codec
apache-commons-io affected Rocky Linux:8 apache-commons-io
apache-commons-lang3 affected Rocky Linux:8 apache-commons-lang3
apache-commons-logging affected Rocky Linux:8 apache-commons-logging
atinject affected Rocky Linux:8 atinject
cdi-api affected Rocky Linux:8 cdi-api
geronimo-annotation affected Rocky Linux:8 geronimo-annotation
glassfish-el affected Rocky Linux:8 glassfish-el
google-guice affected Rocky Linux:8 google-guice
guava20 affected Rocky Linux:8 guava20
hawtjni affected Rocky Linux:8 hawtjni
httpcomponents-client affected Rocky Linux:8 httpcomponents-client
httpcomponents-core affected Rocky Linux:8 httpcomponents-core
jansi affected Rocky Linux:8 jansi
jansi-native affected Rocky Linux:8 jansi-native
jboss-interceptors-1.2-api affected Rocky Linux:8 jboss-interceptors-1.2-api
jsoup affected Rocky Linux:8 jsoup
maven affected Rocky Linux:8 maven
maven-resolver affected Rocky Linux:8 maven-resolver
maven-shared-utils affected Rocky Linux:8 maven-shared-utils
maven-wagon affected Rocky Linux:8 maven-wagon
plexus-cipher affected Rocky Linux:8 plexus-cipher
plexus-classworlds affected Rocky Linux:8 plexus-classworlds
plexus-containers affected Rocky Linux:8 plexus-containers
plexus-interpolation affected Rocky Linux:8 plexus-interpolation
plexus-sec-dispatcher affected Rocky Linux:8 plexus-sec-dispatcher
plexus-utils affected Rocky Linux:8 plexus-utils
sisu affected Rocky Linux:8 sisu
slf4j affected Rocky Linux:8 slf4j
Upstream advisory

ALSA-2022:1860

GooglePoC exploitHIGH2022-05-10

Moderate: maven:3.6 security and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected AlmaLinux:8 aopalliance
apache-commons-cli affected AlmaLinux:8 apache-commons-cli
apache-commons-codec affected AlmaLinux:8 apache-commons-codec
apache-commons-io affected AlmaLinux:8 apache-commons-io
apache-commons-lang3 affected AlmaLinux:8 apache-commons-lang3
atinject affected AlmaLinux:8 atinject
cdi-api affected AlmaLinux:8 cdi-api
geronimo-annotation affected AlmaLinux:8 geronimo-annotation
google-guice affected AlmaLinux:8 google-guice
guava affected AlmaLinux:8 guava
httpcomponents-client affected AlmaLinux:8 httpcomponents-client
httpcomponents-core affected AlmaLinux:8 httpcomponents-core
jansi affected AlmaLinux:8 jansi
jcl-over-slf4j affected AlmaLinux:8 jcl-over-slf4j
jsoup affected AlmaLinux:8 jsoup
jsr-305 affected AlmaLinux:8 jsr-305
maven affected AlmaLinux:8 maven
maven-lib affected AlmaLinux:8 maven-lib
maven-openjdk11 affected AlmaLinux:8 maven-openjdk11
maven-openjdk17 affected AlmaLinux:8 maven-openjdk17
maven-openjdk8 affected AlmaLinux:8 maven-openjdk8
maven-resolver affected AlmaLinux:8 maven-resolver
maven-shared-utils affected AlmaLinux:8 maven-shared-utils
maven-wagon affected AlmaLinux:8 maven-wagon
plexus-cipher affected AlmaLinux:8 plexus-cipher
plexus-classworlds affected AlmaLinux:8 plexus-classworlds
plexus-containers-component-annotations affected AlmaLinux:8 plexus-containers-component-annotations
plexus-interpolation affected AlmaLinux:8 plexus-interpolation
plexus-sec-dispatcher affected AlmaLinux:8 plexus-sec-dispatcher
plexus-utils affected AlmaLinux:8 plexus-utils
sisu affected AlmaLinux:8 sisu
slf4j affected AlmaLinux:8 slf4j
Upstream advisory

RLSA-2022:1860

GooglePoC exploitHIGH2022-05-10

Moderate: maven:3.6 security and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected Rocky Linux:8 aopalliance
apache-commons-cli affected Rocky Linux:8 apache-commons-cli
apache-commons-codec affected Rocky Linux:8 apache-commons-codec
apache-commons-io affected Rocky Linux:8 apache-commons-io
apache-commons-lang3 affected Rocky Linux:8 apache-commons-lang3
atinject affected Rocky Linux:8 atinject
cdi-api affected Rocky Linux:8 cdi-api
geronimo-annotation affected Rocky Linux:8 geronimo-annotation
google-guice affected Rocky Linux:8 google-guice
guava affected Rocky Linux:8 guava
httpcomponents-client affected Rocky Linux:8 httpcomponents-client
httpcomponents-core affected Rocky Linux:8 httpcomponents-core
jansi affected Rocky Linux:8 jansi
jsoup affected Rocky Linux:8 jsoup
jsr-305 affected Rocky Linux:8 jsr-305
maven affected Rocky Linux:8 maven
maven-resolver affected Rocky Linux:8 maven-resolver
maven-shared-utils affected Rocky Linux:8 maven-shared-utils
maven-wagon affected Rocky Linux:8 maven-wagon
plexus-cipher affected Rocky Linux:8 plexus-cipher
plexus-classworlds affected Rocky Linux:8 plexus-classworlds
plexus-containers affected Rocky Linux:8 plexus-containers
plexus-interpolation affected Rocky Linux:8 plexus-interpolation
plexus-sec-dispatcher affected Rocky Linux:8 plexus-sec-dispatcher
plexus-utils affected Rocky Linux:8 plexus-utils
sisu affected Rocky Linux:8 sisu
slf4j affected Rocky Linux:8 slf4j
Upstream advisory

GHSA-83g2-8m93-v3w7

Open SourcePoC exploitHIGH2022-05-24

golang.org/x/net/html Infinite Loop vulnerability

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-83g2-8m93-v3w7

Open SourcePoC exploitHIGH2022-05-24

golang.org/x/net/html Infinite Loop vulnerability

Affected products

ProductStatusVendorPackageEcosystem
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
hey affected wolfi hey
hey affected chainguard hey
k3d affected wolfi k3d
k3d affected chainguard k3d
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
x/net affected golang.org golang.org/x/net
x/net affected golang.org
Upstream advisory

GO-2022-0273

Open SourcePoC exploit2022-05-18

Panic due to crafted inputs in archive/zip

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

MGASA-2022-0180

Open SourcePoC exploitHIGH2022-05-15

Updated golang-github-prometheus-client packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-client affected Mageia:8 golang-github-prometheus-client
Upstream advisory

GO-2022-0212

Open SourcePoC exploit2022-05-23

Request smuggling due to accepting invalid headers in net/http via net/textproto

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GHSA-jwvw-v7c5-m82h

Open SourcePoC exploitHIGH2022-05-13

protobuf susceptible to buffer overflow

Affected products

ProductStatusVendorPackageEcosystem
com.google.protobuf:protobuf-parent affected Maven com.google.protobuf:protobuf-parent
Google.Protobuf affected NuGet Google.Protobuf
Google.Protobuf affected NuGet Google.Protobuf
protobuf affected google google/protobuf
protobuf affected google google/protobuf
protobuf affected PyPI protobuf
protocolbuffers/protobuf affected github.com github.com/protocolbuffers/protobuf
Upstream advisory

GHSA-gx69-6cp4-hxrj

Open SourcePoC exploitHIGH2022-05-13

RubyGems Link Following vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-gx69-6cp4-hxrj

Open SourcePoC exploitHIGH2022-05-13

RubyGems Link Following vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-74pv-v9gh-h25p

Open SourcePoC exploitHIGH2022-05-13

RubyGems Infinite Loop vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-74pv-v9gh-h25p

Open SourcePoC exploitHIGH2022-05-13

RubyGems Infinite Loop vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GO-2022-0166

Open SourcePoC exploitHIGH2022-05-24

Denial of service due to unchecked parameters in crypto/dsa

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

ALSA-2022:4799

Open SourcePoC exploit2022-05-30

Important: rsyslog security update

Affected products

ProductStatusVendorPackageEcosystem
rsyslog affected AlmaLinux:8 rsyslog
rsyslog-crypto affected AlmaLinux:8 rsyslog-crypto
rsyslog-doc affected AlmaLinux:8 rsyslog-doc
rsyslog-elasticsearch affected AlmaLinux:8 rsyslog-elasticsearch
rsyslog-gnutls affected AlmaLinux:8 rsyslog-gnutls
rsyslog-gssapi affected AlmaLinux:8 rsyslog-gssapi
rsyslog-kafka affected AlmaLinux:8 rsyslog-kafka
rsyslog-mmaudit affected AlmaLinux:8 rsyslog-mmaudit
rsyslog-mmfields affected AlmaLinux:8 rsyslog-mmfields
rsyslog-mmjsonparse affected AlmaLinux:8 rsyslog-mmjsonparse
rsyslog-mmkubernetes affected AlmaLinux:8 rsyslog-mmkubernetes
rsyslog-mmnormalize affected AlmaLinux:8 rsyslog-mmnormalize
rsyslog-mmsnmptrapd affected AlmaLinux:8 rsyslog-mmsnmptrapd
rsyslog-mysql affected AlmaLinux:8 rsyslog-mysql
rsyslog-omamqp1 affected AlmaLinux:8 rsyslog-omamqp1
rsyslog-openssl affected AlmaLinux:8 rsyslog-openssl
rsyslog-pgsql affected AlmaLinux:8 rsyslog-pgsql
rsyslog-relp affected AlmaLinux:8 rsyslog-relp
rsyslog-snmp affected AlmaLinux:8 rsyslog-snmp
rsyslog-udpspoof affected AlmaLinux:8 rsyslog-udpspoof
Upstream advisory

CLSA-2022-1652706523

Open SourcePoC exploit2022-05-16

Fixed CVE-2022-24903 in rsyslog

Affected products

ProductStatusVendorPackageEcosystem
rsyslog affected TuxCare:CentOS:8.5 rsyslog
rsyslog-crypto affected TuxCare:CentOS:8.5 rsyslog-crypto
rsyslog-doc affected TuxCare:CentOS:8.5 rsyslog-doc
rsyslog-elasticsearch affected TuxCare:CentOS:8.5 rsyslog-elasticsearch
rsyslog-gnutls affected TuxCare:CentOS:8.5 rsyslog-gnutls
rsyslog-gssapi affected TuxCare:CentOS:8.5 rsyslog-gssapi
rsyslog-kafka affected TuxCare:CentOS:8.5 rsyslog-kafka
rsyslog-mmaudit affected TuxCare:CentOS:8.5 rsyslog-mmaudit
rsyslog-mmjsonparse affected TuxCare:CentOS:8.5 rsyslog-mmjsonparse
rsyslog-mmkubernetes affected TuxCare:CentOS:8.5 rsyslog-mmkubernetes
rsyslog-mmnormalize affected TuxCare:CentOS:8.5 rsyslog-mmnormalize
rsyslog-mmsnmptrapd affected TuxCare:CentOS:8.5 rsyslog-mmsnmptrapd
rsyslog-mysql affected TuxCare:CentOS:8.5 rsyslog-mysql
rsyslog-omamqp1 affected TuxCare:CentOS:8.5 rsyslog-omamqp1
rsyslog-openssl affected TuxCare:CentOS:8.5 rsyslog-openssl
rsyslog-pgsql affected TuxCare:CentOS:8.5 rsyslog-pgsql
rsyslog-relp affected TuxCare:CentOS:8.5 rsyslog-relp
rsyslog-snmp affected TuxCare:CentOS:8.5 rsyslog-snmp
rsyslog-udpspoof affected TuxCare:CentOS:8.5 rsyslog-udpspoof
Upstream advisory

CLSA-2022-1652706426

Open SourcePoC exploit2022-05-16

Fixed CVE-2022-24903 in rsyslog

Affected products

ProductStatusVendorPackageEcosystem
rsyslog affected TuxCare:CentOS:8.4 rsyslog
rsyslog-crypto affected TuxCare:CentOS:8.4 rsyslog-crypto
rsyslog-doc affected TuxCare:CentOS:8.4 rsyslog-doc
rsyslog-elasticsearch affected TuxCare:CentOS:8.4 rsyslog-elasticsearch
rsyslog-gnutls affected TuxCare:CentOS:8.4 rsyslog-gnutls
rsyslog-gssapi affected TuxCare:CentOS:8.4 rsyslog-gssapi
rsyslog-kafka affected TuxCare:CentOS:8.4 rsyslog-kafka
rsyslog-mmaudit affected TuxCare:CentOS:8.4 rsyslog-mmaudit
rsyslog-mmjsonparse affected TuxCare:CentOS:8.4 rsyslog-mmjsonparse
rsyslog-mmkubernetes affected TuxCare:CentOS:8.4 rsyslog-mmkubernetes
rsyslog-mmnormalize affected TuxCare:CentOS:8.4 rsyslog-mmnormalize
rsyslog-mmsnmptrapd affected TuxCare:CentOS:8.4 rsyslog-mmsnmptrapd
rsyslog-mysql affected TuxCare:CentOS:8.4 rsyslog-mysql
rsyslog-omamqp1 affected TuxCare:CentOS:8.4 rsyslog-omamqp1
rsyslog-pgsql affected TuxCare:CentOS:8.4 rsyslog-pgsql
rsyslog-relp affected TuxCare:CentOS:8.4 rsyslog-relp
rsyslog-snmp affected TuxCare:CentOS:8.4 rsyslog-snmp
rsyslog-udpspoof affected TuxCare:CentOS:8.4 rsyslog-udpspoof
Upstream advisory

