CVE-2022-26134
CVEs:CVE-2022-26134
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 7 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
CVEs:CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3....
CVEs:CVE-2022-26134
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| confluence_data_center | affected | atlassian | — | — |
| confluence_server | affected | atlassian | — | — |
Security update for SUSE Manager Client Tools
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-prometheus-alertmanager | affected | SUSE:Manager Client Tools 12 | golang-github-prometheus-alertmanager | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP5 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:HPE Helion OpenStack 8 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:OpenStack Cloud 8 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:OpenStack Cloud 9 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:OpenStack Cloud Crowbar 8 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:OpenStack Cloud Crowbar 9 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Manager Client Tools 12 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP3 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server for SAP Applications 12 SP4 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 12 SP3-LTSS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 12 SP3-BCL | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 12 SP4-LTSS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 12 SP5 | golang-github-prometheus-node_exporter | — |
| golang-github-QubitProducts-exporter_exporter | affected | SUSE:Manager Client Tools 12 | golang-github-QubitProducts-exporter_exporter | — |
| grafana | affected | SUSE:Manager Client Tools 12 | grafana | — |
| mgr-cfg | affected | SUSE:Manager Client Tools 12 | mgr-cfg | — |
| mgr-custom-info | affected | SUSE:Manager Client Tools 12 | mgr-custom-info | — |
| mgr-daemon | affected | SUSE:Manager Client Tools 12 | mgr-daemon | — |
| mgr-osad | affected | SUSE:Manager Client Tools 12 | mgr-osad | — |
| mgr-push | affected | SUSE:Manager Client Tools 12 | mgr-push | — |
| mgr-virtualization | affected | SUSE:Manager Client Tools 12 | mgr-virtualization | — |
| prometheus-blackbox_exporter | affected | SUSE:Manager Client Tools 12 | prometheus-blackbox_exporter | — |
| prometheus-postgres_exporter | affected | SUSE:Manager Client Tools 12 | prometheus-postgres_exporter | — |
| python-hwdata | affected | SUSE:Manager Client Tools 12 | python-hwdata | — |
| rhnlib | affected | SUSE:Manager Client Tools 12 | rhnlib | — |
| spacecmd | affected | SUSE:Manager Client Tools 12 | spacecmd | — |
| spacewalk-client-tools | affected | SUSE:Manager Client Tools 12 | spacewalk-client-tools | — |
| spacewalk-koan | affected | SUSE:Manager Client Tools 12 | spacewalk-koan | — |
| spacewalk-oscap | affected | SUSE:Manager Client Tools 12 | spacewalk-oscap | — |
| spacewalk-remote-utils | affected | SUSE:Manager Client Tools 12 | spacewalk-remote-utils | — |
| supportutils-plugin-salt | affected | SUSE:Manager Client Tools 12 | supportutils-plugin-salt | — |
| supportutils-plugin-susemanager-client | affected | SUSE:Manager Client Tools 12 | supportutils-plugin-susemanager-client | — |
| suseRegisterInfo | affected | SUSE:Manager Client Tools 12 | suseRegisterInfo | — |
| uyuni-common-libs | affected | SUSE:Manager Client Tools 12 | uyuni-common-libs | — |
Security update for google-gson
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-gson | affected | openSUSE:Leap 15.3 | google-gson | — |
| google-gson | affected | SUSE:Linux Enterprise Module for Development Tools 15 SP3 | google-gson | — |
| google-gson | affected | SUSE:Manager Proxy 4.1 | google-gson | — |
| google-gson | affected | SUSE:Linux Enterprise Module for Development Tools 15 SP4 | google-gson | — |
| google-gson | affected | SUSE:Manager Server 4.1 | google-gson | — |
| google-gson | affected | openSUSE:Leap 15.4 | google-gson | — |
| google-gson | affected | SUSE:Manager Server Module 4.2 | google-gson | — |
| google-gson | affected | SUSE:Manager Server Module 4.3 | google-gson | — |
| google-gson | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS | google-gson | — |
| google-gson | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | google-gson | — |
| google-gson | affected | SUSE:Linux Enterprise Server 15 SP2-BCL | google-gson | — |
| google-gson | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | google-gson | — |
| google-gson | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | google-gson | — |
| google-gson | affected | SUSE:Manager Retail Branch Server 4.1 | google-gson | — |
| google-gson | affected | SUSE:Enterprise Storage 7 | google-gson | — |
PUB-A-213172369
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-224859358
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Security update for SUSE Manager Server 4.1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-lusitaniae-apache_exporter | affected | SUSE:Manager Server Module 4.1 | golang-github-lusitaniae-apache_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Manager Server Module 4.1 | golang-github-prometheus-node_exporter | — |
