Google Security Advisories · June 2022 — Google Security Advisories
476 advisories 288 CVEs 7 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2022-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 7 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2022-26134

Project ZeroExploitedCISA KEV listed2022-06-03

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CVEs:CVE-2022-26134

Upstream advisory

CVE-2022-26134

GoogleExploitedCISA KEV listedCRITICAL2022-06-03

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3....

CVEs:CVE-2022-26134

Affected products

ProductStatusVendorPackageEcosystem
confluence_data_center affected atlassian
confluence_server affected atlassian
Upstream advisory

SUSE-SU-2022:2134-1

Open SourceExploitedCISA KEV listedHIGH2022-06-20

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-alertmanager affected SUSE:Manager Client Tools 12 golang-github-prometheus-alertmanager
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 12 SP5 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:HPE Helion OpenStack 8 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:OpenStack Cloud 8 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:OpenStack Cloud 9 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:OpenStack Cloud Crowbar 8 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:OpenStack Cloud Crowbar 9 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Client Tools 12 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 12 SP3 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 12 SP4 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP3-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP3-BCL golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP4-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP5 golang-github-prometheus-node_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Client Tools 12 golang-github-QubitProducts-exporter_exporter
grafana affected SUSE:Manager Client Tools 12 grafana
mgr-cfg affected SUSE:Manager Client Tools 12 mgr-cfg
mgr-custom-info affected SUSE:Manager Client Tools 12 mgr-custom-info
mgr-daemon affected SUSE:Manager Client Tools 12 mgr-daemon
mgr-osad affected SUSE:Manager Client Tools 12 mgr-osad
mgr-push affected SUSE:Manager Client Tools 12 mgr-push
mgr-virtualization affected SUSE:Manager Client Tools 12 mgr-virtualization
prometheus-blackbox_exporter affected SUSE:Manager Client Tools 12 prometheus-blackbox_exporter
prometheus-postgres_exporter affected SUSE:Manager Client Tools 12 prometheus-postgres_exporter
python-hwdata affected SUSE:Manager Client Tools 12 python-hwdata
rhnlib affected SUSE:Manager Client Tools 12 rhnlib
spacecmd affected SUSE:Manager Client Tools 12 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 12 spacewalk-client-tools
spacewalk-koan affected SUSE:Manager Client Tools 12 spacewalk-koan
spacewalk-oscap affected SUSE:Manager Client Tools 12 spacewalk-oscap
spacewalk-remote-utils affected SUSE:Manager Client Tools 12 spacewalk-remote-utils
supportutils-plugin-salt affected SUSE:Manager Client Tools 12 supportutils-plugin-salt
supportutils-plugin-susemanager-client affected SUSE:Manager Client Tools 12 supportutils-plugin-susemanager-client
suseRegisterInfo affected SUSE:Manager Client Tools 12 suseRegisterInfo
uyuni-common-libs affected SUSE:Manager Client Tools 12 uyuni-common-libs
Upstream advisory

SUSE-SU-2022:2044-1

GoogleExploitedCISA KEV listed2022-06-10

Security update for google-gson

Affected products

ProductStatusVendorPackageEcosystem
google-gson affected openSUSE:Leap 15.3 google-gson
google-gson affected SUSE:Linux Enterprise Module for Development Tools 15 SP3 google-gson
google-gson affected SUSE:Manager Proxy 4.1 google-gson
google-gson affected SUSE:Linux Enterprise Module for Development Tools 15 SP4 google-gson
google-gson affected SUSE:Manager Server 4.1 google-gson
google-gson affected openSUSE:Leap 15.4 google-gson
google-gson affected SUSE:Manager Server Module 4.2 google-gson
google-gson affected SUSE:Manager Server Module 4.3 google-gson
google-gson affected SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS google-gson
google-gson affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS google-gson
google-gson affected SUSE:Linux Enterprise Server 15 SP2-BCL google-gson
google-gson affected SUSE:Linux Enterprise Server 15 SP2-LTSS google-gson
google-gson affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 google-gson
google-gson affected SUSE:Manager Retail Branch Server 4.1 google-gson
google-gson affected SUSE:Enterprise Storage 7 google-gson
Upstream advisory

PUB-A-213172369

GoogleExploitedCISA KEV listedHIGH2022-06-01

PUB-A-213172369

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-224859358

GoogleExploitedCISA KEV listed2022-06-01

PUB-A-224859358

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

SUSE-SU-2022:2145-1

Open SourceWeaponized exploitHIGH2022-06-20

Security update for SUSE Manager Server 4.1

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Server Module 4.1 golang-github-lusitaniae-apache_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Server Module 4.1 golang-github-prometheus-node_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Server Module 4.1 golang-github-QubitProducts-exporter_exporter
patterns-suse-manager affected SUSE:Manager Server Module 4.1 patterns-suse-manager
postgresql-jdbc affected SUSE:Manager Server Module 4.1 postgresql-jdbc
prometheus-exporters-formula affected SUSE:Manager Server Module 4.1 prometheus-exporters-formula
prometheus-formula affected SUSE:Manager Server Module 4.1 prometheus-formula
py27-compat-salt affected SUSE:Manager Server Module 4.1 py27-compat-salt
spacecmd affected SUSE:Manager Server Module 4.1 spacecmd
spacewalk-backend affected SUSE:Manager Server Module 4.1 spacewalk-backend
spacewalk-java affected SUSE:Manager Server Module 4.1 spacewalk-java
spacewalk-setup affected SUSE:Manager Server Module 4.1 spacewalk-setup
spacewalk-utils affected SUSE:Manager Server Module 4.1 spacewalk-utils
spacewalk-web affected SUSE:Manager Server Module 4.1 spacewalk-web
subscription-matcher affected SUSE:Manager Server Module 4.1 subscription-matcher
susemanager affected SUSE:Manager Server Module 4.1 susemanager
susemanager-doc-indexes affected SUSE:Manager Server Module 4.1 susemanager-doc-indexes
susemanager-docs_en affected SUSE:Manager Server Module 4.1 susemanager-docs_en
susemanager-schema affected SUSE:Manager Server Module 4.1 susemanager-schema
susemanager-sls affected SUSE:Manager Server Module 4.1 susemanager-sls
Upstream advisory

CVE-2022-20568

Open SourceActive exploitation (sightings)HIGH2022-06-09

In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andro...