GHSA-gv86-43rv-79m2

Open SourcePoC exploitMEDIUM2022-05-14

RubyGems Improper Input Validation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-gv86-43rv-79m2

Open SourcePoC exploitMEDIUM2022-05-14

RubyGems Improper Input Validation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-3vm4-22fp-5rfm

Open SourcePoC exploitHIGH2022-05-24

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
k3d affected chainguard k3d
k3d affected wolfi k3d
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-3vm4-22fp-5rfm

Open SourcePoC exploitHIGH2022-05-24

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GO-2021-0319

Open SourcePoC exploit2022-05-23

Incorrect computation for some invalid field elements in crypto/elliptic

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GHSA-mc6j-h948-v2p6

Open SourcePoC exploitCRITICAL2022-05-14

RubyGems Improper Verification of Cryptographic Signature vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-mc6j-h948-v2p6

Open SourcePoC exploitCRITICAL2022-05-14

RubyGems Improper Verification of Cryptographic Signature vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-qj2w-mw2r-pv39

Open SourcePoC exploitHIGH2022-05-14

RubyGems Deserialization of Untrusted Data vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-qj2w-mw2r-pv39

Open SourcePoC exploitHIGH2022-05-14

RubyGems Deserialization of Untrusted Data vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GO-2021-0317

Open SourcePoC exploit2022-05-23

Uncontrolled memory consumption in math/big

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GHSA-8qxg-mff5-j3wc

Open SourcePoC exploitHIGH2022-05-14

RubyGems Path Traversal vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-8qxg-mff5-j3wc

Open SourcePoC exploitHIGH2022-05-14

RubyGems Path Traversal vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-87qx-g5wg-mwmj

Open SourcePoC exploitHIGH2022-05-14

RubyGems Cross-site Scripting vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-87qx-g5wg-mwmj

Open SourcePoC exploitHIGH2022-05-14

RubyGems Cross-site Scripting vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

GHSA-cqj8-47ch-rvvq

Open SourcePoC exploitMEDIUM2022-05-24

Incorrect Default Permissions in JetBrains Kotlin

Affected products

ProductStatusVendorPackageEcosystem
org.jetbrains.kotlin:kotlin-stdlib affected Maven org.jetbrains.kotlin:kotlin-stdlib
Upstream advisory

GHSA-cqj8-47ch-rvvq

Open SourcePoC exploitMEDIUM2022-05-24

Incorrect Default Permissions in JetBrains Kotlin

Affected products

ProductStatusVendorPackageEcosystem
org.jetbrains.kotlin:kotlin-stdlib affected Maven org.jetbrains.kotlin:kotlin-stdlib
thingsboard affected chainguard thingsboard
thingsboard affected wolfi thingsboard
Upstream advisory

GHSA-fp37-c92q-4pwq

Open SourcePoC exploitCRITICAL2022-05-24

Kubernetes kube-apiserver unauthorized access

Affected products

ProductStatusVendorPackageEcosystem
apiextensions-apiserver affected k8s.io k8s.io/apiextensions-apiserver
Upstream advisory

GHSA-fp37-c92q-4pwq

Open SourcePoC exploitCRITICAL2022-05-24

Kubernetes kube-apiserver unauthorized access

Affected products

ProductStatusVendorPackageEcosystem
apiextensions-apiserver affected k8s.io k8s.io/apiextensions-apiserver
Upstream advisory

GHSA-jmrx-5g74-6v2f

Open SourcePoC exploitMEDIUM2022-05-24

Kubernetes client-go library logs may disclose credentials to unauthorized users

Affected products

ProductStatusVendorPackageEcosystem
client-go affected k8s.io k8s.io/client-go
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

GHSA-jmrx-5g74-6v2f

Open SourcePoC exploitMEDIUM2022-05-24

Kubernetes client-go library logs may disclose credentials to unauthorized users

Affected products

ProductStatusVendorPackageEcosystem
client-go affected k8s.io k8s.io/client-go
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-gc2p-g4fg-29vh

Open SourcePoC exploitHIGH2022-05-24

Kubernetes did not effectively clear service account credentials

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-gc2p-g4fg-29vh

Open SourcePoC exploitHIGH2022-05-24

Kubernetes did not effectively clear service account credentials

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2022-20120

Open SourcePoC exploitHIGH2022-05-03

Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A

CVEs:CVE-2022-20120

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-203213034

GooglePoC exploit2022-05-01

PUB-A-203213034

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-25746

GooglePoC exploitHIGH2022-05-06

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx...

CVEs:CVE-2021-25746

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected kubernetes
Upstream advisory

GHSA-c75v-2vq8-878f

Open SourcePoC exploitCRITICAL2022-05-27

Angular vulnerable to Cross-site Scripting

Affected products

ProductStatusVendorPackageEcosystem
core affected angular @angular/core
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
solr affected chainguard solr
solr affected wolfi solr
Upstream advisory

GHSA-c75v-2vq8-878f

Open SourcePoC exploitCRITICAL2022-05-27

Angular vulnerable to Cross-site Scripting

Affected products

ProductStatusVendorPackageEcosystem
core affected angular @angular/core
Upstream advisory

CVE-2021-4231

Open SourcePoC exploitMEDIUM2022-05-26

Angular vulnerable to Cross-site Scripting

CVEs:CVE-2021-4231

Affected products

ProductStatusVendorPackageEcosystem
core affected angular @angular/core
Upstream advisory

CVE-2021-4231

Open SourcePoC exploitMEDIUM2022-05-26

Angular vulnerable to Cross-site Scripting

CVEs:CVE-2021-4231

Affected products

ProductStatusVendorPackageEcosystem
core affected angular @angular/core
Upstream advisory

CVE-2021-4231

Open SourcePoC exploitCRITICAL2022-05-26

A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might requ...

CVEs:CVE-2021-4231

Affected products

ProductStatusVendorPackageEcosystem
angular affected angular
angularjs affected angularjs
Upstream advisory

GHSA-mm7g-f2gg-cw8g

Open SourcePoC exploitHIGH2022-05-13

Kubernetes arbitrary file overwrite

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-mm7g-f2gg-cw8g

Open SourcePoC exploitHIGH2022-05-13

Kubernetes arbitrary file overwrite

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-x24q-xwrf-66jm

GooglePoC exploitCRITICAL2022-05-17

Improper Neutralization of Input During Web Page Generation in Google Web Toolkit

Affected products

ProductStatusVendorPackageEcosystem
com.google.gwt:gwt affected Maven com.google.gwt:gwt
Upstream advisory

GHSA-x24q-xwrf-66jm

GooglePoC exploitCRITICAL2022-05-17

Improper Neutralization of Input During Web Page Generation in Google Web Toolkit

Affected products

ProductStatusVendorPackageEcosystem
com.google.gwt:gwt affected Maven com.google.gwt:gwt
Upstream advisory

GHSA-hhpm-74pm-hf35

Open SourcePoC exploitHIGH2022-05-24

ingress-nginx component for Kubernetes allows file overwrite

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller-1.9 affected chainguard ingress-nginx-controller-1.9
ingress-nginx-controller-fips affected chainguard ingress-nginx-controller-fips
ingress-nginx-controller-fips-1.9 affected chainguard ingress-nginx-controller-fips-1.9
Upstream advisory

GHSA-hhpm-74pm-hf35

Open SourcePoC exploitHIGH2022-05-24

ingress-nginx component for Kubernetes allows file overwrite

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

ASB-A-218337595

GooglePoC exploit2022-05-01

ASB-A-218337595

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-20008

Open SourcePoC exploitMEDIUM2022-05-10

In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution privileges ne...

CVEs:CVE-2022-20008

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-216481035

GooglePoC exploitMEDIUM2022-05-01

ASB-A-216481035

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20009

Open SourcePoC exploitHIGH2022-05-10

In various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-20009

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-213172319

GooglePoC exploitHIGH2022-05-01

ASB-A-213172319

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-216408350

GooglePoC exploitNONE2022-05-01

PUB-A-216408350

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20005

Open SourcePoC exploitHIGH2022-05-03

In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and a parsed APK . This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...

CVEs:CVE-2022-20005

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20004

Open SourcePoC exploitHIGH2022-05-03

In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2022-20004

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20007

Open SourcePoC exploitHIGH2022-05-03

In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege ...

CVEs:CVE-2022-20007

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39670

Open SourcePoC exploitMEDIUM2022-05-03

In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2021-39670

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-m2h2-264f-f486

Open SourceCoalition ESS < 30%HIGH2022-05-03

angular vulnerable to regular expression denial of service (ReDoS)

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

GHSA-m2h2-264f-f486

Open SourceCoalition ESS < 30%HIGH2022-05-03

angular vulnerable to regular expression denial of service (ReDoS)

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
solr affected wolfi solr
solr affected chainguard solr
Upstream advisory

CVE-2022-25844

Open SourceCoalition ESS < 30%MEDIUM2022-05-01

angular vulnerable to regular expression denial of service (ReDoS)

CVEs:CVE-2022-25844

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

CVE-2022-25844

Open SourceCoalition ESS < 30%HIGH2022-05-01

The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very hig...

CVEs:CVE-2022-25844

Affected products

ProductStatusVendorPackageEcosystem
angularjs affected angularjs
fedora affected fedoraproject
ontap_select_deploy_administration_utility affected netapp
Upstream advisory

CVE-2022-25844

Open SourceCoalition ESS < 30%MEDIUM2022-05-01

angular vulnerable to regular expression denial of service (ReDoS)

CVEs:CVE-2022-25844

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

DEBIAN-CVE-2022-25844

Open SourceCoalition ESS < 30%HIGH2022-05-01

DEBIAN-CVE-2022-25844

Affected products

ProductStatusVendorPackageEcosystem
angular.js affected Debian:12 angular.js
angular.js affected Debian:11 angular.js
angular.js affected Debian:13 angular.js
angular.js affected Debian:14 angular.js
Upstream advisory

ALSA-2022:4797

GoogleCoalition ESS < 30%CRITICAL2022-05-30

Important: maven:3.6 security update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected AlmaLinux:8 aopalliance
apache-commons-cli affected AlmaLinux:8 apache-commons-cli
apache-commons-codec affected AlmaLinux:8 apache-commons-codec
apache-commons-io affected AlmaLinux:8 apache-commons-io
apache-commons-lang3 affected AlmaLinux:8 apache-commons-lang3
atinject affected AlmaLinux:8 atinject
cdi-api affected AlmaLinux:8 cdi-api
geronimo-annotation affected AlmaLinux:8 geronimo-annotation
google-guice affected AlmaLinux:8 google-guice
guava affected AlmaLinux:8 guava
httpcomponents-client affected AlmaLinux:8 httpcomponents-client
httpcomponents-core affected AlmaLinux:8 httpcomponents-core
jansi affected AlmaLinux:8 jansi
jcl-over-slf4j affected AlmaLinux:8 jcl-over-slf4j
jsoup affected AlmaLinux:8 jsoup
jsr-305 affected AlmaLinux:8 jsr-305
maven affected AlmaLinux:8 maven
maven-lib affected AlmaLinux:8 maven-lib
maven-openjdk11 affected AlmaLinux:8 maven-openjdk11
maven-openjdk17 affected AlmaLinux:8 maven-openjdk17
maven-openjdk8 affected AlmaLinux:8 maven-openjdk8
maven-resolver affected AlmaLinux:8 maven-resolver
maven-shared-utils affected AlmaLinux:8 maven-shared-utils
maven-wagon affected AlmaLinux:8 maven-wagon
plexus-cipher affected AlmaLinux:8 plexus-cipher
plexus-classworlds affected AlmaLinux:8 plexus-classworlds
plexus-containers-component-annotations affected AlmaLinux:8 plexus-containers-component-annotations
plexus-interpolation affected AlmaLinux:8 plexus-interpolation
plexus-sec-dispatcher affected AlmaLinux:8 plexus-sec-dispatcher
plexus-utils affected AlmaLinux:8 plexus-utils
sisu affected AlmaLinux:8 sisu
slf4j affected AlmaLinux:8 slf4j
Upstream advisory

RLSA-2022:4797

GoogleCoalition ESS < 30%CRITICAL2022-05-30

Important: maven:3.6 security update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected Rocky Linux:8 aopalliance
apache-commons-cli affected Rocky Linux:8 apache-commons-cli
apache-commons-codec affected Rocky Linux:8 apache-commons-codec
apache-commons-io affected Rocky Linux:8 apache-commons-io
apache-commons-lang3 affected Rocky Linux:8 apache-commons-lang3
atinject affected Rocky Linux:8 atinject
cdi-api affected Rocky Linux:8 cdi-api
geronimo-annotation affected Rocky Linux:8 geronimo-annotation
google-guice affected Rocky Linux:8 google-guice
guava affected Rocky Linux:8 guava
httpcomponents-client affected Rocky Linux:8 httpcomponents-client
httpcomponents-core affected Rocky Linux:8 httpcomponents-core
jansi affected Rocky Linux:8 jansi
jsoup affected Rocky Linux:8 jsoup
jsr-305 affected Rocky Linux:8 jsr-305
maven affected Rocky Linux:8 maven
maven-resolver affected Rocky Linux:8 maven-resolver
maven-shared-utils affected Rocky Linux:8 maven-shared-utils
maven-wagon affected Rocky Linux:8 maven-wagon
plexus-cipher affected Rocky Linux:8 plexus-cipher
plexus-classworlds affected Rocky Linux:8 plexus-classworlds
plexus-containers affected Rocky Linux:8 plexus-containers
plexus-interpolation affected Rocky Linux:8 plexus-interpolation
plexus-sec-dispatcher affected Rocky Linux:8 plexus-sec-dispatcher
plexus-utils affected Rocky Linux:8 plexus-utils
sisu affected Rocky Linux:8 sisu
slf4j affected Rocky Linux:8 slf4j
Upstream advisory