| golang-github-QubitProducts-exporter_exporter | affected | SUSE:Manager Server Module 4.1 | golang-github-QubitProducts-exporter_exporter | — |
| patterns-suse-manager | affected | SUSE:Manager Server Module 4.1 | patterns-suse-manager | — |
| postgresql-jdbc | affected | SUSE:Manager Server Module 4.1 | postgresql-jdbc | — |
| prometheus-exporters-formula | affected | SUSE:Manager Server Module 4.1 | prometheus-exporters-formula | — |
| prometheus-formula | affected | SUSE:Manager Server Module 4.1 | prometheus-formula | — |
| py27-compat-salt | affected | SUSE:Manager Server Module 4.1 | py27-compat-salt | — |
| spacecmd | affected | SUSE:Manager Server Module 4.1 | spacecmd | — |
| spacewalk-backend | affected | SUSE:Manager Server Module 4.1 | spacewalk-backend | — |
| spacewalk-java | affected | SUSE:Manager Server Module 4.1 | spacewalk-java | — |
| spacewalk-setup | affected | SUSE:Manager Server Module 4.1 | spacewalk-setup | — |
| spacewalk-utils | affected | SUSE:Manager Server Module 4.1 | spacewalk-utils | — |
| spacewalk-web | affected | SUSE:Manager Server Module 4.1 | spacewalk-web | — |
| subscription-matcher | affected | SUSE:Manager Server Module 4.1 | subscription-matcher | — |
| susemanager | affected | SUSE:Manager Server Module 4.1 | susemanager | — |
| susemanager-doc-indexes | affected | SUSE:Manager Server Module 4.1 | susemanager-doc-indexes | — |
| susemanager-docs_en | affected | SUSE:Manager Server Module 4.1 | susemanager-docs_en | — |
| susemanager-schema | affected | SUSE:Manager Server Module 4.1 | susemanager-schema | — |
| susemanager-sls | affected | SUSE:Manager Server Module 4.1 | susemanager-sls | — |
CVEs:CVE-2022-20568
In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andro...
CVEs:CVE-2022-20568
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-209480901
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
PUB-A-209481085
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
Moderate: go-toolset:rhel8 security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
CVEs:CVE-2022-20140
In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2022-20140
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2022-20130
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20130
Fix CVE(s): CVE-2022-0391
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.5 | affected | TuxCare:Ubuntu:16.04 | idle-python3.5 | — |
| libpython3.5 | affected | TuxCare:Ubuntu:16.04 | libpython3.5 | — |
| libpython3.5-dev | affected | TuxCare:Ubuntu:16.04 | libpython3.5-dev | — |
| libpython3.5-minimal | affected | TuxCare:Ubuntu:16.04 | libpython3.5-minimal | — |
| libpython3.5-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython3.5-stdlib | — |
| libpython3.5-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython3.5-testsuite | — |
| python3.5 | affected | TuxCare:Ubuntu:16.04 | python3.5 | — |
| python3.5-dev | affected | TuxCare:Ubuntu:16.04 | python3.5-dev | — |
| python3.5-doc | affected | TuxCare:Ubuntu:16.04 | python3.5-doc | — |
| python3.5-examples | affected | TuxCare:Ubuntu:16.04 | python3.5-examples | — |
| python3.5-minimal | affected | TuxCare:Ubuntu:16.04 | python3.5-minimal | — |
| python3.5-venv | affected | TuxCare:Ubuntu:16.04 | python3.5-venv | — |
Recommended update for SUSE Manager Proxy 4.1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-lusitaniae-apache_exporter | affected | SUSE:Manager Proxy Module 4.1 | golang-github-lusitaniae-apache_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Manager Proxy Module 4.1 | golang-github-prometheus-node_exporter | — |
| golang-github-QubitProducts-exporter_exporter | affected | SUSE:Manager Proxy Module 4.1 | golang-github-QubitProducts-exporter_exporter | — |
| patterns-suse-manager | affected | SUSE:Manager Proxy Module 4.1 | patterns-suse-manager | — |
| spacecmd | affected | SUSE:Manager Proxy Module 4.1 | spacecmd | — |
| spacewalk-backend | affected | SUSE:Manager Proxy Module 4.1 | spacewalk-backend | — |
| spacewalk-web | affected | SUSE:Manager Proxy Module 4.1 | spacewalk-web | — |
Security update for node_exporter
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Manager Proxy 4.1 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Manager Retail Branch Server 4.1 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Manager Server 4.1 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Enterprise Storage 6 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Enterprise Storage 7 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | openSUSE:Leap 15.3 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | openSUSE:Leap 15.4 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 15 SP2-BCL | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Module for Basesystem 15 SP3 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Module for Basesystem 15 SP4 | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 15 SP1-BCL | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | golang-github-prometheus-node_exporter | — |
Security update for golang-github-prometheus-alertmanager
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-prometheus-alertmanager | affected | SUSE:Manager Proxy Module 4.3 | golang-github-prometheus-alertmanager | — |
| golang-github-prometheus-alertmanager | affected | SUSE:Enterprise Storage 6 | golang-github-prometheus-alertmanager | — |