CVEs:CVE-2022-20568

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-209480901

GoogleActive exploitation (sightings)2022-06-01

PUB-A-209480901

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-209481085

GoogleActive exploitation (sightings)2022-06-01

PUB-A-209481085

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

RLSA-2022:5337

Open SourcePoC exploitCRITICAL2022-06-28

Moderate: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

CVE-2022-20140

Open SourcePoC exploitHIGH2022-06-06

In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2022-20140

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20130

Open SourcePoC exploitHIGH2022-06-06

In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2022-20130

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CLSA-2022-1654106859

Open SourcePoC exploit2022-06-01

Fix CVE(s): CVE-2022-0391

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

SUSE-RU-2022:2145-1

Open SourcePoC exploitCRITICAL2022-06-20

Recommended update for SUSE Manager Proxy 4.1

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Proxy Module 4.1 golang-github-lusitaniae-apache_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Proxy Module 4.1 golang-github-prometheus-node_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Proxy Module 4.1 golang-github-QubitProducts-exporter_exporter
patterns-suse-manager affected SUSE:Manager Proxy Module 4.1 patterns-suse-manager
spacecmd affected SUSE:Manager Proxy Module 4.1 spacecmd
spacewalk-backend affected SUSE:Manager Proxy Module 4.1 spacewalk-backend
spacewalk-web affected SUSE:Manager Proxy Module 4.1 spacewalk-web
Upstream advisory

SUSE-SU-2022:2140-1

Open SourcePoC exploitCRITICAL2022-06-20

Security update for node_exporter

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Proxy 4.1 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Retail Branch Server 4.1 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Server 4.1 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Enterprise Storage 6 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Enterprise Storage 7 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected openSUSE:Leap 15.3 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected openSUSE:Leap 15.4 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP2-BCL golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Module for Basesystem 15 SP3 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Module for Basesystem 15 SP4 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP1-BCL golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP1-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP2-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 golang-github-prometheus-node_exporter
Upstream advisory

SUSE-SU-2022:2139-1

Open SourcePoC exploitCRITICAL2022-06-20

Security update for golang-github-prometheus-alertmanager

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-alertmanager affected SUSE:Manager Proxy Module 4.3 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected SUSE:Enterprise Storage 6 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected SUSE:Manager Client Tools 15 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected SUSE:Manager Proxy Module 4.1 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected openSUSE:Leap 15.3 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected openSUSE:Leap 15.4 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected SUSE:Manager Proxy Module 4.2 golang-github-prometheus-alertmanager
Upstream advisory

SUSE-SU-2022:2137-1

Open SourcePoC exploitCRITICAL2022-06-20

Security update for golang-github-prometheus-node_exporter

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15-ESPOS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 15 golang-github-prometheus-node_exporter
Upstream advisory

DEBIAN-CVE-2022-1996

Open SourcePoC exploitCRITICAL2022-06-08

DEBIAN-CVE-2022-1996

Affected products

ProductStatusVendorPackageEcosystem
golang-github-emicklei-go-restful affected Debian:11 golang-github-emicklei-go-restful
golang-github-emicklei-go-restful affected Debian:12 golang-github-emicklei-go-restful
golang-github-emicklei-go-restful affected Debian:13 golang-github-emicklei-go-restful
golang-github-emicklei-go-restful affected Debian:14 golang-github-emicklei-go-restful
Upstream advisory

GO-2022-0477

Open SourcePoC exploitHIGH2022-06-09

Indefinite hang with large buffers on Windows in crypto/rand

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

CVE-2022-30634

GooglePoC exploitHIGH2022-06-07

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVEs:CVE-2022-30634

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights_telegraf_agent affected netapp
go affected golang
Upstream advisory

CVE-2022-29804

GooglePoC exploitHIGH2022-06-07

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVEs:CVE-2022-29804

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

PUB-A-215814262

GooglePoC exploitNONE2022-06-01

PUB-A-215814262

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DSA-5168-1

Open SourcePoC exploit2022-06-22

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

PUB-A-189614572

GooglePoC exploitHIGH2022-06-01

PUB-A-189614572

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

OESA-2022-1694

Open SourcePoC exploit2022-06-02

protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected openEuler:22.03-LTS protobuf
Upstream advisory

openSUSE-SU-2022:10036-1

Open SourcePoC exploitCRITICAL2022-06-29

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

openSUSE-SU-2022:10035-1

Open SourcePoC exploitCRITICAL2022-06-29

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

MGASA-2022-0241

Open SourcePoC exploitCRITICAL2022-06-24

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

CVE-2021-38561

Open SourcePoC exploitHIGH2022-06-29

golang.org/x/text/language Out-of-bounds Read vulnerability

CVEs:CVE-2021-38561

Affected products

ProductStatusVendorPackageEcosystem
x/text affected golang.org golang.org/x/text
Upstream advisory

CVE-2021-38561

GooglePoC exploitHIGH2021-10-06

golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service...

CVEs:CVE-2021-38561

Affected products

ProductStatusVendorPackageEcosystem
text affected golang
Upstream advisory

CVE-2022-2162

GooglePoC exploitCRITICAL2022-06-22

Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page.

CVEs:CVE-2022-2162

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

ASB-A-218836280

GooglePoC exploitHIGH2022-06-01

ASB-A-218836280

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-162326603

GooglePoC exploitMEDIUM2022-06-01

ASB-A-162326603

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-222023189

GooglePoC exploitHIGH2022-06-01

ASB-A-222023189

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-194694600

GooglePoC exploitHIGH2022-06-01

PUB-A-194694600

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-127973231

GooglePoC exploit2022-06-01

PUB-A-127973231

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-224080927

GooglePoC exploit2022-06-01

PUB-A-224080927

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-213173524

GooglePoC exploit2022-06-01

PUB-A-213173524

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-30580

GooglePoC exploitHIGH2022-06-07

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVEs:CVE-2022-30580

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2022-20173

Open SourcePoC exploitHIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A

CVEs:CVE-2022-20173

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-207116951

GooglePoC exploit2022-06-01

PUB-A-207116951

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20186

Open SourcePoC exploitHIGH2022-06-06

In kbase_mem_alias of mali_kbase_mem_linux.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2022-20186