ALSA-2022:4798

GoogleCoalition ESS < 30%CRITICAL2022-05-30

Important: maven:3.5 security update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected AlmaLinux:8 aopalliance
apache-commons-cli affected AlmaLinux:8 apache-commons-cli
apache-commons-codec affected AlmaLinux:8 apache-commons-codec
apache-commons-io affected AlmaLinux:8 apache-commons-io
apache-commons-lang3 affected AlmaLinux:8 apache-commons-lang3
apache-commons-logging affected AlmaLinux:8 apache-commons-logging
atinject affected AlmaLinux:8 atinject
cdi-api affected AlmaLinux:8 cdi-api
geronimo-annotation affected AlmaLinux:8 geronimo-annotation
glassfish-el-api affected AlmaLinux:8 glassfish-el-api
google-guice affected AlmaLinux:8 google-guice
guava20 affected AlmaLinux:8 guava20
hawtjni-runtime affected AlmaLinux:8 hawtjni-runtime
httpcomponents-client affected AlmaLinux:8 httpcomponents-client
httpcomponents-core affected AlmaLinux:8 httpcomponents-core
jansi affected AlmaLinux:8 jansi
jansi-native affected AlmaLinux:8 jansi-native
jboss-interceptors-1.2-api affected AlmaLinux:8 jboss-interceptors-1.2-api
jcl-over-slf4j affected AlmaLinux:8 jcl-over-slf4j
jsoup affected AlmaLinux:8 jsoup
maven affected AlmaLinux:8 maven
maven-lib affected AlmaLinux:8 maven-lib
maven-resolver-api affected AlmaLinux:8 maven-resolver-api
maven-resolver-connector-basic affected AlmaLinux:8 maven-resolver-connector-basic
maven-resolver-impl affected AlmaLinux:8 maven-resolver-impl
maven-resolver-spi affected AlmaLinux:8 maven-resolver-spi
maven-resolver-transport-wagon affected AlmaLinux:8 maven-resolver-transport-wagon
maven-resolver-util affected AlmaLinux:8 maven-resolver-util
maven-shared-utils affected AlmaLinux:8 maven-shared-utils
maven-wagon-file affected AlmaLinux:8 maven-wagon-file
maven-wagon-http affected AlmaLinux:8 maven-wagon-http
maven-wagon-http-shared affected AlmaLinux:8 maven-wagon-http-shared
maven-wagon-provider-api affected AlmaLinux:8 maven-wagon-provider-api
plexus-cipher affected AlmaLinux:8 plexus-cipher
plexus-classworlds affected AlmaLinux:8 plexus-classworlds
plexus-containers-component-annotations affected AlmaLinux:8 plexus-containers-component-annotations
plexus-interpolation affected AlmaLinux:8 plexus-interpolation
plexus-sec-dispatcher affected AlmaLinux:8 plexus-sec-dispatcher
plexus-utils affected AlmaLinux:8 plexus-utils
sisu-inject affected AlmaLinux:8 sisu-inject
sisu-plexus affected AlmaLinux:8 sisu-plexus
slf4j affected AlmaLinux:8 slf4j
Upstream advisory

RLSA-2022:4798

GoogleCoalition ESS < 30%CRITICAL2022-05-30

Important: maven:3.5 security update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected Rocky Linux:8 aopalliance
apache-commons-cli affected Rocky Linux:8 apache-commons-cli
apache-commons-codec affected Rocky Linux:8 apache-commons-codec
apache-commons-io affected Rocky Linux:8 apache-commons-io
apache-commons-lang3 affected Rocky Linux:8 apache-commons-lang3
apache-commons-logging affected Rocky Linux:8 apache-commons-logging
atinject affected Rocky Linux:8 atinject
cdi-api affected Rocky Linux:8 cdi-api
geronimo-annotation affected Rocky Linux:8 geronimo-annotation
glassfish-el affected Rocky Linux:8 glassfish-el
google-guice affected Rocky Linux:8 google-guice
guava20 affected Rocky Linux:8 guava20
hawtjni affected Rocky Linux:8 hawtjni
httpcomponents-client affected Rocky Linux:8 httpcomponents-client
httpcomponents-core affected Rocky Linux:8 httpcomponents-core
jansi affected Rocky Linux:8 jansi
jansi-native affected Rocky Linux:8 jansi-native
jboss-interceptors-1.2-api affected Rocky Linux:8 jboss-interceptors-1.2-api
jsoup affected Rocky Linux:8 jsoup
maven affected Rocky Linux:8 maven
maven-resolver affected Rocky Linux:8 maven-resolver
maven-shared-utils affected Rocky Linux:8 maven-shared-utils
maven-wagon affected Rocky Linux:8 maven-wagon
plexus-cipher affected Rocky Linux:8 plexus-cipher
plexus-classworlds affected Rocky Linux:8 plexus-classworlds
plexus-containers affected Rocky Linux:8 plexus-containers
plexus-interpolation affected Rocky Linux:8 plexus-interpolation
plexus-sec-dispatcher affected Rocky Linux:8 plexus-sec-dispatcher
plexus-utils affected Rocky Linux:8 plexus-utils
sisu affected Rocky Linux:8 sisu
slf4j affected Rocky Linux:8 slf4j
Upstream advisory

GO-2022-0217

Open SourceCoalition ESS < 30%HIGH2022-05-24

Denial of service affecting P-521 and P-384 curves in crypto/elliptic

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GO-2022-0435

Open SourceCoalition ESS < 30%2022-05-20

Panic due to large inputs affecting P-256 curves in crypto/elliptic

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GHSA-hp87-p4gw-j4gq

GoogleCoalition ESS < 30%HIGH2022-05-20

gopkg.in/yaml.v3 Denial of Service

Affected products

ProductStatusVendorPackageEcosystem
yaml.v3 affected gopkg.in gopkg.in/yaml.v3
Upstream advisory

GHSA-hp87-p4gw-j4gq

Open SourceCoalition ESS < 30%HIGH2022-05-20

gopkg.in/yaml.v3 Denial of Service

Affected products

ProductStatusVendorPackageEcosystem
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubernetes-csi-external-snapshotter-6.0 affected chainguard kubernetes-csi-external-snapshotter-6.0
kube-state-metrics-2.2.0 affected chainguard kube-state-metrics-2.2.0
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
thanos-operator affected chainguard thanos-operator
thanos-operator affected wolfi thanos-operator
thanos-operator-fips affected chainguard thanos-operator-fips
yaml.v3 affected gopkg.in
yaml.v3 affected gopkg.in gopkg.in/yaml.v3
Upstream advisory

DEBIAN-CVE-2022-28948

Open SourceCoalition ESS < 30%HIGH2022-05-19

DEBIAN-CVE-2022-28948

Affected products

ProductStatusVendorPackageEcosystem
golang-gopkg-yaml.v3 affected Debian:11 golang-gopkg-yaml.v3
golang-gopkg-yaml.v3 affected Debian:12 golang-gopkg-yaml.v3
golang-gopkg-yaml.v3 affected Debian:13 golang-gopkg-yaml.v3
golang-gopkg-yaml.v3 affected Debian:14 golang-gopkg-yaml.v3
Upstream advisory

GHSA-h86h-8ppg-mxmh

Open SourceCoalition ESS < 30%HIGH2022-05-24

golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-h86h-8ppg-mxmh

Open SourceCoalition ESS < 30%HIGH2022-05-24

golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

Affected products

ProductStatusVendorPackageEcosystem
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
hey affected chainguard hey
hey affected wolfi hey
k3d affected chainguard k3d
k3d affected wolfi k3d
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
x/net affected golang.org golang.org/x/net
x/net affected golang.org
Upstream advisory

GHSA-r5c5-pr8j-pfp7

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

golang.org/x/crypto/salsa20/salsa uses insufficiently random values

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-r5c5-pr8j-pfp7

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

golang.org/x/crypto/salsa20/salsa uses insufficiently random values

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
k3d affected chainguard k3d
k3d affected wolfi k3d
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-3gp9-h8hw-pxpw

Open SourceCoalition ESS < 30%HIGH2022-05-24

Denial of service in .NET core

Affected products

ProductStatusVendorPackageEcosystem
Microsoft.NETCore.App affected NuGet Microsoft.NETCore.App
Microsoft.NETCore.App affected NuGet Microsoft.NETCore.App
Microsoft.NETCore.App.Host.linux-arm affected NuGet Microsoft.NETCore.App.Host.linux-arm
Microsoft.NETCore.App.Host.linux-arm affected NuGet Microsoft.NETCore.App.Host.linux-arm
Microsoft.NETCore.App.Host.linux-arm64 affected NuGet Microsoft.NETCore.App.Host.linux-arm64
Microsoft.NETCore.App.Host.linux-arm64 affected NuGet Microsoft.NETCore.App.Host.linux-arm64
Microsoft.NETCore.App.Host.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Host.linux-musl-arm64
Microsoft.NETCore.App.Host.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Host.linux-musl-arm64
Microsoft.NETCore.App.Host.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Host.linux-musl-x64
Microsoft.NETCore.App.Host.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Host.linux-musl-x64
Microsoft.NETCore.App.Host.linux-x64 affected NuGet Microsoft.NETCore.App.Host.linux-x64
Microsoft.NETCore.App.Host.linux-x64 affected NuGet Microsoft.NETCore.App.Host.linux-x64
Microsoft.NETCore.App.Host.osx-x64 affected NuGet Microsoft.NETCore.App.Host.osx-x64
Microsoft.NETCore.App.Host.osx-x64 affected NuGet Microsoft.NETCore.App.Host.osx-x64
Microsoft.NETCore.App.Host.rhel.6-x64 affected NuGet Microsoft.NETCore.App.Host.rhel.6-x64
Microsoft.NETCore.App.Host.rhel.6-x64 affected NuGet Microsoft.NETCore.App.Host.rhel.6-x64
Microsoft.NETCore.App.Host.win-arm affected NuGet Microsoft.NETCore.App.Host.win-arm
Microsoft.NETCore.App.Host.win-arm affected NuGet Microsoft.NETCore.App.Host.win-arm
Microsoft.NETCore.App.Host.win-arm64 affected NuGet Microsoft.NETCore.App.Host.win-arm64
Microsoft.NETCore.App.Host.win-arm64 affected NuGet Microsoft.NETCore.App.Host.win-arm64
Microsoft.NETCore.App.Host.win-x64 affected NuGet Microsoft.NETCore.App.Host.win-x64
Microsoft.NETCore.App.Host.win-x64 affected NuGet Microsoft.NETCore.App.Host.win-x64
Microsoft.NETCore.App.Host.win-x86 affected NuGet Microsoft.NETCore.App.Host.win-x86
Microsoft.NETCore.App.Host.win-x86 affected NuGet Microsoft.NETCore.App.Host.win-x86
Microsoft.NETCore.App.Runtime.android-arm affected NuGet Microsoft.NETCore.App.Runtime.android-arm
Microsoft.NETCore.App.Runtime.android-arm affected NuGet Microsoft.NETCore.App.Runtime.android-arm
Microsoft.NETCore.App.Runtime.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.android-arm64
Microsoft.NETCore.App.Runtime.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.android-arm64
Microsoft.NETCore.App.Runtime.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.android-x64
Microsoft.NETCore.App.Runtime.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.android-x64
Microsoft.NETCore.App.Runtime.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.android-x86
Microsoft.NETCore.App.Runtime.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.android-x86
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.ios-arm
Microsoft.NETCore.App.Runtime.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.ios-arm
Microsoft.NETCore.App.Runtime.ios-x64 affected NuGet Microsoft.NETCore.App.Runtime.ios-x64
Microsoft.NETCore.App.Runtime.ios-x64 affected NuGet Microsoft.NETCore.App.Runtime.ios-x64
Microsoft.NETCore.App.Runtime.ios-x86 affected NuGet Microsoft.NETCore.App.Runtime.ios-x86
Microsoft.NETCore.App.Runtime.ios-x86 affected NuGet Microsoft.NETCore.App.Runtime.ios-x86
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.rhel.6-x64 affected NuGet Microsoft.NETCore.App.Runtime.rhel.6-x64
Microsoft.NETCore.App.Runtime.rhel.6-x64 affected NuGet Microsoft.NETCore.App.Runtime.rhel.6-x64
Microsoft.NETCore.App.Runtime.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.tvos-arm64
Microsoft.NETCore.App.Runtime.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.tvos-arm64
Microsoft.NETCore.App.Runtime.tvos-x64 affected NuGet Microsoft.NETCore.App.Runtime.tvos-x64
Microsoft.NETCore.App.Runtime.tvos-x64 affected NuGet Microsoft.NETCore.App.Runtime.tvos-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