| golang-github-prometheus-alertmanager | affected | SUSE:Manager Client Tools 15 | golang-github-prometheus-alertmanager | — |
| golang-github-prometheus-alertmanager | affected | SUSE:Manager Proxy Module 4.1 | golang-github-prometheus-alertmanager | — |
| golang-github-prometheus-alertmanager | affected | openSUSE:Leap 15.3 | golang-github-prometheus-alertmanager | — |
| golang-github-prometheus-alertmanager | affected | openSUSE:Leap 15.4 | golang-github-prometheus-alertmanager | — |
| golang-github-prometheus-alertmanager | affected | SUSE:Manager Proxy Module 4.2 | golang-github-prometheus-alertmanager | — |
Security update for golang-github-prometheus-node_exporter
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise High Performance Computing 15-ESPOS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise High Performance Computing 15-LTSS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server 15-LTSS | golang-github-prometheus-node_exporter | — |
| golang-github-prometheus-node_exporter | affected | SUSE:Linux Enterprise Server for SAP Applications 15 | golang-github-prometheus-node_exporter | — |
DEBIAN-CVE-2022-1996
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-emicklei-go-restful | affected | Debian:11 | golang-github-emicklei-go-restful | — |
| golang-github-emicklei-go-restful | affected | Debian:12 | golang-github-emicklei-go-restful | — |
| golang-github-emicklei-go-restful | affected | Debian:13 | golang-github-emicklei-go-restful | — |
| golang-github-emicklei-go-restful | affected | Debian:14 | golang-github-emicklei-go-restful | — |
Indefinite hang with large buffers on Windows in crypto/rand
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.
CVEs:CVE-2022-30634
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cloud_insights_telegraf_agent | affected | netapp | — | — |
| go | affected | golang | — | — |
CVEs:CVE-2022-30634
CVEs:CVE-2022-29804
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
CVEs:CVE-2022-29804
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
PUB-A-215814262
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
PUB-A-189614572
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
protobuf security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openEuler:22.03-LTS | protobuf | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
golang.org/x/text/language Out-of-bounds Read vulnerability
CVEs:CVE-2021-38561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/text | affected | golang.org | golang.org/x/text | — |
golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service...
CVEs:CVE-2021-38561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| text | affected | golang | — | — |
CVEs:CVE-2022-2162
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page.
CVEs:CVE-2022-2162
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
ASB-A-218836280
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
ASB-A-162326603
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
ASB-A-222023189
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-194694600
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-127973231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-224080927
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-213173524
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.
CVEs:CVE-2022-30580
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
CVEs:CVE-2022-30580
CVEs:CVE-2022-20173
Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A
CVEs:CVE-2022-20173
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-207116951
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In kbase_mem_alias of mali_kbase_mem_linux.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2022-20186
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20186
PUB-A-215001024
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Security update for tensorflow2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| bazel3.7 | affected | openSUSE:Leap 15.3 | bazel3.7 | — |
| bazel3.7 | affected | SUSE:Package Hub 15 SP3 | bazel3.7 | — |
| bazel-skylib1.0.3 | affected | SUSE:Package Hub 15 SP3 | bazel-skylib1.0.3 | — |
| bazel-skylib1.0.3 | affected | openSUSE:Leap 15.3 | bazel-skylib1.0.3 | — |
| tensorflow2 | affected | SUSE:Package Hub 15 SP3 | tensorflow2 | — |
| tensorflow2 | affected | openSUSE:Leap 15.3 | tensorflow2 | — |
| tensorflow2_2_6_0-gnu-hpc | affected | openSUSE:Leap 15.3 | tensorflow2_2_6_0-gnu-hpc | — |
| tensorflow2_2_6_0-gnu-hpc | affected | SUSE:Package Hub 15 SP3 | tensorflow2_2_6_0-gnu-hpc | — |
| tensorflow2_2_6_0-gnu-openmpi2-hpc | affected | SUSE:Package Hub 15 SP3 | tensorflow2_2_6_0-gnu-openmpi2-hpc | — |
| tensorflow2_2_6_0-gnu-openmpi2-hpc | affected | openSUSE:Leap 15.3 | tensorflow2_2_6_0-gnu-openmpi2-hpc | — |
| tensorflow2-lite | affected | SUSE:Package Hub 15 SP3 | tensorflow2-lite | — |
| tensorflow2-lite | affected | openSUSE:Leap 15.3 | tensorflow2-lite | — |
ASB-A-220261709
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-223966861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-225469258
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-182986620
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User i...