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-215001024

GooglePoC exploitHIGH2022-06-01

PUB-A-215001024

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

openSUSE-SU-2022:10014-1

Open SourcePoC exploit2022-06-18

Security update for tensorflow2

Affected products

ProductStatusVendorPackageEcosystem
bazel3.7 affected openSUSE:Leap 15.3 bazel3.7
bazel3.7 affected SUSE:Package Hub 15 SP3 bazel3.7
bazel-skylib1.0.3 affected SUSE:Package Hub 15 SP3 bazel-skylib1.0.3
bazel-skylib1.0.3 affected openSUSE:Leap 15.3 bazel-skylib1.0.3
tensorflow2 affected SUSE:Package Hub 15 SP3 tensorflow2
tensorflow2 affected openSUSE:Leap 15.3 tensorflow2
tensorflow2_2_6_0-gnu-hpc affected openSUSE:Leap 15.3 tensorflow2_2_6_0-gnu-hpc
tensorflow2_2_6_0-gnu-hpc affected SUSE:Package Hub 15 SP3 tensorflow2_2_6_0-gnu-hpc
tensorflow2_2_6_0-gnu-openmpi2-hpc affected SUSE:Package Hub 15 SP3 tensorflow2_2_6_0-gnu-openmpi2-hpc
tensorflow2_2_6_0-gnu-openmpi2-hpc affected openSUSE:Leap 15.3 tensorflow2_2_6_0-gnu-openmpi2-hpc
tensorflow2-lite affected SUSE:Package Hub 15 SP3 tensorflow2-lite
tensorflow2-lite affected openSUSE:Leap 15.3 tensorflow2-lite
Upstream advisory

ASB-A-220261709

GooglePoC exploitHIGH2022-06-01

ASB-A-220261709

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-223966861

GooglePoC exploit2022-06-01

PUB-A-223966861

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-225469258

GooglePoC exploit2022-06-01

PUB-A-225469258

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-182986620

GooglePoC exploit2022-06-01

PUB-A-182986620

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20126

Open SourcePoC exploitHIGH2022-06-06

In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User i...

CVEs:CVE-2022-20126

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20142

Open SourcePoC exploitHIGH2022-06-06

In createFromParcel of GeofenceHardwareRequestParcelable.java, there is a possible arbitrary code execution due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2022-20142

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20138

Open SourcePoC exploitHIGH2022-06-06

In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to local escalation of privilege with n...

CVEs:CVE-2022-20138

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-182388481

GooglePoC exploitHIGH2022-06-01

PUB-A-182388481

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-112551163

GooglePoC exploitHIGH2022-06-01

ASB-A-112551163

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-1707

GoogleEPSS > 79%HIGH2022-06-13

The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including 1...

CVEs:CVE-2022-1707

Affected products

ProductStatusVendorPackageEcosystem
google_tag_manager affected gtm4wp
Upstream advisory

CVE-2022-20145

Open SourceCoalition ESS < 30%HIGH2022-06-06

In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges ...

CVEs:CVE-2022-20145

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20127

Open SourceCoalition ESS < 30%HIGH2022-06-06

In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2022-20127

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20210

Open SourceCoalition ESS < 30%HIGH2022-06-06

The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in internal objects based on the received data. A bug in the parsing code could be used by an attacker to remo...

CVEs:CVE-2022-20210

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-228868888

GoogleCoalition ESS < 30%CRITICAL2022-06-01

ASB-A-228868888

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-1708

GoogleCoalition ESS < 30%HIGH2022-06-06

Node DOS by way of memory exhaustion through ExecSync request in CRI-O

CVEs:CVE-2022-1708

Affected products

ProductStatusVendorPackageEcosystem
cri-o/cri-o affected github.com github.com/cri-o/cri-o
Upstream advisory

CVE-2022-1708

GoogleCoalition ESS < 30%CRITICAL2022-06-06

A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O a...

CVEs:CVE-2022-1708

Affected products

ProductStatusVendorPackageEcosystem
cri-o affected kubernetes
enterprise_linux affected redhat
fedora affected fedoraproject
openshift_container_platform affected redhat
Upstream advisory

CVE-2022-22021

Open SourceCoalition ESS < 30%CRITICAL2022-06-10

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2022-22021

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-p782-xgp4-8hr8

Open SourceCoalition ESS < 30%MEDIUM2022-06-24

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

Affected products

ProductStatusVendorPackageEcosystem
ctop affected chainguard ctop
ctop affected wolfi ctop
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
k3d affected chainguard k3d
k3d affected wolfi k3d
kind affected chainguard kind
kind affected wolfi kind
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
x/sys affected golang.org golang.org/x/sys
Upstream advisory

GHSA-p782-xgp4-8hr8

Open SourceCoalition ESS < 30%MEDIUM2022-06-24

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

Affected products

ProductStatusVendorPackageEcosystem
x/sys affected golang.org golang.org/x/sys
Upstream advisory

AZL-37365

Open SourceCoalition ESS < 30%MEDIUM2022-06-23

CVE-2022-29526 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37490

Open SourceCoalition ESS < 30%MEDIUM2022-06-23

CVE-2022-29526 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-47178

Open SourceCoalition ESS < 30%MEDIUM2022-06-23

CVE-2022-29526 affecting package golang for versions less than 1.22.7-2

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-29526

Open SourceCoalition ESS < 30%MEDIUM2022-06-23

DEBIAN-CVE-2022-29526

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

CVE-2022-30192

Open SourceCoalition ESS < 30%CRITICAL2022-06-14

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-30192

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-33639

Open SourceCoalition ESS < 30%CRITICAL2022-06-14

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-33639

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-33638

Open SourceCoalition ESS < 30%CRITICAL2022-06-14

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-33638

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-7xhv-mpjw-422f

GoogleCoalition ESS < 30%CRITICAL2022-06-03

Command injection in google-it

Affected products

ProductStatusVendorPackageEcosystem
google-it affected npm google-it
Upstream advisory

GHSA-7xhv-mpjw-422f

GoogleCoalition ESS < 30%CRITICAL2022-06-03

Command injection in google-it

Affected products

ProductStatusVendorPackageEcosystem
google-it affected npm google-it
Upstream advisory

CVE-2021-34083

GoogleCoalition ESS < 30%CRITICAL2022-06-02

Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved...