GHSA-3gp9-h8hw-pxpw

Open SourceCoalition ESS < 30%HIGH2022-05-24

Denial of service in .NET core

Affected products

ProductStatusVendorPackageEcosystem
Microsoft.NETCore.App affected NuGet Microsoft.NETCore.App
Microsoft.NETCore.App.Host.linux-arm affected NuGet Microsoft.NETCore.App.Host.linux-arm
Microsoft.NETCore.App.Host.linux-arm64 affected NuGet Microsoft.NETCore.App.Host.linux-arm64
Microsoft.NETCore.App.Host.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Host.linux-musl-arm64
Microsoft.NETCore.App.Host.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Host.linux-musl-x64
Microsoft.NETCore.App.Host.linux-x64 affected NuGet Microsoft.NETCore.App.Host.linux-x64
Microsoft.NETCore.App.Host.osx-x64 affected NuGet Microsoft.NETCore.App.Host.osx-x64
Microsoft.NETCore.App.Host.rhel.6-x64 affected NuGet Microsoft.NETCore.App.Host.rhel.6-x64
Microsoft.NETCore.App.Host.win-arm affected NuGet Microsoft.NETCore.App.Host.win-arm
Microsoft.NETCore.App.Host.win-arm64 affected NuGet Microsoft.NETCore.App.Host.win-arm64
Microsoft.NETCore.App.Host.win-x64 affected NuGet Microsoft.NETCore.App.Host.win-x64
Microsoft.NETCore.App.Host.win-x86 affected NuGet Microsoft.NETCore.App.Host.win-x86
Microsoft.NETCore.App.Runtime.android-arm affected NuGet Microsoft.NETCore.App.Runtime.android-arm
Microsoft.NETCore.App.Runtime.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.android-arm64
Microsoft.NETCore.App.Runtime.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.android-x64
Microsoft.NETCore.App.Runtime.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.android-x86
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.ios-arm
Microsoft.NETCore.App.Runtime.ios-x64 affected NuGet Microsoft.NETCore.App.Runtime.ios-x64
Microsoft.NETCore.App.Runtime.ios-x86 affected NuGet Microsoft.NETCore.App.Runtime.ios-x86
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.rhel.6-x64 affected NuGet Microsoft.NETCore.App.Runtime.rhel.6-x64
Microsoft.NETCore.App.Runtime.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.tvos-arm64
Microsoft.NETCore.App.Runtime.tvos-x64 affected NuGet Microsoft.NETCore.App.Runtime.tvos-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

DEBIAN-CVE-2022-30321

Open SourceCoalition ESS < 30%CRITICAL2022-05-25

DEBIAN-CVE-2022-30321

Affected products

ProductStatusVendorPackageEcosystem
golang-github-hashicorp-go-getter affected Debian:11 golang-github-hashicorp-go-getter
golang-github-hashicorp-go-getter affected Debian:12 golang-github-hashicorp-go-getter
Upstream advisory

GHSA-5v8v-66v8-mwm7

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Integer overflow in the bundled Brotli C library

Affected products

ProductStatusVendorPackageEcosystem
brotli affected PyPI brotli
compu-brotli-sys affected crates.io compu-brotli-sys
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

GHSA-5v8v-66v8-mwm7

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Integer overflow in the bundled Brotli C library

Affected products

ProductStatusVendorPackageEcosystem
brotli affected chainguard brotli
brotli affected PyPI brotli
brotli affected wolfi brotli
compu-brotli-sys affected crates.io compu-brotli-sys
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.browser-wasm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

GO-2021-0347

Open SourceCoalition ESS < 30%2022-05-23

Stack exhaustion when compiling deeply nested expressions in regexp

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GO-2022-0220

Open SourceCoalition ESS < 30%2022-05-25

DLL injection on Windows in runtime and syscall

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

MGASA-2022-0210

Open SourceCoalition ESS < 30%2022-05-28

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
golang affected golang
Upstream advisory

CVE-2022-29526

GoogleCoalition ESS < 30%MEDIUM2022-05-24

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

CVEs:CVE-2022-29526

Affected products

ProductStatusVendorPackageEcosystem
beegfs_csi_driver affected netapp
fedora affected fedoraproject
go affected golang
Upstream advisory

CVE-2022-29526

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

CVEs:CVE-2022-29526

Affected products

ProductStatusVendorPackageEcosystem
x/sys affected golang.org golang.org/x/sys
Upstream advisory

GHSA-wf76-qgqq-gcfj

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

RCE vulnerability in Google Kubernetes Engine Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-kubernetes-engine affected Maven org.jenkins-ci.plugins:google-kubernetes-engine
Upstream advisory

GHSA-wf76-qgqq-gcfj

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

RCE vulnerability in Google Kubernetes Engine Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-kubernetes-engine affected Maven org.jenkins-ci.plugins:google-kubernetes-engine
Upstream advisory

GHSA-g954-5hwp-pp24

Open SourceCoalition ESS < 30%HIGH2022-05-28

Prototype Pollution in protobufjs

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected npm protobufjs
Upstream advisory

GHSA-g954-5hwp-pp24

Open SourceCoalition ESS < 30%HIGH2022-05-28

Prototype Pollution in protobufjs

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected npm protobufjs
Upstream advisory

CVE-2022-25878

Open SourceCoalition ESS < 30%HIGH2022-05-27

Prototype Pollution in protobufjs

CVEs:CVE-2022-25878

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected npm protobufjs
Upstream advisory

CVE-2022-25878

Open SourceCoalition ESS < 30%HIGH2022-05-27

Prototype Pollution in protobufjs

CVEs:CVE-2022-25878

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected npm protobufjs
Upstream advisory

CVE-2022-25878

Open SourceCoalition ESS < 30%HIGH2022-05-27

The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProp...

CVEs:CVE-2022-25878

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected protobufjs_project
Upstream advisory

GHSA-qcvw-82hh-gq38

Open SourceCoalition ESS < 30%HIGH2022-05-24

Istio ReDoS Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
cert-manager-istio-csr affected wolfi cert-manager-istio-csr
cert-manager-istio-csr affected chainguard cert-manager-istio-csr
cert-manager-istio-csr-fips affected chainguard cert-manager-istio-csr-fips
istio affected istio.io istio.io/istio
istio-cni-1.21 affected chainguard istio-cni-1.21
istio-cni-1.21 affected wolfi istio-cni-1.21
istio-cni-1.22 affected wolfi istio-cni-1.22
istio-cni-1.22 affected chainguard istio-cni-1.22
istio-fips-1.21 affected chainguard istio-fips-1.21
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-1.21 affected wolfi istio-operator-1.21
istio-operator-1.21 affected chainguard istio-operator-1.21
istio-operator-1.22 affected chainguard istio-operator-1.22
istio-operator-1.22 affected wolfi istio-operator-1.22
istio-pilot-agent-1.21 affected wolfi istio-pilot-agent-1.21
istio-pilot-agent-1.21 affected chainguard istio-pilot-agent-1.21
istio-pilot-agent-1.22 affected wolfi istio-pilot-agent-1.22
istio-pilot-agent-1.22 affected chainguard istio-pilot-agent-1.22
istio-pilot-discovery-1.21 affected chainguard istio-pilot-discovery-1.21
istio-pilot-discovery-1.21 affected wolfi istio-pilot-discovery-1.21
istio-pilot-discovery-1.22 affected wolfi istio-pilot-discovery-1.22
istio-pilot-discovery-1.22 affected chainguard istio-pilot-discovery-1.22
kgateway-2.3 affected chainguard kgateway-2.3
kgateway-2.4 affected chainguard kgateway-2.4
kgateway-fips-2.3 affected chainguard kgateway-fips-2.3
kgateway-fips-2.4 affected chainguard kgateway-fips-2.4
Upstream advisory

GHSA-qcvw-82hh-gq38

Open SourceCoalition ESS < 30%HIGH2022-05-24

Istio ReDoS Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

GHSA-9r3h-wm3x-v245

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin

Affected products

ProductStatusVendorPackageEcosystem
com.elasticbox.jenkins-ci.plugins:kubernetes-ci affected Maven com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Upstream advisory

GHSA-9r3h-wm3x-v245

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin

Affected products

ProductStatusVendorPackageEcosystem
com.elasticbox.jenkins-ci.plugins:kubernetes-ci affected Maven com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Upstream advisory

GHSA-x3jr-pf6g-c48f

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Golang/x/crypto message forgery vulnerability

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-x3jr-pf6g-c48f

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Golang/x/crypto message forgery vulnerability

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
k3d affected chainguard k3d
k3d affected wolfi k3d
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-f4w6-3rh6-6q4q

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access

Affected products

ProductStatusVendorPackageEcosystem
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
calico affected wolfi calico
calico affected chainguard calico
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
kubernetes-1.26 affected chainguard kubernetes-1.26
kubernetes-1.26 affected wolfi kubernetes-1.26
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi/external-provisioner affected github.com github.com/kubernetes-csi/external-provisioner
kubernetes-csi/external-resizer affected github.com github.com/kubernetes-csi/external-resizer
kubernetes-csi/external-snapshotter/v6 affected github.com github.com/kubernetes-csi/external-snapshotter/v6
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
Upstream advisory

GHSA-f4w6-3rh6-6q4q

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-csi/external-provisioner affected github.com github.com/kubernetes-csi/external-provisioner
kubernetes-csi/external-resizer affected github.com github.com/kubernetes-csi/external-resizer
kubernetes-csi/external-snapshotter/v6 affected github.com github.com/kubernetes-csi/external-snapshotter/v6
Upstream advisory

GO-2022-0289

Open SourceCoalition ESS < 30%NONE2022-05-18

Misdirected I/O in syscall

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go
stdlib affected Go stdlib
Upstream advisory

CVE-2022-30127

Open SourceCoalition ESS < 30%CRITICAL2022-05-10

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-30127

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-30128

Open SourceCoalition ESS < 30%CRITICAL2022-05-10

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-30128

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-26905

Open SourceCoalition ESS < 30%MEDIUM2022-05-10

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2022-26905

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-c92w-72c5-9x59

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

kube-state-metrics may expose secret content in metrics

Affected products

ProductStatusVendorPackageEcosystem
kube-state-metrics affected k8s.io k8s.io/kube-state-metrics
Upstream advisory

GHSA-c92w-72c5-9x59

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

kube-state-metrics may expose secret content in metrics

Affected products

ProductStatusVendorPackageEcosystem
kube-state-metrics affected k8s.io k8s.io/kube-state-metrics
Upstream advisory

DEBIAN-CVE-2022-26945

Open SourceCoalition ESS < 30%CRITICAL2022-05-25

DEBIAN-CVE-2022-26945

Affected products

ProductStatusVendorPackageEcosystem
golang-github-hashicorp-go-getter affected Debian:11 golang-github-hashicorp-go-getter
golang-github-hashicorp-go-getter affected Debian:12 golang-github-hashicorp-go-getter
Upstream advisory

GHSA-5rvp-q2j7-h9rj

Open SourceCoalition ESS < 30%HIGH2022-05-24

GHSA-5rvp-q2j7-h9rj

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
Upstream advisory

GO-2022-0434

Open SourceCoalition ESS < 30%HIGH2022-05-23

Panic during certificate parsing on Darwin in crypto/x509

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

DEBIAN-CVE-2022-30322

Open SourceCoalition ESS < 30%CRITICAL2022-05-25

DEBIAN-CVE-2022-30322

Affected products

ProductStatusVendorPackageEcosystem
golang-github-hashicorp-go-getter affected Debian:12 golang-github-hashicorp-go-getter
golang-github-hashicorp-go-getter affected Debian:11 golang-github-hashicorp-go-getter
Upstream advisory

DEBIAN-CVE-2022-30323

Open SourceCoalition ESS < 30%HIGH2022-05-25

DEBIAN-CVE-2022-30323

Affected products

ProductStatusVendorPackageEcosystem
golang-github-hashicorp-go-getter affected Debian:12 golang-github-hashicorp-go-getter
golang-github-hashicorp-go-getter affected Debian:11 golang-github-hashicorp-go-getter
Upstream advisory

GHSA-2v35-wj4r-rcmv

Open SourceCoalition ESS < 30%HIGH2022-05-24

Kubernetes Secrets Store CSI Driver plugins arbitrary file write

Affected products

ProductStatusVendorPackageEcosystem
Azure/secrets-store-csi-driver-provider-azure affected github.com github.com/Azure/secrets-store-csi-driver-provider-azure
GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp affected github.com github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp
hashicorp/vault-csi-provider affected github.com github.com/hashicorp/vault-csi-provider
Upstream advisory

GHSA-2v35-wj4r-rcmv

Open SourceCoalition ESS < 30%HIGH2022-05-24

Kubernetes Secrets Store CSI Driver plugins arbitrary file write

Affected products

ProductStatusVendorPackageEcosystem
Azure/secrets-store-csi-driver-provider-azure affected github.com github.com/Azure/secrets-store-csi-driver-provider-azure
GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp affected github.com github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp
hashicorp/vault-csi-provider affected github.com github.com/hashicorp/vault-csi-provider
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure-fips affected chainguard secrets-store-csi-driver-provider-azure-fips
vault-csi-provider affected chainguard vault-csi-provider
vault-csi-provider-fips affected chainguard vault-csi-provider-fips
Upstream advisory

CVE-2022-1919

GoogleCoalition ESS < 30%CRITICAL2022-05-31

Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1919

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-jwh2-ffg4-48xc

Open SourceCoalition ESS < 30%HIGH2022-05-24

Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client

Affected products

ProductStatusVendorPackageEcosystem
io.fabric8:kubernetes-client affected Maven io.fabric8:kubernetes-client
Upstream advisory

