Advisories
Open SourceExploitedCISA KEV listedCRITICAL2022-07-28
DEBIAN-CVE-2022-2294
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| webkit2gtk |
affected |
Debian:11 |
webkit2gtk |
— |
| webkit2gtk |
affected |
Debian:12 |
webkit2gtk |
— |
| webkit2gtk |
affected |
Debian:13 |
webkit2gtk |
— |
| webkit2gtk |
affected |
Debian:14 |
webkit2gtk |
— |
| wpewebkit |
affected |
Debian:11 |
wpewebkit |
— |
| wpewebkit |
affected |
Debian:12 |
wpewebkit |
— |
| wpewebkit |
affected |
Debian:13 |
wpewebkit |
— |
| wpewebkit |
affected |
Debian:14 |
wpewebkit |
— |
Open SourceExploitedCISA KEV listedCRITICAL2022-07-12
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
Open SourceExploitedCISA KEV listed2022-07-11
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
Project ZeroExploitedCISA KEV listed2022-07-04
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2294
GoogleExploitedCISA KEV listedHIGH2022-07-04
CVEs:CVE-2022-2294
GoogleExploitedCISA KEV listedCRITICAL2022-07-04
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2294
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| extra_packages_for_enterprise_linux |
affected |
fedoraproject |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
| webkitgtk |
affected |
webkitgtk |
— |
— |
| webrtc |
affected |
webrtc_project |
— |
— |
| wpe_webkit |
affected |
wpewebkit |
— |
— |
Open SourceExploitedCISA KEV listedHIGH2022-07-23
DEBIAN-CVE-2022-1096
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleExploitedCISA KEV listedHIGH2022-07-12
CVEs:CVE-2022-22047
Project ZeroExploitedCISA KEV listed2022-07-12
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
CVEs:CVE-2022-22047
GoogleExploitedCISA KEV listedCRITICAL2022-07-12
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
CVEs:CVE-2022-22047
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1507 |
affected |
microsoft |
— |
— |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_10_20h2 |
affected |
microsoft |
— |
— |
| windows_10_21h1 |
affected |
microsoft |
— |
— |
| windows_10_21h2 |
affected |
microsoft |
— |
— |
| windows_11_21h2 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
| windows_server_2022 |
affected |
microsoft |
— |
— |
| windows_server_20h2 |
affected |
microsoft |
— |
— |
Open SourceExploitedCISA KEV listedHIGH2022-07-26
DEBIAN-CVE-2022-1364
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceExploitedVulnCheck KEV listedHIGH2022-07-28
DEBIAN-CVE-2022-2295
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleExploitedVulnCheck KEV listedHIGH2022-07-05
CVEs:CVE-2022-2295
GoogleExploitedVulnCheck KEV listedHIGH2022-07-05
Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2295
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| extra_packages_for_enterprise_linux |
affected |
fedoraproject |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-16
Angular (deprecated package) Cross-site Scripting
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-16
Angular (deprecated package) Cross-site Scripting
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
| solr |
affected |
wolfi |
solr |
— |
| solr |
affected |
chainguard |
solr |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-15
Angular (deprecated package) Cross-site Scripting
CVEs:CVE-2022-25869
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-15
Angular (deprecated package) Cross-site Scripting
CVEs:CVE-2022-25869
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-15
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolatio...
CVEs:CVE-2022-25869
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angularjs |
affected |
angularjs |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-15
DEBIAN-CVE-2022-25869
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular.js |
affected |
Debian:11 |
angular.js |
— |
| angular.js |
affected |
Debian:12 |
angular.js |
— |
| angular.js |
affected |
Debian:13 |
angular.js |
— |
| angular.js |
affected |
Debian:14 |
angular.js |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-26
DEBIAN-CVE-2022-1483
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-26
DEBIAN-CVE-2022-1487
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-26
DEBIAN-CVE-2022-1484
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-26
DEBIAN-CVE-2022-1477
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2022-07-26
DEBIAN-CVE-2022-1481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-26
DEBIAN-CVE-2022-1479
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2022-07-26
DEBIAN-CVE-2022-1486
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-26
DEBIAN-CVE-2022-1485
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2022-07-26
DEBIAN-CVE-2022-1490
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2022-07-26
DEBIAN-CVE-2022-1491
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2022-07-26
DEBIAN-CVE-2022-1493
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-26
DEBIAN-CVE-2022-1501
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-26
DEBIAN-CVE-2022-1482
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-26
DEBIAN-CVE-2022-1498
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-26
DEBIAN-CVE-2022-1494
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-26
DEBIAN-CVE-2022-1492
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-26
DEBIAN-CVE-2022-1499
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-26
DEBIAN-CVE-2022-1500
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-26
DEBIAN-CVE-2022-1495
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-26
DEBIAN-CVE-2022-1488
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-26
DEBIAN-CVE-2022-1497
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-15
fabric8 kubernetes-client vulnerable
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| io.fabric8:kubernetes-client |
affected |
Maven |
io.fabric8:kubernetes-client |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-07-15