CVEs:CVE-2021-34083

Affected products

ProductStatusVendorPackageEcosystem
google-it affected google-it_project
Upstream advisory

CVE-2022-33680

Open SourceCoalition ESS < 30%CRITICAL2022-06-14

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-33680

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-2156

GoogleCoalition ESS < 30%CRITICAL2022-06-22

Use after free in Core in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2156

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

MGASA-2022-0232

Open SourceCoalition ESS < 30%CRITICAL2022-06-16

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

openSUSE-SU-2022:10010-1

Open SourceCoalition ESS < 30%CRITICAL2022-06-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

openSUSE-SU-2022:10009-1

Open SourceCoalition ESS < 30%CRITICAL2022-06-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

DSA-5163-1

Open SourceCoalition ESS < 30%2022-06-12

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-2010

GoogleCoalition ESS < 30%CRITICAL2022-06-10

Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2022-2010

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-xwx5-5c9g-x68x

Open SourceCoalition ESS < 30%HIGH2022-06-10

Ill-formed headers may lead to unexpected behavior in Istio

Affected products

ProductStatusVendorPackageEcosystem
cert-manager-istio-csr affected wolfi cert-manager-istio-csr
cert-manager-istio-csr affected chainguard cert-manager-istio-csr
cert-manager-istio-csr-fips affected chainguard cert-manager-istio-csr-fips
istio affected istio.io istio.io/istio
istio-cni-1.21 affected wolfi istio-cni-1.21
istio-cni-1.21 affected chainguard istio-cni-1.21
istio-cni-1.22 affected chainguard istio-cni-1.22
istio-cni-1.22 affected wolfi istio-cni-1.22
istio-fips-1.21 affected chainguard istio-fips-1.21
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.21 affected chainguard istio-operator-1.21
istio-operator-1.21 affected wolfi istio-operator-1.21
istio-operator-1.22 affected wolfi istio-operator-1.22
istio-operator-1.22 affected chainguard istio-operator-1.22
istio-pilot-agent-1.21 affected wolfi istio-pilot-agent-1.21
istio-pilot-agent-1.21 affected chainguard istio-pilot-agent-1.21
istio-pilot-agent-1.22 affected chainguard istio-pilot-agent-1.22
istio-pilot-agent-1.22 affected wolfi istio-pilot-agent-1.22
istio-pilot-discovery-1.21 affected wolfi istio-pilot-discovery-1.21
istio-pilot-discovery-1.21 affected chainguard istio-pilot-discovery-1.21
istio-pilot-discovery-1.22 affected chainguard istio-pilot-discovery-1.22
istio-pilot-discovery-1.22 affected wolfi istio-pilot-discovery-1.22
kgateway-2.3 affected chainguard kgateway-2.3
kgateway-2.4 affected chainguard kgateway-2.4
kgateway-fips-2.3 affected chainguard kgateway-fips-2.3
kgateway-fips-2.4 affected chainguard kgateway-fips-2.4
Upstream advisory

GHSA-xwx5-5c9g-x68x

Open SourceCoalition ESS < 30%HIGH2022-06-10

Ill-formed headers may lead to unexpected behavior in Istio

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

CVE-2022-31045

Open SourceCoalition ESS < 30%CRITICAL2022-06-09

Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most lik...

CVEs:CVE-2022-31045

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

CVE-2022-31045

Open SourceCoalition ESS < 30%MEDIUM2022-06-09

Ill-formed headers may lead to unexpected behavior in Istio

CVEs:CVE-2022-31045

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

CVE-2022-1961

GoogleCoalition ESS < 30%HIGH2022-06-13

The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~/public/frontend.php` file which allowed attackers with...

CVEs:CVE-2022-1961

Affected products

ProductStatusVendorPackageEcosystem
google_tag_manager affected gtm4wp
Upstream advisory

GHSA-xcrq-6j7j-784j

Open SourceCoalition ESS < 30%HIGH2022-06-24

GHSA-xcrq-6j7j-784j

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected chainguard protobuf-c
protobuf-c affected wolfi protobuf-c
Upstream advisory

ALPINE-CVE-2022-33070

Open SourceCoalition ESS < 30%HIGH2022-06-23

ALPINE-CVE-2022-33070

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected Alpine:v3.17 protobuf-c
protobuf-c affected Alpine:v3.18 protobuf-c
protobuf-c affected Alpine:v3.19 protobuf-c
protobuf-c affected Alpine:v3.20 protobuf-c
protobuf-c affected Alpine:v3.21 protobuf-c
protobuf-c affected Alpine:v3.22 protobuf-c
protobuf-c affected Alpine:v3.23 protobuf-c
protobuf-c affected Alpine:v3.24 protobuf-c
Upstream advisory

AZL-9973

Open SourceCoalition ESS < 30%HIGH2022-06-23

CVE-2022-33070 affecting package protobuf-c for versions less than 1.4.0-2

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected Azure Linux:2 protobuf-c
Upstream advisory

CVE-2022-33070

Open SourceCoalition ESS < 30%HIGH2022-06-23

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVEs:CVE-2022-33070

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
protobuf-c affected protobuf-c_project
Upstream advisory

DEBIAN-CVE-2022-33070

Open SourceCoalition ESS < 30%HIGH2022-06-23

DEBIAN-CVE-2022-33070

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected Debian:11 protobuf-c
protobuf-c affected Debian:12 protobuf-c
protobuf-c affected Debian:13 protobuf-c
protobuf-c affected Debian:14 protobuf-c
Upstream advisory

MGASA-2022-0231

Open SourceCoalition ESS < 30%2022-06-16

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

CVE-2022-30629

GoogleCoalition ESS < 30%LOW2022-06-07

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVEs:CVE-2022-30629

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2021-40897

Open SourceCoalition ESS < 30%HIGH2022-06-27

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.

CVEs:CVE-2021-40897

Affected products

ProductStatusVendorPackageEcosystem
split-html-to-chars affected split-html-to-chars_project
Upstream advisory

GHSA-2927-hv3p-f3vp

GoogleCoalition ESS < 30%MEDIUM2022-06-03

Open redirect in caddy

Affected products

ProductStatusVendorPackageEcosystem
caddyserver/caddy affected github.com github.com/caddyserver/caddy
caddyserver/caddy/v2 affected github.com github.com/caddyserver/caddy/v2
Upstream advisory

GHSA-2927-hv3p-f3vp

Open SourceCoalition ESS < 30%MEDIUM2022-06-03

Open redirect in caddy

Affected products

ProductStatusVendorPackageEcosystem
caddy affected chainguard caddy
caddy affected wolfi caddy
caddy-fips affected chainguard caddy-fips
caddyserver/caddy affected github.com github.com/caddyserver/caddy
caddyserver/caddy/v2 affected github.com github.com/caddyserver/caddy/v2
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

CVE-2022-2011

GoogleCoalition ESS < 30%CRITICAL2022-06-10

Use after free in ANGLE in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2011

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2158

GoogleCoalition ESS < 30%HIGH2022-06-22

Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2158

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
extra_packages_for_enterprise_linux affected fedoraproject
fedora affected fedoraproject
Upstream advisory

CVE-2022-2008

GoogleCoalition ESS < 30%CRITICAL2022-06-10

Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2008

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

openSUSE-SU-2022:10005-1

Open SourceCoalition ESS < 30%CRITICAL2022-06-03

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

CVE-2022-1853

GoogleCoalition ESS < 30%CRITICAL2022-06-01

Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2022-1853

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-2157

GoogleCoalition ESS < 30%CRITICAL2022-06-22

Use after free in Interest groups in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2157

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2161

GoogleCoalition ESS < 30%HIGH2022-06-22

Use after free in WebApp Provider in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who convinced the user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

CVEs:CVE-2022-2161

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2007

GoogleCoalition ESS < 30%CRITICAL2022-06-10

Use after free in WebGPU in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2007

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-1873

GoogleCoalition ESS < 30%CRITICAL2022-06-01

Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-1873

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-25736

Open SourceCoalition ESS < 30%MEDIUM2022-06-29

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” fi...