GHSA-jwh2-ffg4-48xc

Open SourceCoalition ESS < 30%HIGH2022-05-24

Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client

Affected products

ProductStatusVendorPackageEcosystem
io.fabric8:kubernetes-client affected Maven io.fabric8:kubernetes-client
Upstream advisory

GHSA-fh5w-p2j4-4p8x

Open SourceCoalition ESS < 30%HIGH2022-05-24

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

GHSA-fh5w-p2j4-4p8x

Open SourceCoalition ESS < 30%HIGH2022-05-24

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

GHSA-vc7h-cmp3-4hw5

Open SourceCoalition ESS < 30%HIGH2022-05-24

Istio vulnerable to denial of service

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

GHSA-vc7h-cmp3-4hw5

Open SourceCoalition ESS < 30%HIGH2022-05-24

Istio vulnerable to denial of service

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

GHSA-ccxh-j7hg-m5mr

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin

Affected products

ProductStatusVendorPackageEcosystem
io.fabric8.pipeline:kubernetes-pipeline-steps affected Maven io.fabric8.pipeline:kubernetes-pipeline-steps
Upstream advisory

GHSA-ccxh-j7hg-m5mr

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin

Affected products

ProductStatusVendorPackageEcosystem
io.fabric8.pipeline:kubernetes-pipeline-steps affected Maven io.fabric8.pipeline:kubernetes-pipeline-steps
Upstream advisory

GHSA-f46p-q6jh-226m

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin

Affected products

ProductStatusVendorPackageEcosystem
io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps affected Maven io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps
Upstream advisory

GHSA-f46p-q6jh-226m

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Incorrect Authorization in Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin

Affected products

ProductStatusVendorPackageEcosystem
io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps affected Maven io.fabric8.pipeline:kubernetes-pipeline-arquillian-steps
Upstream advisory

GHSA-pvmg-xgmx-9mxh

Open SourceCoalition ESS < 30%HIGH2022-05-07

Improper Input Validation in k8s.io/ingress-nginx

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

GHSA-pvmg-xgmx-9mxh

Open SourceCoalition ESS < 30%HIGH2022-05-07

Improper Input Validation in k8s.io/ingress-nginx

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller-1.9 affected chainguard ingress-nginx-controller-1.9
ingress-nginx-controller-fips affected chainguard ingress-nginx-controller-fips
ingress-nginx-controller-fips-1.9 affected chainguard ingress-nginx-controller-fips-1.9
Upstream advisory

CVE-2021-25745

Open SourceCoalition ESS < 30%HIGH2022-05-06

Improper Input Validation in k8s.io/ingress-nginx

CVEs:CVE-2021-25745

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

CVE-2021-25745

GoogleCoalition ESS < 30%HIGH2022-05-06

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials o...

CVEs:CVE-2021-25745

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected kubernetes
Upstream advisory

GHSA-rr6j-37cv-c7x7

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Missing Authorization in Jenkins Kubernetes Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

GHSA-rr6j-37cv-c7x7

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Missing Authorization in Jenkins Kubernetes Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

GHSA-g2r3-4g8q-h5rj

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Missing authorization in Jenkins Kubernetes Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

GHSA-g2r3-4g8q-h5rj

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Missing authorization in Jenkins Kubernetes Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

CVE-2022-1489

GoogleCoalition ESS < 30%HIGH2022-05-06

Out of bounds memory access in UI Shelf in Google Chrome on Chrome OS, Lacros prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific user interactions.

CVEs:CVE-2022-1489

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-8qh4-fghr-6fxg

GoogleCoalition ESS < 30%HIGH2022-05-24

Improper Limitation of a Pathname to a Restricted Directory in Jenkins Google OAuth Credentials Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-oauth-plugin affected Maven org.jenkins-ci.plugins:google-oauth-plugin
Upstream advisory

GHSA-8qh4-fghr-6fxg

GoogleCoalition ESS < 30%HIGH2022-05-24

Improper Limitation of a Pathname to a Restricted Directory in Jenkins Google OAuth Credentials Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-oauth-plugin affected Maven org.jenkins-ci.plugins:google-oauth-plugin
Upstream advisory

MGASA-2022-0211

Open SourceCoalition ESS < 30%CRITICAL2022-05-28

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

DSA-5148-1

Open SourceCoalition ESS < 30%2022-05-25

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

MGASA-2022-0188

Open SourceCoalition ESS < 30%CRITICAL2022-05-17

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

openSUSE-SU-2022:0133-1

Open SourceCoalition ESS < 30%CRITICAL2022-05-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

DSA-5134-1

Open SourceCoalition ESS < 30%2022-05-12

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-1641

GoogleCoalition ESS < 30%HIGH2022-05-11

Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interaction.

CVEs:CVE-2022-1641

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1639

GoogleCoalition ESS < 30%CRITICAL2022-05-11

Use after free in ANGLE in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1639

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1640

GoogleCoalition ESS < 30%CRITICAL2022-05-11

Use after free in Sharing in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1640

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1496

GoogleCoalition ESS < 30%HIGH2022-05-06

Use after free in File Manager in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.

CVEs:CVE-2022-1496

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-345p-pw5q-g98v

GoogleCoalition ESS < 30%MEDIUM2022-05-24

Jenkins Google Compute Engine Plugin does not verify SSH host keys when connecting agents created by the plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

GHSA-345p-pw5q-g98v

GoogleCoalition ESS < 30%MEDIUM2022-05-24

Jenkins Google Compute Engine Plugin does not verify SSH host keys when connecting agents created by the plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

GHSA-5hvr-3fcr-wx8c

Open SourceCoalition ESS < 30%HIGH2022-05-24

Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin

Affected products

ProductStatusVendorPackageEcosystem
io.alauda.jenkins.plugins:alauda-kubernetes-support affected Maven io.alauda.jenkins.plugins:alauda-kubernetes-support
Upstream advisory

GHSA-5hvr-3fcr-wx8c

Open SourceCoalition ESS < 30%HIGH2022-05-24

Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin

Affected products

ProductStatusVendorPackageEcosystem
io.alauda.jenkins.plugins:alauda-kubernetes-support affected Maven io.alauda.jenkins.plugins:alauda-kubernetes-support
Upstream advisory

CVE-2022-1636

GoogleCoalition ESS < 30%CRITICAL2022-05-11

Use after free in Performance APIs in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1636

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-7h24-4x4c-69mf

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Improper Authorization in Jenkins Alauda Kubernetes Suport Plugin

Affected products

ProductStatusVendorPackageEcosystem
io.alauda.jenkins.plugins:alauda-kubernetes-support affected Maven io.alauda.jenkins.plugins:alauda-kubernetes-support
Upstream advisory

GHSA-7h24-4x4c-69mf

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Improper Authorization in Jenkins Alauda Kubernetes Suport Plugin

Affected products

ProductStatusVendorPackageEcosystem
io.alauda.jenkins.plugins:alauda-kubernetes-support affected Maven io.alauda.jenkins.plugins:alauda-kubernetes-support
Upstream advisory

GHSA-7jf5-p556-75pr

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Jenkins Kubernetes CI/CD Plugin vulnerable to Credential Enumeration

Affected products

ProductStatusVendorPackageEcosystem
com.elasticbox.jenkins-ci.plugins:kubernetes-ci affected Maven com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Upstream advisory

GHSA-7jf5-p556-75pr

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Jenkins Kubernetes CI/CD Plugin vulnerable to Credential Enumeration

Affected products

ProductStatusVendorPackageEcosystem
com.elasticbox.jenkins-ci.plugins:kubernetes-ci affected Maven com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Upstream advisory

GHSA-hch9-6qrj-5f49

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Jenkins Kubernetes CI/CD Plugin vulnerable to Improper Authorization

Affected products

ProductStatusVendorPackageEcosystem
com.elasticbox.jenkins-ci.plugins:kubernetes-ci affected Maven com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Upstream advisory

GHSA-hch9-6qrj-5f49

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Jenkins Kubernetes CI/CD Plugin vulnerable to Improper Authorization

Affected products

ProductStatusVendorPackageEcosystem
com.elasticbox.jenkins-ci.plugins:kubernetes-ci affected Maven com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Upstream advisory

CVE-2022-1637

GoogleCoalition ESS < 30%MEDIUM2022-05-11

Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-1637

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1633

GoogleCoalition ESS < 30%HIGH2022-05-11

Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.

CVEs:CVE-2022-1633

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1634

GoogleCoalition ESS < 30%HIGH2022-05-11

Use after free in Browser UI in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who had convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific user interactions.

CVEs:CVE-2022-1634

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1635

GoogleCoalition ESS < 30%HIGH2022-05-11

Use after free in Permission Prompts in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.

CVEs:CVE-2022-1635

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-28x9-hc4p-9vh2

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Stored XSS vulnerability in android-lint Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jvnet.hudson.plugins:android-lint affected Maven org.jvnet.hudson.plugins:android-lint
Upstream advisory

GHSA-28x9-hc4p-9vh2

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Stored XSS vulnerability in android-lint Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jvnet.hudson.plugins:android-lint affected Maven org.jvnet.hudson.plugins:android-lint
Upstream advisory

CVE-2022-1638

GoogleCoalition ESS < 30%CRITICAL2022-05-11

Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1638

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-v98h-rv7j-hf6j

GoogleCoalition ESS < 30%MEDIUM2022-05-24

Jenkins Google Compute Engine Plugin Missing Authorization vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

GHSA-v98h-rv7j-hf6j

GoogleCoalition ESS < 30%MEDIUM2022-05-24

Jenkins Google Compute Engine Plugin Missing Authorization vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

GHSA-x24m-wr2f-p3vc

GoogleCoalition ESS < 30%MEDIUM2022-05-24

Jenkins Google Compute Engine Plugin Cross-Site Request Forgery vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

GHSA-x24m-wr2f-p3vc

GoogleCoalition ESS < 30%MEDIUM2022-05-24

Jenkins Google Compute Engine Plugin Cross-Site Request Forgery vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-compute-engine affected Maven org.jenkins-ci.plugins:google-compute-engine
Upstream advisory

GHSA-wwr4-79jv-297r

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Missing permission checks in Google Kubernetes Engine Jenkins Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-kubernetes-engine affected Maven org.jenkins-ci.plugins:google-kubernetes-engine
Upstream advisory

GHSA-wwr4-79jv-297r

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Missing permission checks in Google Kubernetes Engine Jenkins Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-kubernetes-engine affected Maven org.jenkins-ci.plugins:google-kubernetes-engine
Upstream advisory

GHSA-vx6r-w45x-q3h6

Open SourceCoalition ESS < 30%HIGH2022-05-24

Jenkins Kubernetes CI/CD Plugin vulnerable to Cross-Site Request Forgery

Affected products

ProductStatusVendorPackageEcosystem
com.elasticbox.jenkins-ci.plugins:kubernetes-ci affected Maven com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Upstream advisory

GHSA-vx6r-w45x-q3h6

Open SourceCoalition ESS < 30%HIGH2022-05-24

Jenkins Kubernetes CI/CD Plugin vulnerable to Cross-Site Request Forgery

Affected products

ProductStatusVendorPackageEcosystem
com.elasticbox.jenkins-ci.plugins:kubernetes-ci affected Maven com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Upstream advisory

GHSA-jjmc-4p83-pp26

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Logic error in Matrix SDK for Android

Affected products

ProductStatusVendorPackageEcosystem
org.matrix.android:matrix-android-sdk2 affected Maven org.matrix.android:matrix-android-sdk2
Upstream advisory

GHSA-jjmc-4p83-pp26

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Logic error in Matrix SDK for Android

Affected products

ProductStatusVendorPackageEcosystem
org.matrix.android:matrix-android-sdk2 affected Maven org.matrix.android:matrix-android-sdk2
Upstream advisory

CVE-2022-27875

Open SourceCoalition ESS < 30%MEDIUM2022-05-05

On F5 Access for Android 3.x versions prior to 3.0.8, a Task Hijacking vulnerability exists in the F5 Access for Android application, which may allow an attacker to steal sensitive user information. Note: Software versions which have reached End of Tec...

CVEs:CVE-2022-27875

Affected products

ProductStatusVendorPackageEcosystem
access_for_android affected f5
Upstream advisory

CVE-2021-36912

GoogleCoalition ESS < 30%CRITICAL2022-05-06

Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role.

CVEs:CVE-2021-36912

Affected products

ProductStatusVendorPackageEcosystem
google-news-sitemap affected google-news-sitemap_project
Upstream advisory

GHSA-75c9-jrh4-79mc

Open SourceCoalition ESS < 30%HIGH2022-05-24

Code injection in `saved_model_cli` in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-75c9-jrh4-79mc

Open SourceCoalition ESS < 30%HIGH2022-05-24

Code injection in `saved_model_cli` in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29216

Open SourceCoalition ESS < 30%HIGH2022-05-20

Code injection in `saved_model_cli` in TensorFlow

CVEs:CVE-2022-29216

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29216

Open SourceCoalition ESS < 30%HIGH2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shell. This code path was maintained...