fabric8 kubernetes-client vulnerable
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| io.fabric8:kubernetes-client |
affected |
Maven |
io.fabric8:kubernetes-client |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-07-07
fabric8 kubernetes-client vulnerable
CVEs:CVE-2021-4178
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| io.fabric8:kubernetes-client |
affected |
Maven |
io.fabric8:kubernetes-client |
— |
Open SourceActive exploitation (sightings)HIGH2022-07-07
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
CVEs:CVE-2021-4178
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| a-mq_streams |
affected |
redhat |
— |
— |
| build_of_quarkus |
affected |
redhat |
— |
— |
| descision_manager |
affected |
redhat |
— |
— |
| fabric8-kubernetes |
affected |
redhat |
— |
— |
| fuse |
affected |
redhat |
— |
— |
| integration_camel_k |
affected |
redhat |
— |
— |
| integration_camel_quarkus |
affected |
redhat |
— |
— |
| openshift_application_runtimes |
affected |
redhat |
— |
— |
| process_automation |
affected |
redhat |
— |
— |
Open SourcePoC exploit2022-07-20
Fix CVE(s): CVE-2015-20107
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python2.7 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python2.7 |
— |
| libpython2.7 |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7 |
— |
| libpython2.7-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-dev |
— |
| libpython2.7-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-minimal |
— |
| libpython2.7-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-stdlib |
— |
| libpython2.7-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-testsuite |
— |
| python2.7 |
affected |
TuxCare:Ubuntu:16.04 |
python2.7 |
— |
| python2.7-dev |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-dev |
— |
| python2.7-doc |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-doc |
— |
| python2.7-examples |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-examples |
— |
| python2.7-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-minimal |
— |
Open SourcePoC exploit2022-07-20
Fix CVE(s): CVE-2015-20107
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python3.5 |
— |
| libpython3.5 |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5 |
— |
| libpython3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-dev |
— |
| libpython3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-minimal |
— |
| libpython3.5-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-stdlib |
— |
| libpython3.5-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-testsuite |
— |
| python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
python3.5 |
— |
| python3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-dev |
— |
| python3.5-doc |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-doc |
— |
| python3.5-examples |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-examples |
— |
| python3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-minimal |
— |
| python3.5-venv |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-venv |
— |
Open SourcePoC exploitHIGH2022-07-15
Denial of service in chain verification in crypto/x509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploitCRITICAL2022-07-15
Uncontrolled resource consumption in github.com/prometheus/client_golang
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dynamic-localpv-provisioner |
affected |
wolfi |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner |
affected |
chainguard |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| prometheus/client_golang |
affected |
github.com |
github.com/prometheus/client_golang |
— |
| prometheus-postgres-exporter-0.10 |
affected |
chainguard |
prometheus-postgres-exporter-0.10 |
— |
Open SourcePoC exploit2022-07-15
Unbounded memory growth in net/http and golang.org/x/net/http2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
— |
— |
| stdlib |
affected |
Go |
stdlib |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourcePoC exploitHIGH2022-07-07
In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2022-20229
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2022-07-07
CVEs:CVE-2022-20229
Open SourcePoC exploitHIGH2022-07-06
DEBIAN-CVE-2022-30591
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-lucas-clemente-quic-go |
affected |
Debian:11 |
golang-github-lucas-clemente-quic-go |
— |
| golang-github-lucas-clemente-quic-go |
affected |
Debian:12 |
golang-github-lucas-clemente-quic-go |
— |
| golang-github-lucas-clemente-quic-go |
affected |
Debian:13 |
golang-github-lucas-clemente-quic-go |
— |
| golang-github-lucas-clemente-quic-go |
affected |
Debian:14 |
golang-github-lucas-clemente-quic-go |
— |
GooglePoC exploitHIGH2022-08-01
CVEs:CVE-2022-28131
Open SourcePoC exploitCRITICAL2022-07-29
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:20.03-LTS-SP1 |
golang |
— |
| golang |
affected |
openEuler:20.03-LTS-SP3 |
golang |
— |
| golang |
affected |
openEuler:22.03-LTS |
golang |
— |
GooglePoC exploitHIGH2022-07-20
Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.
CVEs:CVE-2022-28131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cloud_insights_telegraf |
affected |
netapp |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploit2022-07-20
Stack exhaustion from deeply nested XML documents in encoding/xml
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploitCRITICAL2022-07-16
Updated golang packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Mageia:8 |
golang |
— |
Open SourcePoC exploitHIGH2022-07-15
CVE-2022-30634 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitHIGH2022-07-28
Path traversal via Clean on Windows in path/filepath
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
GooglePoC exploitHIGH2022-08-01
CVEs:CVE-2022-30633
GooglePoC exploitHIGH2022-07-20
Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag.