CVEs:CVE-2022-20126
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20126
In createFromParcel of GeofenceHardwareRequestParcelable.java, there is a possible arbitrary code execution due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2022-20142
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20142
CVEs:CVE-2022-20138
In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to local escalation of privilege with n...
CVEs:CVE-2022-20138
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-182388481
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
ASB-A-112551163
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including 1...
CVEs:CVE-2022-1707
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_tag_manager | affected | gtm4wp | — | — |
CVEs:CVE-2022-1707
CVEs:CVE-2022-20145
In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges ...
CVEs:CVE-2022-20145
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2022-20127
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20127
CVEs:CVE-2022-20210
The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in internal objects based on the received data. A bug in the parsing code could be used by an attacker to remo...
CVEs:CVE-2022-20210
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-228868888
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Node DOS by way of memory exhaustion through ExecSync request in CRI-O
CVEs:CVE-2022-1708
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cri-o/cri-o | affected | github.com | github.com/cri-o/cri-o | — |
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O a...
CVEs:CVE-2022-1708
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cri-o | affected | kubernetes | — | — |
| enterprise_linux | affected | redhat | — | — |
| fedora | affected | fedoraproject | — | — |
| openshift_container_platform | affected | redhat | — | — |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2022-22021
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2022-22021
golang.org/x/sys/unix has Incorrect privilege reporting in syscall
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ctop | affected | chainguard | ctop | — |
| ctop | affected | wolfi | ctop | — |
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| grpcurl | affected | chainguard | grpcurl | — |
| grpcurl | affected | wolfi | grpcurl | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| kind | affected | chainguard | kind | — |
| kind | affected | wolfi | kind | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| x/sys | affected | golang.org | golang.org/x/sys | — |
golang.org/x/sys/unix has Incorrect privilege reporting in syscall
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/sys | affected | golang.org | golang.org/x/sys | — |
CVE-2022-29526 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-29526 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-29526 affecting package golang for versions less than 1.22.7-2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2022-29526
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
CVEs:CVE-2022-30192
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-30192
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2022-33639
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-33639
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2022-33638
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-33638
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
Command injection in google-it
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-it | affected | npm | google-it | — |
Command injection in google-it
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-it | affected | npm | google-it | — |
Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved...
CVEs:CVE-2021-34083
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-it | affected | google-it_project | — | — |
Command injection in google-it
CVEs:CVE-2021-34083
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-it | affected | npm | google-it | — |
Command injection in google-it
CVEs:CVE-2021-34083
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-it | affected | npm | google-it | — |
CVEs:CVE-2022-33680
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-33680
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2022-2156
Use after free in Core in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2156
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
CVEs:CVE-2022-2010
Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2022-2010
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Ill-formed headers may lead to unexpected behavior in Istio
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cert-manager-istio-csr | affected | wolfi | cert-manager-istio-csr | — |
| cert-manager-istio-csr | affected | chainguard | cert-manager-istio-csr | — |
| cert-manager-istio-csr-fips | affected | chainguard | cert-manager-istio-csr-fips | — |
| istio | affected | istio.io | istio.io/istio | — |
| istio-cni-1.21 | affected | wolfi | istio-cni-1.21 | — |
| istio-cni-1.21 | affected | chainguard | istio-cni-1.21 | — |
| istio-cni-1.22 | affected | chainguard | istio-cni-1.22 | — |
| istio-cni-1.22 | affected | wolfi | istio-cni-1.22 | — |
| istio-fips-1.21 | affected | chainguard | istio-fips-1.21 | — |
| istio-operator-1.20 | affected | chainguard | istio-operator-1.20 | — |
| istio-operator-1.20 | affected | wolfi | istio-operator-1.20 | — |
| istio-operator-1.21 | affected | chainguard | istio-operator-1.21 | — |
| istio-operator-1.21 | affected | wolfi | istio-operator-1.21 | — |
| istio-operator-1.22 | affected | wolfi | istio-operator-1.22 | — |
| istio-operator-1.22 | affected | chainguard | istio-operator-1.22 | — |
| istio-pilot-agent-1.21 | affected | wolfi | istio-pilot-agent-1.21 | — |
| istio-pilot-agent-1.21 | affected | chainguard | istio-pilot-agent-1.21 | — |
| istio-pilot-agent-1.22 | affected | chainguard | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22 | affected | wolfi | istio-pilot-agent-1.22 | — |
| istio-pilot-discovery-1.21 | affected | wolfi | istio-pilot-discovery-1.21 | — |
| istio-pilot-discovery-1.21 | affected | chainguard | istio-pilot-discovery-1.21 | — |
| istio-pilot-discovery-1.22 | affected | chainguard | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22 | affected | wolfi | istio-pilot-discovery-1.22 | — |
| kgateway-2.3 | affected | chainguard | kgateway-2.3 | — |
| kgateway-2.4 | affected | chainguard | kgateway-2.4 | — |
| kgateway-fips-2.3 | affected | chainguard | kgateway-fips-2.3 | — |
| kgateway-fips-2.4 | affected | chainguard | kgateway-fips-2.4 | — |
Ill-formed headers may lead to unexpected behavior in Istio
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio.io | istio.io/istio | — |
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most lik...