CVEs:CVE-2022-29216

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29216

Open SourceCoalition ESS < 30%HIGH2022-05-20

Code injection in `saved_model_cli` in TensorFlow

CVEs:CVE-2022-29216

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f4rr-5m7v-wxcw

Open SourceCoalition ESS < 30%HIGH2022-05-24

Type confusion leading to `CHECK`-failure based denial of service in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f4rr-5m7v-wxcw

Open SourceCoalition ESS < 30%HIGH2022-05-24

Type confusion leading to `CHECK`-failure based denial of service in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29209

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the macros that TensorFlow uses for writing assertions (e.g., `CHECK_LT`, `CHECK_GT`, etc.) have an incorrect logic when comparing `size_t` an...

CVEs:CVE-2022-29209

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29209

Open SourceCoalition ESS < 30%HIGH2022-05-20

Type confusion leading to `CHECK`-failure based denial of service in TensorFlow

CVEs:CVE-2022-29209

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29209

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Type confusion leading to `CHECK`-failure based denial of service in TensorFlow

CVEs:CVE-2022-29209

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2r2f-g8mw-9gvr

Open SourceCoalition ESS < 30%HIGH2022-05-24

Segfault and OOB write due to incomplete validation in `EditDistance` in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2r2f-g8mw-9gvr

Open SourceCoalition ESS < 30%HIGH2022-05-24

Segfault and OOB write due to incomplete validation in `EditDistance` in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29208

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.EditDistance` has incomplete validation. Users can pass negative values to cause a segmentation fault based ...

CVEs:CVE-2022-29208

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29208

Open SourceCoalition ESS < 30%HIGH2022-05-20

Segfault and OOB write due to incomplete validation in `EditDistance` in TensorFlow

CVEs:CVE-2022-29208

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29208

Open SourceCoalition ESS < 30%HIGH2022-05-20

Segfault and OOB write due to incomplete validation in `EditDistance` in TensorFlow

CVEs:CVE-2022-29208

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g5q2-cxgq-h2rw

GoogleCoalition ESS < 30%HIGH2022-05-24

Information leak in Gerrit

Affected products

ProductStatusVendorPackageEcosystem
com.google.gerrit:gerrit-plugin-api affected Maven com.google.gerrit:gerrit-plugin-api
Upstream advisory

GHSA-g5q2-cxgq-h2rw

GoogleCoalition ESS < 30%HIGH2022-05-24

Information leak in Gerrit

Affected products

ProductStatusVendorPackageEcosystem
com.google.gerrit:gerrit-plugin-api affected Maven com.google.gerrit:gerrit-plugin-api
Upstream advisory

GHSA-fv25-wrff-wf86

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `GetSessionTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fv25-wrff-wf86

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `GetSessionTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29191

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.GetSessionTensor` does not fully validate the input arguments. This results in a `CHECK`-failure which can b...

CVEs:CVE-2022-29191

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29191

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation causes denial of service via `GetSessionTensor`

CVEs:CVE-2022-29191

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29191

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation causes denial of service via `GetSessionTensor`

CVEs:CVE-2022-29191

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hx9q-2mx4-m4pg

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `Conv3DBackpropFilterV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hx9q-2mx4-m4pg

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `Conv3DBackpropFilterV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29204

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.UnsortedSegmentJoin` does not fully validate the input arguments. This results in a `CHECK`-failure which ca...

CVEs:CVE-2022-29204

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29204

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation causes denial of service via `Conv3DBackpropFilterV2`

CVEs:CVE-2022-29204

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29204

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation causes denial of service via `Conv3DBackpropFilterV2`

CVEs:CVE-2022-29204

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xw4c-9434-3f7p

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Jenkins Google Kubernetes Engine Plugin vulnerable to Exposure of Resource to Wrong Sphere

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-kubernetes-engine affected Maven org.jenkins-ci.plugins:google-kubernetes-engine
Upstream advisory

GHSA-xw4c-9434-3f7p

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Jenkins Google Kubernetes Engine Plugin vulnerable to Exposure of Resource to Wrong Sphere

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-kubernetes-engine affected Maven org.jenkins-ci.plugins:google-kubernetes-engine
Upstream advisory

GHSA-h2wq-prv9-2f56

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation crashes `QuantizeAndDequantizeV4Grad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h2wq-prv9-2f56

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation crashes `QuantizeAndDequantizeV4Grad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29192

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` does not fully validate the input arguments. This results in a `CHECK`-failure ...

CVEs:CVE-2022-29192

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29192

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation crashes `QuantizeAndDequantizeV4Grad`

CVEs:CVE-2022-29192

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29192

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation crashes `QuantizeAndDequantizeV4Grad`

CVEs:CVE-2022-29192

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rc9w-5c64-9vqq

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Missing validation results in undefined behavior in `SparseTensorDenseAdd

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rc9w-5c64-9vqq

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Missing validation results in undefined behavior in `SparseTensorDenseAdd

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29206

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation results in undefined behavior in `SparseTensorDenseAdd

CVEs:CVE-2022-29206

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29206

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.SparseTensorDenseAdd` does not fully validate the input arguments. In this case, a reference gets bound to a...

CVEs:CVE-2022-29206

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29206

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation results in undefined behavior in `SparseTensorDenseAdd

CVEs:CVE-2022-29206

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jjm6-4vf7-cjh4

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Integer overflow in `SpaceToBatchND`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jjm6-4vf7-cjh4

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Integer overflow in `SpaceToBatchND`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pqhm-4wvf-2jg8

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Missing validation results in undefined behavior in `QuantizedConv2D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pqhm-4wvf-2jg8

Open SourceCoalition ESS < 30%MEDIUM2022-05-24

Missing validation results in undefined behavior in `QuantizedConv2D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29201

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation results in undefined behavior in `QuantizedConv2D`

CVEs:CVE-2022-29201

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29201

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.QuantizedConv2D` does not fully validate the input arguments. In this case, references get bound to `nullptr...

CVEs:CVE-2022-29201

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29201

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation results in undefined behavior in `QuantizedConv2D`

CVEs:CVE-2022-29201

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29203

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

Integer overflow in `SpaceToBatchND`

CVEs:CVE-2022-29203

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29203

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Integer overflow in `SpaceToBatchND`

CVEs:CVE-2022-29203

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29203

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.SpaceToBatchND` (in all backends such as XLA and handwritten kernels) is vulnerable to an integer overflow: ...

CVEs:CVE-2022-29203

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-h5g4-ppwx-48q2

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `DeleteSessionTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h5g4-ppwx-48q2

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `DeleteSessionTensor`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29194

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation causes denial of service via `DeleteSessionTensor`

CVEs:CVE-2022-29194

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29194

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation causes denial of service via `DeleteSessionTensor`

CVEs:CVE-2022-29194

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29194

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.DeleteSessionTensor` does not fully validate the input arguments. This results in a `CHECK`-failure which ca...

CVEs:CVE-2022-29194

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-5wpj-c6f7-24x8

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Undefined behavior when users supply invalid resource handles

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5wpj-c6f7-24x8

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Undefined behavior when users supply invalid resource handles

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-54ch-gjq5-4976

Open SourceCoalition ESS < 30%HIGH2022-05-24

Segfault due to missing support for quantized types

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-54ch-gjq5-4976

Open SourceCoalition ESS < 30%HIGH2022-05-24

Segfault due to missing support for quantized types

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2vv3-56qg-g2cf

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `LSTMBlockCell`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2vv3-56qg-g2cf

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `LSTMBlockCell`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p9rc-rmr5-529j

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `LoadAndRemapMatrix`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-p9rc-rmr5-529j

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `LoadAndRemapMatrix`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mg66-qvc5-rm93

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mg66-qvc5-rm93

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hrg5-737c-2p56

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `UnsortedSegmentJoin`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hrg5-737c-2p56

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `UnsortedSegmentJoin`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5v77-j66x-4c4g

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `Conv3DBackpropFilterV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5v77-j66x-4c4g

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `Conv3DBackpropFilterV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h48f-q7rw-hvr7

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `StagePeek`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h48f-q7rw-hvr7

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes denial of service via `StagePeek`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2p9q-h29j-3f5v

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes `TensorSummaryV2` to crash

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-2p9q-h29j-3f5v

Open SourceCoalition ESS < 30%HIGH2022-05-24

Missing validation causes `TensorSummaryV2` to crash

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29193

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.TensorSummaryV2` does not fully validate the input arguments. This results in a `CHECK`-failure which can be...

CVEs:CVE-2022-29193

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29193

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation causes `TensorSummaryV2` to crash

CVEs:CVE-2022-29193

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29193

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation causes `TensorSummaryV2` to crash

CVEs:CVE-2022-29193

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29195

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation causes denial of service via `StagePeek`

CVEs:CVE-2022-29195

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29195

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.StagePeek` does not fully validate the input arguments. This results in a `CHECK`-failure which can be used ...

CVEs:CVE-2022-29195

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29195

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation causes denial of service via `StagePeek`

CVEs:CVE-2022-29195

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29196

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation causes denial of service via `Conv3DBackpropFilterV2`

CVEs:CVE-2022-29196

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29196

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.Conv3DBackpropFilterV2` does not fully validate the input arguments. This results in a `CHECK`-failure which...

CVEs:CVE-2022-29196

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29196

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation causes denial of service via `Conv3DBackpropFilterV2`

CVEs:CVE-2022-29196

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29197

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation causes denial of service via `UnsortedSegmentJoin`

CVEs:CVE-2022-29197

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29197

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.UnsortedSegmentJoin` does not fully validate the input arguments. This results in a `CHECK`-failure which ca...

CVEs:CVE-2022-29197

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29197

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation causes denial of service via `UnsortedSegmentJoin`

CVEs:CVE-2022-29197

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29198

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.SparseTensorToCSRSparseMatrix` does not fully validate the input arguments. This results in a `CHECK`-failur...

CVEs:CVE-2022-29198

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29198

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`

CVEs:CVE-2022-29198

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29198

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`

CVEs:CVE-2022-29198

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29199

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation causes denial of service via `LoadAndRemapMatrix`

CVEs:CVE-2022-29199

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29199

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation causes denial of service via `LoadAndRemapMatrix`

CVEs:CVE-2022-29199

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29199

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.LoadAndRemapMatrix does not fully validate the input arguments. This results in a `CHECK`-failure which can ...

CVEs:CVE-2022-29199

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29200

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Missing validation causes denial of service via `LSTMBlockCell`

CVEs:CVE-2022-29200

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29200

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.LSTMBlockCell` does not fully validate the input arguments. This results in a `CHECK`-failure which can be u...

CVEs:CVE-2022-29200

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29200

Open SourceCoalition ESS < 30%HIGH2022-05-20

Missing validation causes denial of service via `LSTMBlockCell`

CVEs:CVE-2022-29200

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29205

Open SourceCoalition ESS < 30%HIGH2022-05-20

Segfault due to missing support for quantized types

CVEs:CVE-2022-29205

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29205

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, there is a potential for segfault / denial of service in TensorFlow by calling `tf.compat.v1.*` ops which don't yet have support for quantized...

CVEs:CVE-2022-29205

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29205

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Segfault due to missing support for quantized types

CVEs:CVE-2022-29205

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29207

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

Undefined behavior when users supply invalid resource handles

CVEs:CVE-2022-29207

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29207

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, multiple TensorFlow operations misbehave in eager mode when the resource handle provided to them is invalid. In graph mode, it would have been...

CVEs:CVE-2022-29207

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29207

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Undefined behavior when users supply invalid resource handles

CVEs:CVE-2022-29207

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8wwm-6264-x792

Open SourceCoalition ESS < 30%HIGH2022-05-24

Core dump when loading TFLite models with quantization in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8wwm-6264-x792

Open SourceCoalition ESS < 30%HIGH2022-05-24

Core dump when loading TFLite models with quantization in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cwpm-f78v-7m5c

Open SourceCoalition ESS < 30%HIGH2022-05-24

Denial of service in `tf.ragged.constant` due to lack of validation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cwpm-f78v-7m5c

Open SourceCoalition ESS < 30%HIGH2022-05-24

Denial of service in `tf.ragged.constant` due to lack of validation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29212

Open SourceCoalition ESS < 30%HIGH2022-05-20

Core dump when loading TFLite models with quantization in TensorFlow

CVEs:CVE-2022-29212

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29212

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, certain TFLite models that were created using TFLite model converter would crash when loaded in the TFLite interpreter. The culprit is that du...

CVEs:CVE-2022-29212

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29212

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Core dump when loading TFLite models with quantization in TensorFlow

CVEs:CVE-2022-29212

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29202

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Denial of service in `tf.ragged.constant` due to lack of validation

CVEs:CVE-2022-29202

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29202

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.ragged.constant` does not fully validate the input arguments. This results in a denial of service by consuming all a...

CVEs:CVE-2022-29202

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29202

Open SourceCoalition ESS < 30%HIGH2022-05-20

Denial of service in `tf.ragged.constant` due to lack of validation

CVEs:CVE-2022-29202

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xrp2-fhq4-4q3w

Open SourceCoalition ESS < 30%HIGH2022-05-24

Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xrp2-fhq4-4q3w

Open SourceCoalition ESS < 30%HIGH2022-05-24

Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29211

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.histogram_fixed_width` is vulnerable to a crash when the values array contain `Not a Number` (`NaN`) elements. The i...