CVEs:CVE-2022-30633
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploit2022-07-20
Stack exhaustion when unmarshaling certain documents in encoding/xml
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
GooglePoC exploitHIGH2022-08-01
CVEs:CVE-2022-30630
GooglePoC exploitHIGH2022-08-01
CVEs:CVE-2022-30632
GooglePoC exploitHIGH2022-07-20
Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.
CVEs:CVE-2022-30630
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploit2022-07-20
Stack exhaustion in Glob on certain paths in io/fs
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
GooglePoC exploitHIGH2022-07-20
Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators.
CVEs:CVE-2022-30632
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploit2022-07-20
Stack exhaustion on crafted paths in path/filepath
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
GooglePoC exploitHIGH2022-08-01
CVEs:CVE-2022-30631
GooglePoC exploitHIGH2022-07-20
Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files.
CVEs:CVE-2022-30631
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploit2022-07-20
Stack exhaustion when reading certain archives in compress/gzip
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
GooglePoC exploitHIGH2022-08-01
CVEs:CVE-2022-30635
GooglePoC exploitHIGH2022-07-20
Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.
CVEs:CVE-2022-30635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploit2022-07-20
Stack exhaustion when decoding certain messages in encoding/gob
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploitHIGH2022-07-07
In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is...
CVEs:CVE-2022-20224
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2022-07-07
CVEs:CVE-2022-20224
Open SourcePoC exploitCRITICAL2022-07-28
DEBIAN-CVE-2022-2162
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploit2022-07-26
Empty Cmd.Path can trigger unintended binary in os/exec on Windows
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
GooglePoC exploitCRITICAL2022-07-07
CVEs:CVE-2021-39815
Open SourcePoC exploitCRITICAL2022-07-07
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidV...
CVEs:CVE-2021-39815
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2022-07-07
CVEs:CVE-2022-20122
Open SourcePoC exploitCRITICAL2022-07-07
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidV...
CVEs:CVE-2022-20122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2022-07-07
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges nee...
CVEs:CVE-2022-20223
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2022-07-07
CVEs:CVE-2022-20223
GooglePoC exploitMEDIUM2022-07-07
CVEs:CVE-2022-20227
Open SourcePoC exploitHIGH2022-07-07
In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Androi...
CVEs:CVE-2022-20227
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2022-07-01
ASB-A-216825460
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourceCoalition ESS 30-63%HIGH2022-07-23
DEBIAN-CVE-2022-1134
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-29
Updated chromium-browser-stable packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:8 |
chromium-browser-stable |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2480
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%2022-07-22
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-19
Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2480
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-19
CVEs:CVE-2022-2480
Open SourceCoalition ESS < 30%HIGH2022-07-25
DEBIAN-CVE-2022-1232
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%2022-07-01
Incorrect parsing validation in net/url
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourceCoalition ESS < 30%NONE2022-07-01
Unbounded read from invalid inputs in encoding/binary
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-15
Panic due to large headers in net/http and golang.org/x/net/http/httpguts
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpcurl |
affected |
chainguard |
grpcurl |
— |
| grpcurl |
affected |
wolfi |
grpcurl |
— |
| hey |
affected |
wolfi |
hey |
— |
| hey |
affected |
chainguard |
hey |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| stdlib |
affected |
Go |
stdlib |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourceCoalition ESS < 30%2022-07-01
Insufficiently random values in golang.org/x/crypto/salsa20
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| x/crypto |
affected |
golang.org |
golang.org/x/crypto |
— |
GoogleCoalition ESS < 30%HIGH2022-07-01
ASB-A-231281131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%2022-07-15
Incorrect privilege reporting in syscall and golang.org/x/sys/unix
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ctop |
affected |
chainguard |
ctop |
— |
| ctop |
affected |
wolfi |
ctop |
— |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| dynamic-localpv-provisioner |
affected |
chainguard |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner |
affected |
wolfi |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| grpcurl |
affected |
chainguard |
grpcurl |
— |
| grpcurl |
affected |
wolfi |
grpcurl |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| kind |
affected |
chainguard |
kind |
— |
| kind |
affected |
wolfi |
kind |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| prometheus-postgres-exporter-0.10 |
affected |
chainguard |
prometheus-postgres-exporter-0.10 |
— |
| stdlib |
affected |
Go |
stdlib |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| x/sys |
affected |
golang.org |
golang.org/x/sys |
— |
GoogleCoalition ESS < 30%HIGH2022-07-01
ASB-A-231275475
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-06
Panic in certificate parsing in crypto/x509 and golang.org/x/crypto/cryptobyte
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| stdlib |
affected |
Go |
stdlib |
— |
| x/crypto |
affected |
golang.org |
golang.org/x/crypto |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-28
Heap buffer overflow in WebGL in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2415
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-28
CVEs:CVE-2022-2415
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2415
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2156
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-08-01
CVEs:CVE-2022-1705
GoogleCoalition ESS < 30%MEDIUM2022-07-25
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
CVEs:CVE-2022-1705
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourceCoalition ESS < 30%2022-07-25
Improper sanitization of Transfer-Encoding headers in net/http
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
GoogleCoalition ESS < 30%MEDIUM2022-08-01
CVEs:CVE-2022-32148
GoogleCoalition ESS < 30%MEDIUM2022-07-28
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy ...