CVEs:CVE-2021-25736

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2021-25736

Open SourceCoalition ESS < 30%MEDIUM2022-06-29

Kube-proxy may unintentionally forward traffic

CVEs:CVE-2021-25736

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2021-25736

Open SourceCoalition ESS < 30%MEDIUM2022-06-29

Kube-proxy may unintentionally forward traffic

CVEs:CVE-2021-25736

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2022-1869

GoogleCoalition ESS < 30%MEDIUM2022-06-01

Type Confusion in V8 in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1869

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-20123

Open SourceCoalition ESS < 30%HIGH2022-06-06

In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2022-20123

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20131

Open SourceCoalition ESS < 30%HIGH2022-06-06

In nci_proc_rf_management_ntf of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2022-20131

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-1855

GoogleCoalition ESS < 30%CRITICAL2022-06-01

Use after free in Messaging in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1855

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1874

GoogleCoalition ESS < 30%CRITICAL2022-06-01

Insufficient policy enforcement in Safe Browsing in Google Chrome on Mac prior to 102.0.5005.61 allowed a remote attacker to bypass downloads protection policy via a crafted HTML page.

CVEs:CVE-2022-1874

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1854

GoogleCoalition ESS < 30%CRITICAL2022-06-01

Use after free in ANGLE in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1854

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-2165

GoogleCoalition ESS < 30%MEDIUM2022-06-22

Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2022-2165

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-1867

GoogleCoalition ESS < 30%MEDIUM2022-06-01

Insufficient validation of untrusted input in Data Transfer in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass same origin policy via a crafted clipboard content.

CVEs:CVE-2022-1867

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1857

GoogleCoalition ESS < 30%CRITICAL2022-06-01

Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass file system restrictions via a crafted HTML page.

CVEs:CVE-2022-1857

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1866

GoogleCoalition ESS < 30%HIGH2022-06-01

Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions.

CVEs:CVE-2022-1866

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1859

GoogleCoalition ESS < 30%HIGH2022-06-01

Use after free in Performance Manager in Google Chrome prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1859

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-2163

GoogleCoalition ESS < 30%CRITICAL2022-06-22

Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction.

CVEs:CVE-2022-2163

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
extra_packages_for_enterprise_linux affected fedoraproject
fedora affected fedoraproject
Upstream advisory

CVE-2022-20209

Open SourceCoalition ESS < 30%HIGH2022-06-06

In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2022-20209

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-1860

GoogleCoalition ESS < 30%HIGH2022-06-01

Use after free in UI Foundations in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user interactions.

CVEs:CVE-2022-1860

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1861

GoogleCoalition ESS < 30%HIGH2022-06-01

Use after free in Sharing in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific user interaction.

CVEs:CVE-2022-1861

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1858

GoogleCoalition ESS < 30%MEDIUM2022-06-01

Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform an out of bounds memory read via specific user interaction.

CVEs:CVE-2022-1858

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1875

GoogleCoalition ESS < 30%MEDIUM2022-06-01

Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-1875

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1772

GoogleCoalition ESS < 30%MEDIUM2022-06-13

The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, ...

CVEs:CVE-2022-1772

Affected products

ProductStatusVendorPackageEcosystem
google_places_reviews affected google_places_reviews_project
Upstream advisory

CVE-2022-1876

GoogleCoalition ESS < 30%CRITICAL2022-06-01

Heap buffer overflow in DevTools in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-1876

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-20202

Open SourceCoalition ESS < 30%HIGH2022-06-06

In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interacti...

CVEs:CVE-2022-20202

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-2160

GoogleCoalition ESS < 30%CRITICAL2022-06-22

Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted...

CVEs:CVE-2022-2160

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Chrome affected Google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2164

GoogleCoalition ESS < 30%MEDIUM2022-06-22

Inappropriate implementation in Extensions API in Google Chrome prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted HTML page.

CVEs:CVE-2022-2164

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-31055

GoogleCoalition ESS < 30%HIGH2022-06-13

kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was broken and allowed traffic from any IP. The problem has been patched in v1.6.0. As a workaround, those who...

CVEs:CVE-2022-31055

Affected products

ProductStatusVendorPackageEcosystem
kctf affected google
Upstream advisory

CVE-2022-1321

GoogleCoalition ESS < 30%HIGH2022-06-27

The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks w...

CVEs:CVE-2022-1321

Affected products

ProductStatusVendorPackageEcosystem
google_authenticator affected miniorange
Upstream advisory

CVE-2022-1870

GoogleCoalition ESS < 30%CRITICAL2022-06-01

Use after free in App Service in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

CVEs:CVE-2022-1870

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1994

GoogleCoalition ESS < 30%CRITICAL2022-06-27

The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disal...

CVEs:CVE-2022-1994

Affected products

ProductStatusVendorPackageEcosystem
login_with_otp_over_sms\,_email\,_whatsapp_and_google_authenticator affected miniorange
Upstream advisory

CVE-2021-25088

GoogleCoalition ESS < 30%CRITICAL2022-06-20

The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is di...

CVEs:CVE-2021-25088

Affected products

ProductStatusVendorPackageEcosystem
google_xml_sitemaps affected google_xml_sitemaps_project
Upstream advisory

CVE-2022-1856

GoogleCoalition ESS < 30%HIGH2022-06-01

Use after free in User Education in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension or specific user interaction.

CVEs:CVE-2022-1856

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1868

GoogleCoalition ESS < 30%MEDIUM2022-06-01

Inappropriate implementation in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page.

CVEs:CVE-2022-1868

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1862

GoogleCoalition ESS < 30%MEDIUM2022-06-01

Inappropriate implementation in Extensions in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass profile restrictions via a crafted HTML page.

CVEs:CVE-2022-1862

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1863

GoogleCoalition ESS < 30%HIGH2022-06-01

Use after free in Tab Groups in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.