CVEs:CVE-2022-29211

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29211

Open SourceCoalition ESS < 30%HIGH2022-05-20

Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow

CVEs:CVE-2022-29211

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29211

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Segfault if `tf.histogram_fixed_width` is called with NaN values in TensorFlow

CVEs:CVE-2022-29211

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5889-7v45-q28m

Open SourceCoalition ESS < 30%HIGH2022-05-24

Incomplete validation in signal ops leads to crashes in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5889-7v45-q28m

Open SourceCoalition ESS < 30%HIGH2022-05-24

Incomplete validation in signal ops leads to crashes in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29213

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Incomplete validation in signal ops leads to crashes in TensorFlow

CVEs:CVE-2022-29213

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29213

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the `tf.compat.v1.signal.rfft2d` and `tf.compat.v1.signal.rfft3d` lack input validation and under certain condition can result in crashes (due...

CVEs:CVE-2022-29213

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-29213

Open SourceCoalition ESS < 30%HIGH2022-05-20

Incomplete validation in signal ops leads to crashes in TensorFlow

CVEs:CVE-2022-29213

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-20010

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2022-20010

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-hc2f-7r5r-r2hg

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Heap buffer overflow due to incorrect hash function in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hc2f-7r5r-r2hg

Open SourceCoalition ESS < 30%CRITICAL2022-05-24

Heap buffer overflow due to incorrect hash function in TensorFlow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29210

Open SourceCoalition ESS < 30%MEDIUM2022-05-20

Heap buffer overflow due to incorrect hash function in TensorFlow

CVEs:CVE-2022-29210

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29210

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

Heap buffer overflow due to incorrect hash function in TensorFlow

CVEs:CVE-2022-29210

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-29210

Open SourceCoalition ESS < 30%CRITICAL2022-05-20

TensorFlow is an open source platform for machine learning. In version 2.8.0, the `TensorKey` hash function used total estimated `AllocatedBytes()`, which (a) is an estimate per tensor, and (b) is a very poor hash function for constants (e.g. `int32_t`...

CVEs:CVE-2022-29210

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-20113

Open SourceCoalition ESS < 30%HIGH2022-05-03

In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. ...

CVEs:CVE-2022-20113

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-218337596

GoogleCoalition ESS < 30%2022-05-01

ASB-A-218337596

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2021-22556

GoogleCoalition ESS < 30%CRITICAL2022-05-03

The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache invalidation operations on pages that they don’t own, allowing them to control kernel memory from userspace. We recommend upgrading...

CVEs:CVE-2021-22556

Affected products

ProductStatusVendorPackageEcosystem
fuchsia affected google
Upstream advisory

PUB-A-190503256

GoogleCoalition ESS < 30%2022-05-01

PUB-A-190503256

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-204909309

GoogleCoalition ESS < 30%2022-05-01

PUB-A-204909309

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom-opensource/data-kernel affected platform platform/vendor/qcom-opensource/data-kernel
Upstream advisory

CVE-2022-28781

Open SourceCoalition ESS < 30%HIGH2022-05-03

Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.

CVEs:CVE-2022-28781

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20006

Open SourceCoalition ESS < 30%HIGH2022-05-10

In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's under the lockscreen due to a race condition. This could lead to local escalation of privilege if a Guest user is enabled, with no ad...

CVEs:CVE-2022-20006

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20103

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In aee daemon, there is a possible information disclosure due to symbolic link following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; ...

CVEs:CVE-2022-20103

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20105

Open SourceCoalition ESS < 30%HIGH2022-05-03

In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV0333046...

CVEs:CVE-2022-20105

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2022-20106

Open SourceCoalition ESS < 30%HIGH2022-05-03

In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460...

CVEs:CVE-2022-20106

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2022-20108

Open SourceCoalition ESS < 30%HIGH2022-05-03

In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV0333...

CVEs:CVE-2022-20108

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

DEBIAN-CVE-2022-20011

Open SourceCoalition ESS < 30%MEDIUM2022-05-10

DEBIAN-CVE-2022-20011

Affected products

ProductStatusVendorPackageEcosystem
android-platform-frameworks-base affected Debian:11 android-platform-frameworks-base
android-platform-frameworks-base affected Debian:12 android-platform-frameworks-base
android-platform-frameworks-base affected Debian:13 android-platform-frameworks-base
android-platform-frameworks-base affected Debian:14 android-platform-frameworks-base
Upstream advisory

CVE-2022-20011

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2022-20011

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20101

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; ...

CVEs:CVE-2022-20101

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20098

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0641901...

CVEs:CVE-2022-20098

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39738

Open SourceCoalition ESS < 30%HIGH2022-05-10

In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2021-39738

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20085

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0630887...

CVEs:CVE-2022-20085

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-28784

Open SourceCoalition ESS < 30%HIGH2022-05-03

Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.

CVEs:CVE-2022-28784

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20107

Open SourceCoalition ESS < 30%HIGH2022-05-03

In subtitle service, there is a possible application crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330673; Issue ID:...

CVEs:CVE-2022-20107

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2022-20114

Open SourceCoalition ESS < 30%HIGH2022-05-03

In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privile...

CVEs:CVE-2022-20114

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20116

Open SourceCoalition ESS < 30%HIGH2022-05-03

In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2022-20116

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20111

Open SourceCoalition ESS < 30%HIGH2022-05-03

In ion, there is a possible use after free due to incorrect error handling. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366069; Issue ...

CVEs:CVE-2022-20111

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-0882

GoogleCoalition ESS < 30%MEDIUM2022-05-03

A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater.

CVEs:CVE-2022-0882

Affected products

ProductStatusVendorPackageEcosystem
fuchsia affected google
Upstream advisory

CVE-2021-39700

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In the policies of adbd.te, there was a logic error which caused the CTS Listening Ports Test to report invalid results. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2021-39700

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20087

Open SourceCoalition ESS < 30%HIGH2022-05-03

In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06477970; Issue ID: ...

CVEs:CVE-2022-20087

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20094

Open SourceCoalition ESS < 30%HIGH2022-05-03

In imgsensor, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479763; I...

CVEs:CVE-2022-20094

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20095

Open SourceCoalition ESS < 30%HIGH2022-05-03

In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479763; Issu...

CVEs:CVE-2022-20095

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20096

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06419003; Issue ID: ...

CVEs:CVE-2022-20096

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21743

Open SourceCoalition ESS < 30%HIGH2022-05-03

In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06371108; Issue ID: A...

CVEs:CVE-2022-21743

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20089

Open SourceCoalition ESS < 30%HIGH2022-05-03

In aee driver, there is a possible memory corruption due to active debug code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06240397; Issue ID: ...

CVEs:CVE-2022-20089

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20104

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In aee daemon, there is a possible information disclosure due to improper access control. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS064...

CVEs:CVE-2022-20104

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20092

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS063660...

CVEs:CVE-2022-20092

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20088

Open SourceCoalition ESS < 30%HIGH2022-05-03

In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0620920...

CVEs:CVE-2022-20088

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20099

Open SourceCoalition ESS < 30%HIGH2022-05-03

In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; ...

CVEs:CVE-2022-20099

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20109

Open SourceCoalition ESS < 30%HIGH2022-05-03

In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS063999...

CVEs:CVE-2022-20109

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-223071150

GoogleCoalition ESS < 30%HIGH2022-05-01

ASB-A-223071150

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-223072269

GoogleCoalition ESS < 30%HIGH2022-05-01

ASB-A-223072269

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20102

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0629644...

CVEs:CVE-2022-20102

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20100

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0638394...

CVEs:CVE-2022-20100

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20119

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2022-20119

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-213170715

GoogleCoalition ESS < 30%MEDIUM2022-05-01

PUB-A-213170715

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-28782

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package before completion of Setup wizard. The patch blocks entry point of the vulnerability.

CVEs:CVE-2022-28782

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20115

Open SourceCoalition ESS < 30%HIGH2022-05-03

In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due to a missing permission check. This could lead to local information disclosure with User execution priv...

CVEs:CVE-2022-20115

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20084

Open SourceCoalition ESS < 30%HIGH2022-05-03

In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2022-20084

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20093

Open SourceCoalition ESS < 30%HIGH2022-05-03

In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20093

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20121

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In getNodeValue of USCCDMPlugin.java, there is a possible disclosure of ICCID due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2022-20121

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-223071148

GoogleCoalition ESS < 30%NONE2022-05-01

ASB-A-223071148

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-212573046

GoogleCoalition ESS < 30%MEDIUM2022-05-01

PUB-A-212573046

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-28783

Open SourceCoalition ESS < 30%HIGH2022-05-03

Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

CVEs:CVE-2022-28783

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-28785

Open SourceCoalition ESS < 30%HIGH2022-05-03

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVEs:CVE-2022-28785

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-28786

Open SourceCoalition ESS < 30%HIGH2022-05-03

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVEs:CVE-2022-28786

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-28787

Open SourceCoalition ESS < 30%HIGH2022-05-03

Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVEs:CVE-2022-28787

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-28788

Open SourceCoalition ESS < 30%HIGH2022-05-03

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVEs:CVE-2022-28788

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20112

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileg...

CVEs:CVE-2022-20112

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-28780

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.

CVEs:CVE-2022-28780

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20118

Open SourceCoalition ESS < 30%HIGH2022-05-03

In ion_ioctl and related functions of ion.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2022-20118

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-205707793

GoogleCoalition ESS < 30%HIGH2022-05-01

PUB-A-205707793

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20090

Open SourceCoalition ESS < 30%HIGH2022-05-03

In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209197; Issue ID: ALPS...

CVEs:CVE-2022-20090

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20091

Open SourceCoalition ESS < 30%HIGH2022-05-03

In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS...

CVEs:CVE-2022-20091

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20110

Open SourceCoalition ESS < 30%HIGH2022-05-03

In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS...

CVEs:CVE-2022-20110

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20097

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; ...

CVEs:CVE-2022-20097

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20117

Open SourceCoalition ESS < 30%MEDIUM2022-05-03

In (TBD) of (TBD), there is a possible way to decrypt local data encrypted by the GSC due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2022-20117

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-217475903

GoogleCoalition ESS < 30%MEDIUM2022-05-01

PUB-A-217475903

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-gj46-mfx7-2vwx

Open SourceEPSS <= 49%MEDIUM2022-05-17

GHSA-gj46-mfx7-2vwx

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
firefox affected wolfi firefox
firefox affected chainguard firefox
Upstream advisory

GHSA-64x6-q8pq-xjmg

Open SourceEPSS <= 49%MEDIUM2022-05-17

GHSA-64x6-q8pq-xjmg

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
firefox affected chainguard firefox
firefox affected wolfi firefox
Upstream advisory

GHSA-5p4h-3377-7w67

Open SourceEPSS <= 49%HIGH2022-05-13

golang.org/x/net/html NULL Pointer Dereference vulnerability

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-5p4h-3377-7w67

Open SourceEPSS <= 49%HIGH2022-05-13

golang.org/x/net/html NULL Pointer Dereference vulnerability

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-fcf9-6fv2-fc5v

Open SourceEPSS <= 49%HIGH2022-05-13

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-fcf9-6fv2-fc5v

Open SourceEPSS <= 49%HIGH2022-05-13

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-2wp2-chmh-r934

Open SourceEPSS <= 49%HIGH2022-05-13

golang.org/x/net/html NULL Pointer Dereference vulnerability

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-2wp2-chmh-r934

Open SourceEPSS <= 49%HIGH2022-05-13

golang.org/x/net/html NULL Pointer Dereference vulnerability

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-mv93-wvcp-7m7r

Open SourceEPSS <= 49%HIGH2022-05-13

golang.org/x/net/html Improper Validation of Array Index vulnerability

Affected products

ProductStatusVendorPackageEcosystem
hey affected chainguard hey
hey affected wolfi hey
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-mv93-wvcp-7m7r

Open SourceEPSS <= 49%HIGH2022-05-13

golang.org/x/net/html Improper Validation of Array Index vulnerability

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-4r78-hx75-jjj2

Open SourceEPSS <= 49%HIGH2022-05-13

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

Affected products

ProductStatusVendorPackageEcosystem
hey affected wolfi hey
hey affected chainguard hey
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-4r78-hx75-jjj2

Open SourceEPSS <= 49%HIGH2022-05-13

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-g4fh-wrxx-g83w

Open SourceEPSS <= 49%2022-05-17

GHSA-g4fh-wrxx-g83w

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
firefox affected chainguard firefox
firefox affected wolfi firefox
Upstream advisory

GHSA-2jq6-ffph-p4h8

Open SourceEPSS <= 49%HIGH2022-05-13

Kubernetes arbitrary file overwrite

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-2jq6-ffph-p4h8

Open SourceEPSS <= 49%HIGH2022-05-13

Kubernetes arbitrary file overwrite

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-x23w-pq92-wqgx

Open SourceEPSS <= 49%NONE2022-05-02

GHSA-x23w-pq92-wqgx

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

GHSA-7w66-j2r2-vm3p

Open SourceEPSS <= 49%CRITICAL2022-05-13

GHSA-7w66-j2r2-vm3p

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-1.19 affected chainguard kubernetes-1.19
kubernetes-1.20 affected chainguard kubernetes-1.20
kubernetes-1.21 affected chainguard kubernetes-1.21
kubernetes-1.22 affected chainguard kubernetes-1.22
kubernetes-1.23 affected chainguard kubernetes-1.23
kubernetes-1.24 affected wolfi kubernetes-1.24
kubernetes-1.24 affected chainguard kubernetes-1.24
kubernetes-1.25 affected chainguard kubernetes-1.25
kubernetes-1.25 affected wolfi kubernetes-1.25
kubernetes-1.26 affected chainguard kubernetes-1.26
kubernetes-1.26 affected wolfi kubernetes-1.26
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.30 affected chainguard kubernetes-1.30
kubernetes-1.30 affected wolfi kubernetes-1.30
kubernetes-1.31 affected wolfi kubernetes-1.31
kubernetes-1.31 affected chainguard kubernetes-1.31
kubernetes-1.32 affected wolfi kubernetes-1.32
kubernetes-1.32 affected chainguard kubernetes-1.32
Upstream advisory