CVEs:CVE-2022-32148
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourceCoalition ESS < 30%2022-07-28
Exposure of client IP addresses in net/http
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-21
DEBIAN-CVE-2022-0971
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2010
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-28
DEBIAN-CVE-2022-2481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-07-19
Use after free in Views in Google Chrome prior to 103.0.5060.134 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via UI interaction.
CVEs:CVE-2022-2481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-19
CVEs:CVE-2022-2481
Open SourceCoalition ESS < 30%HIGH2022-07-07
In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2022-20222
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-07
CVEs:CVE-2022-20222
Open SourceCoalition ESS < 30%HIGH2022-07-30
protobuf-c security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf-c |
affected |
openEuler:22.03-LTS |
protobuf-c |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-28
DEBIAN-CVE-2022-2296
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-07-05
Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via direct UI interactions.
CVEs:CVE-2022-2296
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| extra_packages_for_enterprise_linux |
affected |
fedoraproject |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-05
CVEs:CVE-2022-2296
Open SourceCoalition ESS < 30%CRITICAL2022-07-25
DEBIAN-CVE-2022-1310
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%2022-07-28
Session tickets lack random ticket_age_add in crypto/tls
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-13
aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aws-iam-authenticator |
affected |
sigs.k8s.io |
sigs.k8s.io/aws-iam-authenticator |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-13
aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aws-iam-authenticator |
affected |
sigs.k8s.io |
sigs.k8s.io/aws-iam-authenticator |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-12
aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9
CVEs:CVE-2022-2385
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aws-iam-authenticator |
affected |
sigs.k8s.io |
sigs.k8s.io/aws-iam-authenticator |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-12
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
CVEs:CVE-2022-2385
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aws-iam-authenticator |
affected |
kubernetes |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-21
DEBIAN-CVE-2022-0976
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-26
DEBIAN-CVE-2022-1489
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-25
DEBIAN-CVE-2022-1308
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2011
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-28
DEBIAN-CVE-2022-2158
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2008
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-27
DEBIAN-CVE-2022-1853
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2157
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-26
DEBIAN-CVE-2022-1478
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-28
DEBIAN-CVE-2022-2161
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-26
google-cloudstorage-commands Command Injection vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-cloudstorage-commands |
affected |
npm |
google-cloudstorage-commands |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-26
google-cloudstorage-commands Command Injection vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-cloudstorage-commands |
affected |
npm |
google-cloudstorage-commands |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-25
google-cloudstorage-commands Command Injection vulnerability
CVEs:CVE-2020-28436
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-cloudstorage-commands |
affected |
npm |
google-cloudstorage-commands |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-25
This affects all versions of package google-cloudstorage-commands.
CVEs:CVE-2020-28436
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-cloudstorage-commands |
affected |
google-cloudstorage-commands_project |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-25
google-cloudstorage-commands Command Injection vulnerability
CVEs:CVE-2020-28436
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-cloudstorage-commands |
affected |
npm |
google-cloudstorage-commands |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2007
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-25
DEBIAN-CVE-2022-1313
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-25
DEBIAN-CVE-2022-1305
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-25
DEBIAN-CVE-2022-1314
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-27
DEBIAN-CVE-2022-1873
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-26
DEBIAN-CVE-2022-1641
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-21
DEBIAN-CVE-2022-0977
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-27
DEBIAN-CVE-2022-1869
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-08-01
CVEs:CVE-2022-1962
GoogleCoalition ESS < 30%MEDIUM2022-07-20
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.