CVEs:CVE-2022-1863

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1864

GoogleCoalition ESS < 30%HIGH2022-06-01

Use after free in WebApp Installs in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.

CVEs:CVE-2022-1864

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1865

GoogleCoalition ESS < 30%HIGH2022-06-01

Use after free in Bookmarks in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.

CVEs:CVE-2022-1865

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1871

GoogleCoalition ESS < 30%CRITICAL2022-06-01

Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page.

CVEs:CVE-2022-1871

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1872

GoogleCoalition ESS < 30%CRITICAL2022-06-01

Insufficient policy enforcement in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.

CVEs:CVE-2022-1872

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-1829

GoogleCoalition ESS < 30%MEDIUM2022-06-20

The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored Cross-Site Scripting due to the l...

CVEs:CVE-2022-1829

Affected products

ProductStatusVendorPackageEcosystem
inline_google_maps affected inline_google_maps_project
Upstream advisory

CVE-2022-20171

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A

CVEs:CVE-2022-20171

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20191

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A

CVEs:CVE-2022-20191

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-209324757

GoogleCoalition ESS < 30%2022-06-01

PUB-A-209324757

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-215565667

GoogleCoalition ESS < 30%2022-06-01

PUB-A-215565667

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-21757

Open SourceCoalition ESS < 30%HIGH2022-06-06

In WIFI Firmware, there is a possible system crash due to a missing count check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06468894; Issue ...

CVEs:CVE-2022-21757

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20160

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A

CVEs:CVE-2022-20160

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20164

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A

CVEs:CVE-2022-20164

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20167

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A

CVEs:CVE-2022-20167

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20170

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A

CVEs:CVE-2022-20170

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-204891956

GoogleCoalition ESS < 30%2022-06-01

PUB-A-204891956

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-204956204

GoogleCoalition ESS < 30%2022-06-01

PUB-A-204956204

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-209421931

GoogleCoalition ESS < 30%2022-06-01

PUB-A-209421931

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-210083655

GoogleCoalition ESS < 30%2022-06-01

PUB-A-210083655

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20190

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-208744915References: N/A

CVEs:CVE-2022-20190

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-208744915

GoogleCoalition ESS < 30%2022-06-01

PUB-A-208744915

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-29453

GoogleCoalition ESS < 30%MEDIUM2022-06-15

Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.

CVEs:CVE-2022-29453

Affected products

ProductStatusVendorPackageEcosystem
api_key_for_google_maps affected ayecode
Upstream advisory

CVE-2022-0875

GoogleCoalition ESS < 30%MEDIUM2022-06-27

The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

CVEs:CVE-2022-0875

Affected products

ProductStatusVendorPackageEcosystem
google_authenticator affected miniorange
Upstream advisory

PUB-A-196011539

GoogleCoalition ESS < 30%MEDIUM2022-06-01

PUB-A-196011539

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20175

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-209252491References: N/A

CVEs:CVE-2022-20175

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20177

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-209906686References: N/A

CVEs:CVE-2022-20177

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20184

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-209153114References: N/A

CVEs:CVE-2022-20184

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20188

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-207254598References: N/A

CVEs:CVE-2022-20188

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-197154898

GoogleCoalition ESS < 30%MEDIUM2022-06-01

PUB-A-197154898

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-207254598

GoogleCoalition ESS < 30%2022-06-01

PUB-A-207254598

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-209153114

GoogleCoalition ESS < 30%2022-06-01

PUB-A-209153114

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-209252491

GoogleCoalition ESS < 30%2022-06-01

PUB-A-209252491

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-209906686

GoogleCoalition ESS < 30%2022-06-01

PUB-A-209906686

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20168

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-210594998References: N/A

CVEs:CVE-2022-20168

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20181

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-210936609References: N/A

CVEs:CVE-2022-20181

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-210594998

GoogleCoalition ESS < 30%2022-06-01

PUB-A-210594998

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-210936609

GoogleCoalition ESS < 30%2022-06-01

PUB-A-210936609

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20149

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-211685939References: N/A

CVEs:CVE-2022-20149

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20151

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-210712565References: N/A

CVEs:CVE-2022-20151

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20169

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A

CVEs:CVE-2022-20169

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20179

Open SourceCoalition ESS < 30%HIGH2022-06-06

Product: AndroidVersions: Android kernelAndroid ID: A-211683760References: N/A

CVEs:CVE-2022-20179

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-210712565

GoogleCoalition ESS < 30%2022-06-01

PUB-A-210712565

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-211162353

GoogleCoalition ESS < 30%2022-06-01

PUB-A-211162353

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-211683760

GoogleCoalition ESS < 30%2022-06-01

PUB-A-211683760

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-211685939

GoogleCoalition ESS < 30%2022-06-01

PUB-A-211685939

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-21745

Open SourceCoalition ESS < 30%HIGH2022-06-06

In WIFI Firmware, there is a possible memory corruption due to a use after free. This could lead to remote escalation of privilege, when devices are connecting to the attacker-controllable Wi-Fi hotspot, with no additional execution privileges needed. ...

CVEs:CVE-2022-21745

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-228972609

GoogleCoalition ESS < 30%HIGH2022-06-01

ASB-A-228972609

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-222023207

GoogleCoalition ESS < 30%2022-06-01

PUB-A-222023207

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DEBIAN-CVE-2022-31022

Open SourceCoalition ESS < 30%MEDIUM2022-06-01

DEBIAN-CVE-2022-31022

Affected products

ProductStatusVendorPackageEcosystem
golang-github-blevesearch-bleve affected Debian:11 golang-github-blevesearch-bleve
Upstream advisory

CVE-2022-30711

Open SourceCoalition ESS < 30%HIGH2022-06-07

Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2022-30711

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30713

Open SourceCoalition ESS < 30%HIGH2022-06-07

Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2022-30713

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30710

Open SourceCoalition ESS < 30%HIGH2022-06-07

Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2022-30710

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30722

Open SourceCoalition ESS < 30%CRITICAL2022-06-07

Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.

CVEs:CVE-2022-30722

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30712

Open SourceCoalition ESS < 30%CRITICAL2022-06-07

Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2022-30712

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-197614484

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-197614484

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-30716

Open SourceCoalition ESS < 30%MEDIUM2022-06-07

Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.