GHSA-rp82-xvg3-727c

GoogleEPSS <= 49%MEDIUM2022-05-14

Jenkins Google Login Plugin Session Fixation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

GHSA-rp82-xvg3-727c

GoogleEPSS <= 49%MEDIUM2022-05-14

Jenkins Google Login Plugin Session Fixation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

GHSA-2h9c-34v6-3qmr

Open SourceEPSS <= 49%LOW2022-05-13

Kubernetes in OpenShift3 Access Control Misconfiguration

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-2h9c-34v6-3qmr

Open SourceEPSS <= 49%LOW2022-05-13

Kubernetes in OpenShift3 Access Control Misconfiguration

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-1.19 affected chainguard kubernetes-1.19
kubernetes-1.20 affected chainguard kubernetes-1.20
kubernetes-1.21 affected chainguard kubernetes-1.21
kubernetes-1.22 affected chainguard kubernetes-1.22
kubernetes-1.23 affected chainguard kubernetes-1.23
kubernetes-1.24 affected chainguard kubernetes-1.24
kubernetes-1.24 affected wolfi kubernetes-1.24
kubernetes-1.25 affected wolfi kubernetes-1.25
kubernetes-1.25 affected chainguard kubernetes-1.25
kubernetes-1.26 affected wolfi kubernetes-1.26
kubernetes-1.26 affected chainguard kubernetes-1.26
kubernetes-1.27 affected chainguard kubernetes-1.27
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.30 affected chainguard kubernetes-1.30
kubernetes-1.30 affected wolfi kubernetes-1.30
kubernetes-1.31 affected wolfi kubernetes-1.31
kubernetes-1.31 affected chainguard kubernetes-1.31
kubernetes-1.32 affected wolfi kubernetes-1.32
kubernetes-1.32 affected chainguard kubernetes-1.32
Upstream advisory

GHSA-fqg2-c97r-rqcj

Open SourceEPSS <= 49%HIGH2022-05-13

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

GHSA-fqg2-c97r-rqcj

Open SourceEPSS <= 49%HIGH2022-05-13

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

GO-2021-0154

Open SourceEPSS <= 49%2022-05-25

Man-in-the-middle attack with SessionTicketsDisabled in crypto/tls

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GHSA-pcm9-fp55-563v

GoogleEPSS <= 49%HIGH2022-05-17

OWASP HTML Sanitizer allows redirecting to an arbitrary URL when JavaScript is disabled

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer affected Maven com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
Upstream advisory

GHSA-pcm9-fp55-563v

GoogleEPSS <= 49%HIGH2022-05-17

OWASP HTML Sanitizer allows redirecting to an arbitrary URL when JavaScript is disabled

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer affected Maven com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
Upstream advisory

GHSA-4gjj-r7w8-42cq

Open SourceEPSS <= 49%HIGH2022-05-13

Jerome Gamez Firebase Admin SDK for PHP Incorrect Access Control vulnerability

Affected products

ProductStatusVendorPackageEcosystem
firebase-php affected kreait kreait/firebase-php
firebase-php affected kreait kreait/firebase-php
Upstream advisory

GHSA-4gjj-r7w8-42cq

Open SourceEPSS <= 49%HIGH2022-05-13

Jerome Gamez Firebase Admin SDK for PHP Incorrect Access Control vulnerability

Affected products

ProductStatusVendorPackageEcosystem
firebase-php affected kreait kreait/firebase-php
Upstream advisory

GO-2022-0171

Open SourceEPSS <= 49%2022-05-24

Mishandled trust preferences for root certificates on Darwin in crypto/x509

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

GHSA-v67x-gpg7-mwv3

Open SourceEPSS <= 49%HIGH2022-05-14

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

GHSA-v67x-gpg7-mwv3

Open SourceEPSS <= 49%HIGH2022-05-14

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

GHSA-7wj7-vv48-8jpg

Open SourceEPSS <= 49%NONE2022-05-13

GHSA-7wj7-vv48-8jpg

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

GHSA-p3x5-5xpx-9phm

Open SourceEPSS <= 49%HIGH2022-05-24

Kubernetes ingress exposes sensitive information

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
Upstream advisory

GHSA-p3x5-5xpx-9phm

Open SourceEPSS <= 49%HIGH2022-05-24

Kubernetes ingress exposes sensitive information

Affected products

ProductStatusVendorPackageEcosystem
ingress-nginx affected k8s.io k8s.io/ingress-nginx
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller-1.9 affected chainguard ingress-nginx-controller-1.9
ingress-nginx-controller-fips affected chainguard ingress-nginx-controller-fips
ingress-nginx-controller-fips-1.9 affected chainguard ingress-nginx-controller-fips-1.9
Upstream advisory

GHSA-vm2p-f5j4-mj6g

Open SourceEPSS <= 49%CRITICAL2022-05-14

Auth0 angular-jwt misinterprets allowlist as regex

Affected products

ProductStatusVendorPackageEcosystem
angular-jwt affected npm angular-jwt
Upstream advisory

GHSA-vm2p-f5j4-mj6g

Open SourceEPSS <= 49%CRITICAL2022-05-14

Auth0 angular-jwt misinterprets allowlist as regex

Affected products

ProductStatusVendorPackageEcosystem
angular-jwt affected npm angular-jwt
Upstream advisory

GHSA-j279-cx9m-jv3w

GoogleEPSS <= 49%MEDIUM2022-05-14

Jenkins Google Login Plugin Open Redirect vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

GHSA-j279-cx9m-jv3w

GoogleEPSS <= 49%MEDIUM2022-05-14

Jenkins Google Login Plugin Open Redirect vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

GHSA-88fh-8979-q2rr

Open SourceEPSS <= 49%CRITICAL2022-05-14

Angular Redactor XSS Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
angular-redactor affected npm angular-redactor
Upstream advisory

GHSA-88fh-8979-q2rr

Open SourceEPSS <= 49%CRITICAL2022-05-14

Angular Redactor XSS Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
angular-redactor affected npm angular-redactor
Upstream advisory

GHSA-pwpc-hqq2-hx2x

GoogleEPSS <= 49%CRITICAL2022-05-14

Cross-site Scripting in wicket-jquery-ui

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent affected Maven com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent
Upstream advisory

GHSA-pwpc-hqq2-hx2x

GoogleEPSS <= 49%CRITICAL2022-05-14

Cross-site Scripting in wicket-jquery-ui

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent affected Maven com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent
Upstream advisory

GHSA-3vcx-w94h-68vg

Open SourceEPSS <= 49%HIGH2022-05-14

XXE vulnerability in Jenkins Android Lint Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jvnet.hudson.plugins:android-lint affected Maven org.jvnet.hudson.plugins:android-lint
Upstream advisory

GHSA-3vcx-w94h-68vg

Open SourceEPSS <= 49%HIGH2022-05-14

XXE vulnerability in Jenkins Android Lint Plugin

Affected products

ProductStatusVendorPackageEcosystem
org.jvnet.hudson.plugins:android-lint affected Maven org.jvnet.hudson.plugins:android-lint
Upstream advisory

GHSA-pjv3-rh6v-2pj8

GoogleEPSS <= 49%CRITICAL2022-05-14

Cross-site Scripting in wicket-jquery-ui

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent affected Maven com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent
Upstream advisory

GHSA-pjv3-rh6v-2pj8

GoogleEPSS <= 49%CRITICAL2022-05-14

Cross-site Scripting in wicket-jquery-ui

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent affected Maven com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent
Upstream advisory

GHSA-h5rj-jwq2-3jp4

Open SourceEPSS <= 49%HIGH2022-05-13

GHSA-h5rj-jwq2-3jp4

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

GHSA-6pcv-qqx4-mxm3

Open SourceEPSS <= 49%CRITICAL2022-05-13

Minikube RCE via DNS Rebinding

Affected products

ProductStatusVendorPackageEcosystem
minikube affected k8s.io k8s.io/minikube
Upstream advisory

GHSA-6pcv-qqx4-mxm3

Open SourceEPSS <= 49%CRITICAL2022-05-13

Minikube RCE via DNS Rebinding

Affected products

ProductStatusVendorPackageEcosystem
minikube affected k8s.io k8s.io/minikube
Upstream advisory

GHSA-rvx4-gg8w-qw24

Open SourceEPSS <= 49%MEDIUM2022-05-13

Jenkins Google Play Android Publisher Plugin allows attacker to obtain credential IDs

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-play-android-publisher affected Maven org.jenkins-ci.plugins:google-play-android-publisher
Upstream advisory

GHSA-rvx4-gg8w-qw24

Open SourceEPSS <= 49%MEDIUM2022-05-13

Jenkins Google Play Android Publisher Plugin allows attacker to obtain credential IDs

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-play-android-publisher affected Maven org.jenkins-ci.plugins:google-play-android-publisher
Upstream advisory

GHSA-h6cr-c397-vq66

Open SourceEPSS <= 49%CRITICAL2022-05-17

GHSA-h6cr-c397-vq66

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

GHSA-8ph5-wgc5-5jj9

Open SourceEPSS <= 49%MEDIUM2022-05-13

GHSA-8ph5-wgc5-5jj9

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
firefox affected chainguard firefox
firefox affected wolfi firefox
Upstream advisory

GHSA-fm24-8vcm-jw5m

Open SourceEPSS <= 49%MEDIUM2022-05-17

GHSA-fm24-8vcm-jw5m

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

GHSA-mw6j-hh29-h379

Open SourceAll remainingHIGH2022-05-25

`CHECK` failure in depthwise ops via overflows

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mw6j-hh29-h379

Open SourceAll remainingHIGH2022-05-25

`CHECK` failure in depthwise ops via overflows

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

ALBA-2022:1856

GoogleAll remainingHIGH2022-05-10

llvm-toolset:rhel8 bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
clang affected AlmaLinux:8 clang
clang-analyzer affected AlmaLinux:8 clang-analyzer
clang-devel affected AlmaLinux:8 clang-devel
clang-libs affected AlmaLinux:8 clang-libs
clang-resource-filesystem affected AlmaLinux:8 clang-resource-filesystem
clang-tools-extra affected AlmaLinux:8 clang-tools-extra
compiler-rt affected AlmaLinux:8 compiler-rt
git-clang-format affected AlmaLinux:8 git-clang-format
libomp affected AlmaLinux:8 libomp
libomp-devel affected AlmaLinux:8 libomp-devel
libomp-test affected AlmaLinux:8 libomp-test
lld affected AlmaLinux:8 lld
lldb affected AlmaLinux:8 lldb
lldb-devel affected AlmaLinux:8 lldb-devel
lld-devel affected AlmaLinux:8 lld-devel
lld-libs affected AlmaLinux:8 lld-libs
llvm affected AlmaLinux:8 llvm
llvm-devel affected AlmaLinux:8 llvm-devel
llvm-doc affected AlmaLinux:8 llvm-doc
llvm-googletest affected AlmaLinux:8 llvm-googletest
llvm-libs affected AlmaLinux:8 llvm-libs
llvm-static affected AlmaLinux:8 llvm-static
llvm-test affected AlmaLinux:8 llvm-test
llvm-toolset affected AlmaLinux:8 llvm-toolset
python3-clang affected AlmaLinux:8 python3-clang
python3-lit affected AlmaLinux:8 python3-lit
python3-lldb affected AlmaLinux:8 python3-lldb
Upstream advisory

ALBA-2022:1846

Open SourceAll remainingHIGH2022-05-10

rsyslog bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
rsyslog affected AlmaLinux:8 rsyslog
rsyslog-crypto affected AlmaLinux:8 rsyslog-crypto
rsyslog-doc affected AlmaLinux:8 rsyslog-doc
rsyslog-elasticsearch affected AlmaLinux:8 rsyslog-elasticsearch
rsyslog-gnutls affected AlmaLinux:8 rsyslog-gnutls
rsyslog-gssapi affected AlmaLinux:8 rsyslog-gssapi
rsyslog-kafka affected AlmaLinux:8 rsyslog-kafka
rsyslog-mmaudit affected AlmaLinux:8 rsyslog-mmaudit
rsyslog-mmfields affected AlmaLinux:8 rsyslog-mmfields
rsyslog-mmjsonparse affected AlmaLinux:8 rsyslog-mmjsonparse
rsyslog-mmkubernetes affected AlmaLinux:8 rsyslog-mmkubernetes
rsyslog-mmnormalize affected AlmaLinux:8 rsyslog-mmnormalize
rsyslog-mmsnmptrapd affected AlmaLinux:8 rsyslog-mmsnmptrapd
rsyslog-mysql affected AlmaLinux:8 rsyslog-mysql
rsyslog-omamqp1 affected AlmaLinux:8 rsyslog-omamqp1
rsyslog-openssl affected AlmaLinux:8 rsyslog-openssl
rsyslog-pgsql affected AlmaLinux:8 rsyslog-pgsql
rsyslog-relp affected AlmaLinux:8 rsyslog-relp
rsyslog-snmp affected AlmaLinux:8 rsyslog-snmp
rsyslog-udpspoof affected AlmaLinux:8 rsyslog-udpspoof
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.