CVEs:CVE-2022-1962
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-20
Stack exhaustion due to deeply nested types in go/parser
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-23
DEBIAN-CVE-2022-1125
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-23
DEBIAN-CVE-2022-1139
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-27
DEBIAN-CVE-2022-1855
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-27
DEBIAN-CVE-2022-1874
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-23
DEBIAN-CVE-2022-1127
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-23
DEBIAN-CVE-2022-1146
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-23
DEBIAN-CVE-2022-1131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-23
DEBIAN-CVE-2022-1133
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-21
DEBIAN-CVE-2022-0973
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-23
DEBIAN-CVE-2022-1138
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-26
DEBIAN-CVE-2022-1639
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-26
DEBIAN-CVE-2022-1640
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-25
DEBIAN-CVE-2022-1311
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-22
DEBIAN-CVE-2022-0978
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-21
DEBIAN-CVE-2022-0974
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-21
DEBIAN-CVE-2022-0975
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-26
DEBIAN-CVE-2022-1496
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-23
DEBIAN-CVE-2022-1135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-25
DEBIAN-CVE-2022-1309
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-23
DEBIAN-CVE-2022-1143
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-26
DEBIAN-CVE-2022-1636
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-27
DEBIAN-CVE-2022-1854
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2478
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-07-19
CVEs:CVE-2022-2478
GoogleCoalition ESS < 30%CRITICAL2022-07-19
Use after free in PDF in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2478
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-22
DEBIAN-CVE-2022-0979
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-28
DEBIAN-CVE-2022-2165
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-27
DEBIAN-CVE-2022-1867
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-23
DEBIAN-CVE-2022-1141
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-26
DEBIAN-CVE-2022-1637
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-23
DEBIAN-CVE-2022-1130
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-27
DEBIAN-CVE-2022-1857
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-27
DEBIAN-CVE-2022-1866
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2477
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-07-19
CVEs:CVE-2022-2477
GoogleCoalition ESS < 30%CRITICAL2022-07-19
Use after free in Guest View in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2477
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-23
DEBIAN-CVE-2022-1129
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-26
DEBIAN-CVE-2022-1633
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-26
DEBIAN-CVE-2022-1634
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-26
DEBIAN-CVE-2022-1635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-27
DEBIAN-CVE-2022-1859
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-21
DEBIAN-CVE-2022-0972
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2163
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-28
DEBIAN-CVE-2022-2479
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-07-19
Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file directories via a ...
CVEs:CVE-2022-2479
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-19
CVEs:CVE-2022-2479
Open SourceCoalition ESS < 30%MEDIUM2022-07-25
DEBIAN-CVE-2022-1306
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-25
DEBIAN-CVE-2022-1307
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-27
DEBIAN-CVE-2022-1860
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-27
DEBIAN-CVE-2022-1861
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-23
DEBIAN-CVE-2022-1142
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-27
DEBIAN-CVE-2022-1858
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-27
DEBIAN-CVE-2022-1875
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-26
DEBIAN-CVE-2022-1638
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-07-23
Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
CVEs:CVE-2022-1144
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-23
CVEs:CVE-2022-1144
Open SourceCoalition ESS < 30%HIGH2022-07-23
DEBIAN-CVE-2022-1144
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-27
DEBIAN-CVE-2022-1876
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-23
DEBIAN-CVE-2022-1128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-07-28
CVEs:CVE-2022-2399
GoogleCoalition ESS < 30%CRITICAL2022-07-28
Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2399
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2399
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-28
DEBIAN-CVE-2022-2160
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-23
DEBIAN-CVE-2022-1145
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-28
Jenkins Android Signing Plugin allows attackers to check whether attacker-specified file patterns match workspace contents
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:android-signing |
affected |
Maven |
org.jenkins-ci.plugins:android-signing |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-28
Jenkins Android Signing Plugin allows attackers to check whether attacker-specified file patterns match workspace contents
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:android-signing |
affected |
Maven |
org.jenkins-ci.plugins:android-signing |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-27
Jenkins Android Signing Plugin allows attackers to check whether attacker-specified file patterns match workspace contents
CVEs:CVE-2022-36915
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:android-signing |
affected |
Maven |
org.jenkins-ci.plugins:android-signing |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-27
Jenkins Android Signing Plugin 2.2.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacke...
CVEs:CVE-2022-36915
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_signing |
affected |
jenkins |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-23
DEBIAN-CVE-2022-1137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-28
DEBIAN-CVE-2022-2164
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-23
DEBIAN-CVE-2022-1136
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-25
DEBIAN-CVE-2022-1312
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-07-17
The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
CVEs:CVE-2022-1672
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| insights_from_google_pagespeed |
affected |
insights_from_google_pagespeed_project |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-17
CVEs:CVE-2022-1672
Open SourceCoalition ESS < 30%CRITICAL2022-07-27
DEBIAN-CVE-2022-1870
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-27
DEBIAN-CVE-2022-1856
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-07
In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.P...