CVEs:CVE-2022-30716

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-222644279

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-222644279

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-30709

Open SourceCoalition ESS < 30%HIGH2022-06-07

Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

CVEs:CVE-2022-30709

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30719

Open SourceCoalition ESS < 30%HIGH2022-06-07

Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

CVEs:CVE-2022-30719

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30720

Open SourceCoalition ESS < 30%HIGH2022-06-07

Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

CVEs:CVE-2022-30720

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30721

Open SourceCoalition ESS < 30%HIGH2022-06-07

Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

CVEs:CVE-2022-30721

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30717

Open SourceCoalition ESS < 30%HIGH2022-06-07

Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.

CVEs:CVE-2022-30717

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20135

Open SourceCoalition ESS < 30%HIGH2022-06-06

In writeToParcel of GateKeeperResponse.java, there is a possible parcel format mismatch. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2022-20135

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30715

Open SourceCoalition ESS < 30%MEDIUM2022-06-07

Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.

CVEs:CVE-2022-30715

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20132

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In lg_probe and related functions of hid-lg.c and other USB HID files, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure if a malicious USB HID device were plugged in, with no addit...

CVEs:CVE-2022-20132

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-188677105

GoogleCoalition ESS < 30%MEDIUM2022-06-01

ASB-A-188677105

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20195

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: A...

CVEs:CVE-2022-20195

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20124

Open SourceCoalition ESS < 30%HIGH2022-06-06

In deletePackageX of DeletePackageHelper.java, there is a possible way for a Guest user to reset pre-loaded applications for other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileg...

CVEs:CVE-2022-20124

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-209481020

GoogleCoalition ESS < 30%2022-06-01

PUB-A-209481020

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/opensource/camera-kernel affected platform platform/vendor/opensource/camera-kernel
Upstream advisory

CVE-2022-20133

Open SourceCoalition ESS < 30%HIGH2022-06-06

In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed f...

CVEs:CVE-2022-20133

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20144

Open SourceCoalition ESS < 30%HIGH2022-06-06

In multiple functions of AvatarPhotoController.java, there is a possible access to content owned by system content providers due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User...

CVEs:CVE-2022-20144

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20162

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In asn1_p256_int of crypto/asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2022-20162

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-223492713

GoogleCoalition ESS < 30%MEDIUM2022-06-01

PUB-A-223492713

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-21759

Open SourceCoalition ESS < 30%HIGH2022-06-06

In power service, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419106; ...

CVEs:CVE-2022-21759

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20125

Open SourceCoalition ESS < 30%HIGH2022-06-06

In GBoard, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to local escalation of privilege if an attacker has physical access to the device, with no additional execution privileges needed. User inte...

CVEs:CVE-2022-20125

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-194402515

GoogleCoalition ESS < 30%NONE2022-06-01

ASB-A-194402515

Affected products

ProductStatusVendorPackageEcosystem
vendor/unbundled_google/packages/LatinIMEGooglePrebuilt affected platform platform/vendor/unbundled_google/packages/LatinIMEGooglePrebuilt
Upstream advisory

CVE-2022-20193

Open SourceCoalition ESS < 30%HIGH2022-06-06

In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to a logic error in the code. This could lead to local escalation of privilege by conflating apps with User execution privileges needed...

CVEs:CVE-2022-20193

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20233

Open SourceCoalition ESS < 30%HIGH2022-06-06

In param_find_digests_internal and related functions of the Titan-M source, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interac...

CVEs:CVE-2022-20233

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-222472803

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-222472803

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20203

Open SourceCoalition ESS < 30%HIGH2022-06-15

In multiple locations of the nanopb library, there is a possible way to corrupt memory when decoding untrusted protobuf files. This could lead to local escalation of privilege,with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2022-20203

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20153

Open SourceCoalition ESS < 30%HIGH2022-06-06

In rcu_cblist_dequeue of rcu_segcblist.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2022-20153

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-222091980

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-222091980

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20201

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20201

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-193443223

GoogleCoalition ESS < 30%NONE2022-06-01

PUB-A-193443223

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20196

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In gallery3d and photos, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2022-20196

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20148

Open SourceCoalition ESS < 30%HIGH2022-06-06

In TBD of TBD, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...

CVEs:CVE-2022-20148

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-219513976

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-219513976

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20134

Open SourceCoalition ESS < 30%HIGH2022-06-06

In readArguments of CallSubjectDialog.java, there is a possible way to trick the user to call the wrong phone number due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User...

CVEs:CVE-2022-20134

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20147

Open SourceCoalition ESS < 30%HIGH2022-06-06

In nfa_dm_check_set_config of nfa_dm_main.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2022-20147

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20156

Open SourceCoalition ESS < 30%HIGH2022-06-06

In unflatten of GraphicBuffer.cpp, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2022-20156

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20159

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In asn1_ec_pkey_parse of acropora/crypto/asn1_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-20159

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20165

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In asn1_parse of asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2022-20165

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-210971465

GoogleCoalition ESS < 30%MEDIUM2022-06-01

PUB-A-210971465

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-212803946

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-212803946

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-220868345

GoogleCoalition ESS < 30%MEDIUM2022-06-01

PUB-A-220868345

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20192

Open SourceCoalition ESS < 30%HIGH2022-06-06

In grantEmbeddedWindowFocus of WindowManagerService.java, there is a possible way to change an input channel for embedded hierarchy due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges ne...

CVEs:CVE-2022-20192

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20194

Open SourceCoalition ESS < 30%HIGH2022-06-06

In onCreate of ChooseLockGeneric.java, there is a possible permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2022-20194

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20197

Open SourceCoalition ESS < 30%HIGH2022-06-06

In recycle of Parcel.java, there is a possible way to start foreground activity from background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2022-20197

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20207

Open SourceCoalition ESS < 30%HIGH2022-06-06

In static definitions of GattServiceConfig.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-20207

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39691

Open SourceCoalition ESS < 30%HIGH2022-06-06

In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploita...

CVEs:CVE-2021-39691

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20137

Open SourceCoalition ESS < 30%HIGH2022-06-06

In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User ...

CVEs:CVE-2022-20137

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20174

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In exynos_secEnv_init of mach-gs101.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2022-20174

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20176

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In auth_store of sjtag-driver.c, there is a possible read of uninitialized memory due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2022-20176

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20178

Open SourceCoalition ESS < 30%HIGH2022-06-06

In ioctl_dpm_qos_update and ioctl_event_control_set of (TBD), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed f...

CVEs:CVE-2022-20178

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20183

Open SourceCoalition ESS < 30%HIGH2022-06-06

In hypx_create_blob_dmabuf of faceauth_hypx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2022-20183

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20185

Open SourceCoalition ESS < 30%HIGH2022-06-06

In TBD of TBD, there is a possible use after free bug. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-20884...