CVEs:CVE-2022-31045
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio | — | — |
Ill-formed headers may lead to unexpected behavior in Istio
CVEs:CVE-2022-31045
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio | affected | istio.io | istio.io/istio | — |
The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~/public/frontend.php` file which allowed attackers with...
CVEs:CVE-2022-1961
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_tag_manager | affected | gtm4wp | — | — |
CVEs:CVE-2022-1961
GHSA-xcrq-6j7j-784j
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf-c | affected | chainguard | protobuf-c | — |
| protobuf-c | affected | wolfi | protobuf-c | — |
ALPINE-CVE-2022-33070
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf-c | affected | Alpine:v3.17 | protobuf-c | — |
| protobuf-c | affected | Alpine:v3.18 | protobuf-c | — |
| protobuf-c | affected | Alpine:v3.19 | protobuf-c | — |
| protobuf-c | affected | Alpine:v3.20 | protobuf-c | — |
| protobuf-c | affected | Alpine:v3.21 | protobuf-c | — |
| protobuf-c | affected | Alpine:v3.22 | protobuf-c | — |
| protobuf-c | affected | Alpine:v3.23 | protobuf-c | — |
| protobuf-c | affected | Alpine:v3.24 | protobuf-c | — |
CVE-2022-33070 affecting package protobuf-c for versions less than 1.4.0-2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf-c | affected | Azure Linux:2 | protobuf-c | — |
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
CVEs:CVE-2022-33070
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| fedora | affected | fedoraproject | — | — |
| protobuf-c | affected | protobuf-c_project | — | — |
CVEs:CVE-2022-33070
DEBIAN-CVE-2022-33070
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf-c | affected | Debian:11 | protobuf-c | — |
| protobuf-c | affected | Debian:12 | protobuf-c | — |
| protobuf-c | affected | Debian:13 | protobuf-c | — |
| protobuf-c | affected | Debian:14 | protobuf-c | — |
Updated golang packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:8 | golang | — |
CVEs:CVE-2022-30629
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
CVEs:CVE-2022-30629
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.
CVEs:CVE-2021-40897
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| split-html-to-chars | affected | split-html-to-chars_project | — | — |
CVEs:CVE-2021-40897
Open redirect in caddy
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| caddyserver/caddy | affected | github.com | github.com/caddyserver/caddy | — |
| caddyserver/caddy/v2 | affected | github.com | github.com/caddyserver/caddy/v2 | — |
Open redirect in caddy
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| caddy | affected | chainguard | caddy | — |
| caddy | affected | wolfi | caddy | — |
| caddy-fips | affected | chainguard | caddy-fips | — |
| caddyserver/caddy | affected | github.com | github.com/caddyserver/caddy | — |
| caddyserver/caddy/v2 | affected | github.com | github.com/caddyserver/caddy/v2 | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
CVEs:CVE-2022-2011
Use after free in ANGLE in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2158
Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2158
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| extra_packages_for_enterprise_linux | affected | fedoraproject | — | — |
| fedora | affected | fedoraproject | — | — |
Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2008
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2008
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2022-1853
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1853
Use after free in Interest groups in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2157
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2157
Use after free in WebApp Provider in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who convinced the user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
CVEs:CVE-2022-2161
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2161
CVEs:CVE-2022-2007
Use after free in WebGPU in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2007
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-1873
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1873
Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” fi...
CVEs:CVE-2021-25736
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | kubernetes | — | — |
Kube-proxy may unintentionally forward traffic
CVEs:CVE-2021-25736
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kube-proxy may unintentionally forward traffic
CVEs:CVE-2021-25736
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
CVEs:CVE-2022-1869
Type Confusion in V8 in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1869
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-20123
In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2022-20123
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In nci_proc_rf_management_ntf of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2022-20131
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20131
CVEs:CVE-2022-1855
Use after free in Messaging in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1855
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1874
Insufficient policy enforcement in Safe Browsing in Google Chrome on Mac prior to 102.0.5005.61 allowed a remote attacker to bypass downloads protection policy via a crafted HTML page.
CVEs:CVE-2022-1874
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in ANGLE in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1854
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1854
CVEs:CVE-2022-2165
Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVEs:CVE-2022-2165
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Insufficient validation of untrusted input in Data Transfer in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass same origin policy via a crafted clipboard content.
CVEs:CVE-2022-1867
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1867
Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass file system restrictions via a crafted HTML page.
CVEs:CVE-2022-1857
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1857
Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions.