CVEs:CVE-2022-20228
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-07
CVEs:CVE-2022-20228
Open SourceCoalition ESS < 30%MEDIUM2022-07-27
DEBIAN-CVE-2022-1868
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-22
DEBIAN-CVE-2022-0980
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-27
DEBIAN-CVE-2022-1862
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-28
Jenkins Google Cloud Backup Plugin allows attackers with Overall/Read permission to request a manual backup.
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-cloud-backup |
affected |
Maven |
org.jenkins-ci.plugins:google-cloud-backup |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-28
Jenkins Google Cloud Backup Plugin allows attackers with Overall/Read permission to request a manual backup.
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-cloud-backup |
affected |
Maven |
org.jenkins-ci.plugins:google-cloud-backup |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-27
A missing permission check in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers with Overall/Read permission to request a manual backup.
CVEs:CVE-2022-36917
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_cloud_backup |
affected |
jenkins |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-27
Jenkins Google Cloud Backup Plugin allows attackers with Overall/Read permission to request a manual backup.
CVEs:CVE-2022-36917
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-cloud-backup |
affected |
Maven |
org.jenkins-ci.plugins:google-cloud-backup |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-27
DEBIAN-CVE-2022-1863
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-27
DEBIAN-CVE-2022-1864
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-27
DEBIAN-CVE-2022-1865
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-27
DEBIAN-CVE-2022-1871
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-27
DEBIAN-CVE-2022-1872
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-07
CVEs:CVE-2022-20216
Open SourceCoalition ESS < 30%HIGH2022-07-07
android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.sprd.firewall has set exported as true.Product: AndroidVersions: Android SoCAndroid ID: A-231911916
CVEs:CVE-2022-20216
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-07
'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploited...
CVEs:CVE-2022-20238
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-07
CVEs:CVE-2022-20238
GoogleCoalition ESS < 30%2022-07-01
ASB-A-231911916
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2022-07-01
ASB-A-233154555
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-28
CSRF vulnerability in Jenkins Google Cloud Backup Plugin
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-cloud-backup |
affected |
Maven |
org.jenkins-ci.plugins:google-cloud-backup |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-28
CSRF vulnerability in Jenkins Google Cloud Backup Plugin
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-cloud-backup |
affected |
Maven |
org.jenkins-ci.plugins:google-cloud-backup |
— |
GoogleCoalition ESS < 30%HIGH2022-07-27
A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup.
CVEs:CVE-2022-36916
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_cloud_backup |
affected |
jenkins |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-27
CSRF vulnerability in Jenkins Google Cloud Backup Plugin
CVEs:CVE-2022-36916
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-cloud-backup |
affected |
Maven |
org.jenkins-ci.plugins:google-cloud-backup |
— |
GoogleCoalition ESS < 30%HIGH2022-07-07
CVEs:CVE-2022-20236
Open SourceCoalition ESS < 30%HIGH2022-07-07
A drm driver have oob problem, could cause the system crash or EOPProduct: AndroidVersions: Android SoCAndroid ID: A-233124709
CVEs:CVE-2022-20236
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-01
ASB-A-233124709
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-13
In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName' and 'pkgTitle' from user.An unprivileged app can use a malicous mComponentName with a benign pkgTitle ...
CVEs:CVE-2022-20234
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-13
CVEs:CVE-2022-20234
GoogleCoalition ESS < 30%HIGH2022-07-06
CVEs:CVE-2022-21767
Open SourceCoalition ESS < 30%HIGH2022-07-06
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0678443...
CVEs:CVE-2022-21767
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-06
CVEs:CVE-2022-21768
Open SourceCoalition ESS < 30%HIGH2022-07-06
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0678435...
CVEs:CVE-2022-21768
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-01
ASB-A-231275476
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-07-01
ASB-A-231281132
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-07-07
There is a unauthorized broadcast in the SprdContactsProvider. A third-party app could use this issue to delete Fdn contact.Product: AndroidVersions: Android SoCAndroid ID: A-232441378
CVEs:CVE-2022-20217
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-07
CVEs:CVE-2022-20217
GoogleCoalition ESS < 30%2022-07-01
ASB-A-232441378
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-29
Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release.
CVEs:CVE-2022-1799
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_play_services_software_development_kit |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-07-29
CVEs:CVE-2022-1799
Open SourceCoalition ESS < 30%MEDIUM2022-07-23
DEBIAN-CVE-2022-1132
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-07
CVEs:CVE-2022-20221
Open SourceCoalition ESS < 30%MEDIUM2022-07-07
In avrc_ctrl_pars_vendor_cmd of avrc_pars_ct.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction i...
CVEs:CVE-2022-20221
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-07
CVEs:CVE-2022-20220
Open SourceCoalition ESS < 30%HIGH2022-07-07
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2022-20220
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-07-01
ASB-A-209075540
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Improper validation of integrity check vulnerability in Samsung USB Driver Windows Installer for Mobile Phones prior to version 1.7.56.0 allows local attackers to delete arbitrary directory using directory junction.