CVEs:CVE-2022-20185

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20198

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In llcp_dlc_proc_connect_pdu of llcp_dlc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure from the NFC stack with System execution privileges needed. User interaction is not neede...

CVEs:CVE-2022-20198

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20208

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In parseRecursively of cppbor_parse.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2022-20208

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-188911154

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-188911154

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-197787879

GoogleCoalition ESS < 30%MEDIUM2022-06-01

PUB-A-197787879

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-208842348

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-208842348

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-210847407

GoogleCoalition ESS < 30%MEDIUM2022-06-01

PUB-A-210847407

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-224932775

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-224932775

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20205

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In isFileUri of FileUtil.java, there is a possible way to bypass the check for a file:// scheme due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2022-20205

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30723

Open SourceCoalition ESS < 30%MEDIUM2022-06-07

Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVEs:CVE-2022-30723

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30724

Open SourceCoalition ESS < 30%MEDIUM2022-06-07

Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVEs:CVE-2022-30724

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30725

Open SourceCoalition ESS < 30%MEDIUM2022-06-07

Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVEs:CVE-2022-30725

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21756

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In WLAN driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535950; I...

CVEs:CVE-2022-21756

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21755

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In WLAN driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545464; I...

CVEs:CVE-2022-21755

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21750

Open SourceCoalition ESS < 30%HIGH2022-06-06

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06521283; Is...

CVEs:CVE-2022-21750

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21751

Open SourceCoalition ESS < 30%HIGH2022-06-06

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511132; Is...

CVEs:CVE-2022-21751

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21752

Open SourceCoalition ESS < 30%HIGH2022-06-06

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Is...

CVEs:CVE-2022-21752

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21753

Open SourceCoalition ESS < 30%HIGH2022-06-06

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Is...

CVEs:CVE-2022-21753

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21754

Open SourceCoalition ESS < 30%HIGH2022-06-06

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535953; Is...

CVEs:CVE-2022-21754

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20154

Open SourceCoalition ESS < 30%HIGH2022-06-06

In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2022-20154

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-174846563

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-174846563

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20152

Open SourceCoalition ESS < 30%HIGH2022-06-06

In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2022-20152

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21758

Open SourceCoalition ESS < 30%HIGH2022-06-06

In ccu, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06439600; Issue ID: ALPS06439600.

CVEs:CVE-2022-21758

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-202006198

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-202006198

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39806

Open SourceCoalition ESS < 30%HIGH2022-06-06

In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege during startup of servicemanager, if an attacker can trigger an initialization failure, with no addi...

CVEs:CVE-2021-39806

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20146

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In uploadFile of FileUploadServiceImpl.java, there is a possible incorrect file access due to a confused deputy. This could lead to local information disclosure of private files with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2022-20146

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-211757677

GoogleCoalition ESS < 30%MEDIUM2022-06-01

PUB-A-211757677

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20172

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2022-20172

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20182

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not ne...

CVEs:CVE-2022-20182

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20200

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2022-20200

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20206

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclosure about enabled notification listeners with User execution privileges needed. User interaction is not...

CVEs:CVE-2022-20206

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21760

Open SourceCoalition ESS < 30%HIGH2022-06-06

In apusys driver, there is a possible system crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479562; Issue ID: ALPS06...

CVEs:CVE-2022-21760

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21761

Open SourceCoalition ESS < 30%HIGH2022-06-06

In apusys driver, there is a possible system crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479532; Issue ID: ALPS06...

CVEs:CVE-2022-21761

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21762

Open SourceCoalition ESS < 30%HIGH2022-06-06

In apusys driver, there is a possible system crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06477946; Issue ID: ALPS06...

CVEs:CVE-2022-21762

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21746

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In imgsensor, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479698; Issue ID: A...

CVEs:CVE-2022-21746

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21747

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In imgsensor, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478078; Issue ID: A...

CVEs:CVE-2022-21747

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-206987222

GoogleCoalition ESS < 30%MEDIUM2022-06-01

PUB-A-206987222

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-222348453

GoogleCoalition ESS < 30%MEDIUM2022-06-01

PUB-A-222348453

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-30728

Open SourceCoalition ESS < 30%LOW2022-06-07

Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

CVEs:CVE-2022-30728

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30714

Open SourceCoalition ESS < 30%LOW2022-06-07

Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

CVEs:CVE-2022-30714

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20204

Open SourceCoalition ESS < 30%HIGH2022-06-06

In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges n...

CVEs:CVE-2022-20204

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30729

Open SourceCoalition ESS < 30%MEDIUM2022-06-07

Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner.

CVEs:CVE-2022-30729

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20129

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper input validation. This could lead to local denial of service with no additional execution privileges neede...

CVEs:CVE-2022-20129

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20143

Open SourceCoalition ESS < 30%HIGH2022-06-06

In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20143

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21748

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06511030; Issu...

CVEs:CVE-2022-21748

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21749

Open SourceCoalition ESS < 30%MEDIUM2022-06-06

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...

CVEs:CVE-2022-21749

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30726

Open SourceCoalition ESS < 30%HIGH2022-06-07

Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.

CVEs:CVE-2022-30726

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-30727

Open SourceCoalition ESS < 30%MEDIUM2022-06-07

Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.

CVEs:CVE-2022-30727

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-28794

Open SourceCoalition ESS < 30%MEDIUM2022-06-07

Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.

CVEs:CVE-2022-28794

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20155

Open SourceCoalition ESS < 30%HIGH2022-06-06

In ipu_core_jqs_msg_transport_kernel_write_sync of ipu-core-jqs-msg-transport.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2022-20155

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-176754369

GoogleCoalition ESS < 30%HIGH2022-06-01

PUB-A-176754369

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2017-20092

GoogleEPSS <= 49%CRITICAL2022-06-24

A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.

CVEs:CVE-2017-20092

Affected products

ProductStatusVendorPackageEcosystem
google_analytics_dashboard affected yoast
Upstream advisory

PUB-A-210498909

GoogleEPSS <= 49%2022-06-01

PUB-A-210498909

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

OSV-2022-460

Open SourceAll remainingCRITICAL2022-06-06

Heap-use-after-free in inflate

Affected products

ProductStatusVendorPackageEcosystem
grpc affected OSS-Fuzz grpc
Upstream advisory

PUB-A-211647233

GoogleAll remainingNONE2022-06-01

PUB-A-211647233

Affected products

ProductStatusVendorPackageEcosystem
vendor/unbundled_google/packages/CarrierEntitlement affected platform platform/vendor/unbundled_google/packages/CarrierEntitlement
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.