CVEs:CVE-2022-1866
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1866
CVEs:CVE-2022-1859
Use after free in Performance Manager in Google Chrome prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-2163
Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction.
CVEs:CVE-2022-2163
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| extra_packages_for_enterprise_linux | affected | fedoraproject | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-20209
In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2022-20209
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-1860
Use after free in UI Foundations in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user interactions.
CVEs:CVE-2022-1860
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1861
Use after free in Sharing in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific user interaction.
CVEs:CVE-2022-1861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform an out of bounds memory read via specific user interaction.
CVEs:CVE-2022-1858
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1858
CVEs:CVE-2022-1875
Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-1875
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1772
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, ...
CVEs:CVE-2022-1772
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_places_reviews | affected | google_places_reviews_project | — | — |
Heap buffer overflow in DevTools in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-1876
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1876
In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interacti...
CVEs:CVE-2022-20202
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20202
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted...
CVEs:CVE-2022-2160
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| Chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2160
CVEs:CVE-2022-2164
Inappropriate implementation in Extensions API in Google Chrome prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted HTML page.
CVEs:CVE-2022-2164
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was broken and allowed traffic from any IP. The problem has been patched in v1.6.0. As a workaround, those who...
CVEs:CVE-2022-31055
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kctf | affected | — | — |
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks w...
CVEs:CVE-2022-1321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_authenticator | affected | miniorange | — | — |
CVEs:CVE-2022-1321
CVEs:CVE-2022-1870
Use after free in App Service in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
CVEs:CVE-2022-1870
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1994
The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disal...
CVEs:CVE-2022-1994
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| login_with_otp_over_sms\,_email\,_whatsapp_and_google_authenticator | affected | miniorange | — | — |
CVEs:CVE-2021-25088
The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is di...
CVEs:CVE-2021-25088
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_xml_sitemaps | affected | google_xml_sitemaps_project | — | — |
Use after free in User Education in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension or specific user interaction.
CVEs:CVE-2022-1856
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1856
Inappropriate implementation in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page.
CVEs:CVE-2022-1868
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1868
Inappropriate implementation in Extensions in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass profile restrictions via a crafted HTML page.
CVEs:CVE-2022-1862
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1862
Use after free in Tab Groups in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.
CVEs:CVE-2022-1863
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1863
CVEs:CVE-2022-1864
Use after free in WebApp Installs in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.
CVEs:CVE-2022-1864
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in Bookmarks in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.
CVEs:CVE-2022-1865
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1865
Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page.
CVEs:CVE-2022-1871
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1871
Insufficient policy enforcement in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.
CVEs:CVE-2022-1872
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-1872
The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored Cross-Site Scripting due to the l...
CVEs:CVE-2022-1829
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| inline_google_maps | affected | inline_google_maps_project | — | — |
CVEs:CVE-2022-1829
Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A
CVEs:CVE-2022-20171
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20171
Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A
CVEs:CVE-2022-20191
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20191
PUB-A-209324757
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-215565667
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-21757
In WIFI Firmware, there is a possible system crash due to a missing count check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06468894; Issue ...
CVEs:CVE-2022-21757
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A
CVEs:CVE-2022-20160
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20160
Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A
CVEs:CVE-2022-20164
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20164
CVEs:CVE-2022-20167
Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A
CVEs:CVE-2022-20167
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20170
Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A
CVEs:CVE-2022-20170
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-204891956
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-204956204
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-209421931
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-210083655
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Product: AndroidVersions: Android kernelAndroid ID: A-208744915References: N/A
CVEs:CVE-2022-20190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20190
PUB-A-208744915
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-29453
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.
CVEs:CVE-2022-29453
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| api_key_for_google_maps | affected | ayecode | — | — |
CVEs:CVE-2022-0875
The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks
CVEs:CVE-2022-0875
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_authenticator | affected | miniorange | — | — |
PUB-A-196011539
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-20175
Product: AndroidVersions: Android kernelAndroid ID: A-209252491References: N/A
CVEs:CVE-2022-20175
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Product: AndroidVersions: Android kernelAndroid ID: A-209906686References: N/A
CVEs:CVE-2022-20177
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20177
Product: AndroidVersions: Android kernelAndroid ID: A-209153114References: N/A
CVEs:CVE-2022-20184
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20184
CVEs:CVE-2022-20188
Product: AndroidVersions: Android kernelAndroid ID: A-207254598References: N/A
CVEs:CVE-2022-20188
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-197154898
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-207254598
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-209153114
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-209252491
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-209906686
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Product: AndroidVersions: Android kernelAndroid ID: A-210594998References: N/A
CVEs:CVE-2022-20168
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20168
CVEs:CVE-2022-20181
Product: AndroidVersions: Android kernelAndroid ID: A-210936609References: N/A
CVEs:CVE-2022-20181
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-210594998
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-210936609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Product: AndroidVersions: Android kernelAndroid ID: A-211685939References: N/A
CVEs:CVE-2022-20149
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20149
Product: AndroidVersions: Android kernelAndroid ID: A-210712565References: N/A
CVEs:CVE-2022-20151
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20151
CVEs:CVE-2022-20169
Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A
CVEs:CVE-2022-20169
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20179
Product: AndroidVersions: Android kernelAndroid ID: A-211683760References: N/A
CVEs:CVE-2022-20179
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-210712565
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-211162353
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-211683760
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-211685939
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In WIFI Firmware, there is a possible memory corruption due to a use after free. This could lead to remote escalation of privilege, when devices are connecting to the attacker-controllable Wi-Fi hotspot, with no additional execution privileges needed. ...