CVEs:CVE-2022-33711
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_usb_driver |
affected |
samsung |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-12
CVEs:CVE-2022-33711
Open SourceCoalition ESS < 30%HIGH2022-07-12
Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of AppLinker.
CVEs:CVE-2022-30754
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-12
CVEs:CVE-2022-30754
GoogleCoalition ESS < 30%HIGH2022-07-12
CVEs:CVE-2022-30756
Open SourceCoalition ESS < 30%HIGH2022-07-12
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder.
CVEs:CVE-2022-30756
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-06
In sound driver, there is a possible information disclosure due to symlink following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558663; Issu...
CVEs:CVE-2022-21770
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21770
GoogleCoalition ESS < 30%2022-07-01
PUB-A-213241418
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-13
In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...
CVEs:CVE-2022-20218
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-13
CVEs:CVE-2022-20218
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33690
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Improper input validation in Contacts Storage prior to SMR Jul-2022 Release 1 allows attacker to access arbitrary file.
CVEs:CVE-2022-33690
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21769
Open SourceCoalition ESS < 30%MEDIUM2022-07-06
In CCCI, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID: A...
CVEs:CVE-2022-21769
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-13
CVEs:CVE-2022-20212
Open SourceCoalition ESS < 30%HIGH2022-07-13
In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploi...
CVEs:CVE-2022-20212
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-06
In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID:...
CVEs:CVE-2022-21765
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21765
Open SourceCoalition ESS < 30%HIGH2022-07-06
In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID:...
CVEs:CVE-2022-21766
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21766
GoogleCoalition ESS < 30%HIGH2022-07-12
CVEs:CVE-2022-33704
Open SourceCoalition ESS < 30%CRITICAL2022-07-12
Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-33704
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21783
Open SourceCoalition ESS < 30%HIGH2022-07-06
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Is...
CVEs:CVE-2022-21783
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21784
Open SourceCoalition ESS < 30%HIGH2022-07-06
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Is...
CVEs:CVE-2022-21784
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21785
Open SourceCoalition ESS < 30%HIGH2022-07-06
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06807363; Is...
CVEs:CVE-2022-21785
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21786
Open SourceCoalition ESS < 30%HIGH2022-07-06
In audio DSP, there is a possible memory corruption due to improper casting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558822; Issue ID: AL...
CVEs:CVE-2022-21786
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-06
In audio DSP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558844; Issu...
CVEs:CVE-2022-21787
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21787
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21779
Open SourceCoalition ESS < 30%HIGH2022-07-06
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Is...
CVEs:CVE-2022-21779
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-06
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Is...
CVEs:CVE-2022-21780
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21780
Open SourceCoalition ESS < 30%HIGH2022-07-06
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Is...
CVEs:CVE-2022-21781
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21781
Open SourceCoalition ESS < 30%HIGH2022-07-06
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Is...
CVEs:CVE-2022-21782
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21782
GoogleCoalition ESS < 30%MEDIUM2022-07-12
CVEs:CVE-2022-33685
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.
CVEs:CVE-2022-33685
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-12
Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.
CVEs:CVE-2022-30755
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-12
CVEs:CVE-2022-30755
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
CVEs:CVE-2022-33686
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33686
Open SourceCoalition ESS < 30%LOW2022-07-07
In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Pr...
CVEs:CVE-2022-20226
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-07
CVEs:CVE-2022-20226
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.
CVEs:CVE-2022-33687
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33687
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33688
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.
CVEs:CVE-2022-33688
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33692
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.
CVEs:CVE-2022-33692
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
CVEs:CVE-2022-33693
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33693
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33694
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wifi information via unprotected intent broadcasting.
CVEs:CVE-2022-33694
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.
CVEs:CVE-2022-33696
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33696
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33697
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.
CVEs:CVE-2022-33697
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33698
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.
CVEs:CVE-2022-33698
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
CVEs:CVE-2022-33699
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33699
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
CVEs:CVE-2022-33700
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33700
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with privilege of Finder.
CVEs:CVE-2022-30758
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-12
CVEs:CVE-2022-30758
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21763
Open SourceCoalition ESS < 30%MEDIUM2022-07-06
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:...
CVEs:CVE-2022-21763
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21764
Open SourceCoalition ESS < 30%MEDIUM2022-07-06
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:...
CVEs:CVE-2022-21764
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-06
In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS067138...
CVEs:CVE-2022-21777
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-06
CVEs:CVE-2022-21777
GoogleCoalition ESS < 30%MEDIUM2022-07-01
ASB-A-231271468
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-01
ASB-A-231275473
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-07-12
CVEs:CVE-2022-33695
Open SourceCoalition ESS < 30%HIGH2022-07-12
Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.