CVEs:CVE-2022-21745
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21745
ASB-A-228972609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-222023207
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
DEBIAN-CVE-2022-31022
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-blevesearch-bleve | affected | Debian:11 | golang-github-blevesearch-bleve | — |
CVEs:CVE-2022-30711
Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-30711
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-30713
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30713
Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-30710
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30710
CVEs:CVE-2022-30722
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.
CVEs:CVE-2022-30722
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-30712
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30712
PUB-A-197614484
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-30716
Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.
CVEs:CVE-2022-30716
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-222644279
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
CVEs:CVE-2022-30709
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30709
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
CVEs:CVE-2022-30719
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30719
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
CVEs:CVE-2022-30720
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30720
CVEs:CVE-2022-30721
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
CVEs:CVE-2022-30721
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30717
Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.
CVEs:CVE-2022-30717
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20135
In writeToParcel of GateKeeperResponse.java, there is a possible parcel format mismatch. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2022-20135
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.
CVEs:CVE-2022-30715
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30715
CVEs:CVE-2022-20132
In lg_probe and related functions of hid-lg.c and other USB HID files, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure if a malicious USB HID device were plugged in, with no addit...
CVEs:CVE-2022-20132
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-188677105
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-20195
In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: A...
CVEs:CVE-2022-20195
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In deletePackageX of DeletePackageHelper.java, there is a possible way for a Guest user to reset pre-loaded applications for other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileg...
CVEs:CVE-2022-20124
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20124
PUB-A-209481020
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
| vendor/opensource/camera-kernel | affected | platform | platform/vendor/opensource/camera-kernel | — |
CVEs:CVE-2022-20133
In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed f...
CVEs:CVE-2022-20133
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In multiple functions of AvatarPhotoController.java, there is a possible access to content owned by system content providers due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User...
CVEs:CVE-2022-20144
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20144
In asn1_p256_int of crypto/asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2022-20162
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20162
PUB-A-223492713
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-21759
In power service, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419106; ...
CVEs:CVE-2022-21759
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20125
In GBoard, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to local escalation of privilege if an attacker has physical access to the device, with no additional execution privileges needed. User inte...
CVEs:CVE-2022-20125
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-194402515
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| vendor/unbundled_google/packages/LatinIMEGooglePrebuilt | affected | platform | platform/vendor/unbundled_google/packages/LatinIMEGooglePrebuilt | — |
In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to a logic error in the code. This could lead to local escalation of privilege by conflating apps with User execution privileges needed...
CVEs:CVE-2022-20193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20193
CVEs:CVE-2022-20233
In param_find_digests_internal and related functions of the Titan-M source, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interac...
CVEs:CVE-2022-20233
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-222472803
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In multiple locations of the nanopb library, there is a possible way to corrupt memory when decoding untrusted protobuf files. This could lead to local escalation of privilege,with no additional execution privileges needed. User interaction is not need...
CVEs:CVE-2022-20203
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20203
CVEs:CVE-2022-20153
In rcu_cblist_dequeue of rcu_segcblist.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2022-20153
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-222091980
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-20201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20201
PUB-A-193443223
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20196
In gallery3d and photos, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2022-20196
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In TBD of TBD, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...
CVEs:CVE-2022-20148
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20148
PUB-A-219513976
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In readArguments of CallSubjectDialog.java, there is a possible way to trick the user to call the wrong phone number due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User...
CVEs:CVE-2022-20134
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20134
CVEs:CVE-2022-20147
In nfa_dm_check_set_config of nfa_dm_main.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2022-20147
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In unflatten of GraphicBuffer.cpp, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2022-20156
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20156
In asn1_ec_pkey_parse of acropora/crypto/asn1_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-20159
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20159
CVEs:CVE-2022-20165
In asn1_parse of asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
CVEs:CVE-2022-20165
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-210971465
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-212803946
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-220868345
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20192
In grantEmbeddedWindowFocus of WindowManagerService.java, there is a possible way to change an input channel for embedded hierarchy due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges ne...