CVEs:CVE-2022-33695
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.
CVEs:CVE-2022-30757
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-30757
GoogleCoalition ESS < 30%MEDIUM2022-07-07
CVEs:CVE-2022-20225
Open SourceCoalition ESS < 30%MEDIUM2022-07-07
In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User intera...
CVEs:CVE-2022-20225
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%NONE2022-07-15
Improper input validation in github.com/google/go-attestation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/go-attestation |
affected |
github.com |
— |
— |
| google/go-attestation |
affected |
github.com |
github.com/google/go-attestation |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-12
Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.
CVEs:CVE-2022-33689
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33689
Open SourceCoalition ESS < 30%HIGH2022-07-12
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.
CVEs:CVE-2022-30752
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-30752
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-30750
Open SourceCoalition ESS < 30%LOW2022-07-12
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.
CVEs:CVE-2022-30750
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-30751
Open SourceCoalition ESS < 30%LOW2022-07-12
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.
CVEs:CVE-2022-30751
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%LOW2022-07-12
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.
CVEs:CVE-2022-30753
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-30753
Open SourceCoalition ESS < 30%MEDIUM2022-07-07
In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed...
CVEs:CVE-2022-20230
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-07
CVEs:CVE-2022-20230
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.
CVEs:CVE-2022-33702
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-12
CVEs:CVE-2022-33702
Open SourceCoalition ESS < 30%LOW2022-07-12
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.
CVEs:CVE-2022-33701
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-07-12
CVEs:CVE-2022-33701
Open SourceCoalition ESS < 30%HIGH2022-07-06
In GED driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641585; Issue ID: ALPS...
CVEs:CVE-2022-21771
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21771
Open SourceCoalition ESS < 30%MEDIUM2022-07-06
In TEEI driver, there is a possible type confusion due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493842; Issue ID: ALP...
CVEs:CVE-2022-21772
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21772
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21773
Open SourceCoalition ESS < 30%HIGH2022-07-06
In TEEI driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641388; Issue ID: ALP...
CVEs:CVE-2022-21773
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-07-06
In TEEI driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641447; Issue ID: ALP...
CVEs:CVE-2022-21774
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21774
Open SourceCoalition ESS < 30%HIGH2022-07-06
In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479032; Issue ID: AL...
CVEs:CVE-2022-21775
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21775
Open SourceCoalition ESS < 30%HIGH2022-07-06
In MDP, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545450; Issue ID: ALPS06545450.
CVEs:CVE-2022-21776
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-06
CVEs:CVE-2022-21776
Open SourceCoalition ESS < 30%HIGH2022-07-12
Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2022-33703
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-12
CVEs:CVE-2022-33703
Open SourceCoalition ESS < 30%HIGH2022-07-06
In GPU, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044730; Issue ID: ALPS...
CVEs:CVE-2022-20082
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-07-06
CVEs:CVE-2022-20082
GoogleCoalition ESS < 30%MEDIUM2022-07-07
CVEs:CVE-2022-20219
Open SourceCoalition ESS < 30%MEDIUM2022-07-07
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no additional execut...
CVEs:CVE-2022-20219
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-07-12
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations.
CVEs:CVE-2022-33691
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-07-12
CVEs:CVE-2022-33691
Open SourceEPSS <= 49%2022-07-06
Panic on unconsidered isindex and template combination in golang.org/x/net/html
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourceEPSS <= 49%2022-07-01
Incorrect parsing of nested templates in golang.org/x/net/html
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourceEPSS <= 49%2022-07-01
Panic when parsing certain inputs in golang.org/x/net/html
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| hey |
affected |
chainguard |
hey |
— |
| hey |
affected |
wolfi |
hey |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourceEPSS <= 49%2022-07-01
Incorrect computation for P-256 curves in crypto/elliptic
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| stdlib |
affected |
Go |
stdlib |
— |
GoogleEPSS <= 49%MEDIUM2022-07-08
Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-login |
affected |
Maven |
org.jenkins-ci.plugins:google-login |
— |
GoogleEPSS <= 49%MEDIUM2022-07-08
Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-login |
affected |
Maven |
org.jenkins-ci.plugins:google-login |
— |
GoogleEPSS <= 49%MEDIUM2022-07-07
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.
CVEs:CVE-2015-5298
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_login |
affected |
jenkins |
— |
— |
GoogleEPSS <= 49%MEDIUM2022-07-07
Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
CVEs:CVE-2015-5298
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-login |
affected |
Maven |
org.jenkins-ci.plugins:google-login |
— |
Open SourceAll remainingHIGH2022-07-13
UNKNOWN WRITE in SkMaskBlurFilter::blur
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| skia |
affected |
OSS-Fuzz |
skia |
— |