CVEs:CVE-2022-20192
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20194
In onCreate of ChooseLockGeneric.java, there is a possible permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2022-20194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20197
In recycle of Parcel.java, there is a possible way to start foreground activity from background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2022-20197
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20207
In static definitions of GattServiceConfig.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-20207
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39691
In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploita...
CVEs:CVE-2021-39691
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20137
In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User ...
CVEs:CVE-2022-20137
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20174
In exynos_secEnv_init of mach-gs101.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2022-20174
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20176
In auth_store of sjtag-driver.c, there is a possible read of uninitialized memory due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2022-20176
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20178
In ioctl_dpm_qos_update and ioctl_event_control_set of (TBD), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed f...
CVEs:CVE-2022-20178
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20183
In hypx_create_blob_dmabuf of faceauth_hypx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2022-20183
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20185
In TBD of TBD, there is a possible use after free bug. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-20884...
CVEs:CVE-2022-20185
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20198
In llcp_dlc_proc_connect_pdu of llcp_dlc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure from the NFC stack with System execution privileges needed. User interaction is not neede...
CVEs:CVE-2022-20198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20208
In parseRecursively of cppbor_parse.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2022-20208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-188911154
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-197787879
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-208842348
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-210847407
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-224932775
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20205
In isFileUri of FileUtil.java, there is a possible way to bypass the check for a file:// scheme due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2022-20205
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30723
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
CVEs:CVE-2022-30723
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
CVEs:CVE-2022-30724
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30724
CVEs:CVE-2022-30725
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
CVEs:CVE-2022-30725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In WLAN driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535950; I...
CVEs:CVE-2022-21756
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21756
In WLAN driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545464; I...
CVEs:CVE-2022-21755
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21755
CVEs:CVE-2022-21750
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06521283; Is...
CVEs:CVE-2022-21750
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511132; Is...
CVEs:CVE-2022-21751
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21751
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Is...
CVEs:CVE-2022-21752
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21752
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Is...
CVEs:CVE-2022-21753
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21753
CVEs:CVE-2022-21754
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535953; Is...
CVEs:CVE-2022-21754
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20154
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2022-20154
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-174846563
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2022-20152
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20152
In ccu, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06439600; Issue ID: ALPS06439600.
CVEs:CVE-2022-21758
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21758
PUB-A-202006198
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-39806
In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege during startup of servicemanager, if an attacker can trigger an initialization failure, with no addi...
CVEs:CVE-2021-39806
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20146
In uploadFile of FileUploadServiceImpl.java, there is a possible incorrect file access due to a confused deputy. This could lead to local information disclosure of private files with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2022-20146
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-211757677
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2022-20172
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20172
CVEs:CVE-2022-20182
In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not ne...
CVEs:CVE-2022-20182
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2022-20200
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20200
CVEs:CVE-2022-20206
In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclosure about enabled notification listeners with User execution privileges needed. User interaction is not...
CVEs:CVE-2022-20206
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21760
In apusys driver, there is a possible system crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479562; Issue ID: ALPS06...
CVEs:CVE-2022-21760
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21761
In apusys driver, there is a possible system crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479532; Issue ID: ALPS06...
CVEs:CVE-2022-21761
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21762
In apusys driver, there is a possible system crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06477946; Issue ID: ALPS06...
CVEs:CVE-2022-21762
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21746
In imgsensor, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479698; Issue ID: A...
CVEs:CVE-2022-21746
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In imgsensor, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478078; Issue ID: A...
CVEs:CVE-2022-21747
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21747
PUB-A-206987222
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-222348453
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-30728
Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.
CVEs:CVE-2022-30728
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.
CVEs:CVE-2022-30714
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30714
In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges n...
CVEs:CVE-2022-20204
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20204
Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner.
CVEs:CVE-2022-30729
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30729
In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper input validation. This could lead to local denial of service with no additional execution privileges neede...
CVEs:CVE-2022-20129
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20129
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-20143
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20143
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06511030; Issu...
CVEs:CVE-2022-21748
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21748
CVEs:CVE-2022-21749
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...
CVEs:CVE-2022-21749
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.
CVEs:CVE-2022-30726
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30726
Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.
CVEs:CVE-2022-30727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-30727
Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.
CVEs:CVE-2022-28794
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-28794
In ipu_core_jqs_msg_transport_kernel_write_sync of ipu-core-jqs-msg-transport.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...
CVEs:CVE-2022-20155
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20155
PUB-A-176754369
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2017-20092
A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.
CVEs:CVE-2017-20092
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_analytics_dashboard | affected | yoast | — | — |
PUB-A-210498909
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Heap-use-after-free in inflate
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc | affected | OSS-Fuzz | grpc | — |
PUB-A-211647233
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| vendor/unbundled_google/packages/CarrierEntitlement | affected | platform | platform/vendor/unbundled_google/packages/CarrierEntitlement | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.