GO-2022-0535
Certificate validation bypass on Windows in crypto/x509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 16 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Certificate validation bypass on Windows in crypto/x509
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3038
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3038
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple ...
CVEs:CVE-2022-32893
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| safari | affected | apple | — | — |
| webkitgtk | affected | webkitgtk | — | — |
| wpe_webkit | affected | wpewebkit | — | — |
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2022-32893
CVEs:CVE-2022-32893
PUB-A-227638011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
CVEs:CVE-2022-2856
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
CVEs:CVE-2022-2856
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2856
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2022-32894
CVEs:CVE-2022-32894
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a repor...
CVEs:CVE-2022-32894
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| watchos | affected | apple | — | — |
Improper input validation in net/http and net/http/cgi
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
DEBIAN-CVE-2022-2623
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-2623
Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
CVEs:CVE-2022-2623
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User in...
CVEs:CVE-2022-20361
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20361
ASB-A-233078742
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-20400
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2022-20400
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-225178325
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In LteRrcNrProAsnDecode of LteRrcNr_Codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2022-20375
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20375
PUB-A-180956894
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20401
In SAEMM_RetrievEPLMNList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post-authentication with no additional execution privileges needed. User inte...
CVEs:CVE-2022-20401
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-226446030
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20345
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2022-20345
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20403
Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A
CVEs:CVE-2022-20403
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-207975764
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A
CVEs:CVE-2022-20378
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20378
PUB-A-234657153
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20381
Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A
CVEs:CVE-2022-20381
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-188935887
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20407
Product: AndroidVersions: Android kernelAndroid ID: A-210916981References: N/A
CVEs:CVE-2022-20407
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-210916981
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20380
Product: AndroidVersions: Android kernelAndroid ID: A-212625740References: N/A
CVEs:CVE-2022-20380
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Product: AndroidVersions: Android kernelAndroid ID: A-205714161References: N/A
CVEs:CVE-2022-20404
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20404
Product: AndroidVersions: Android kernelAndroid ID: A-184676385References: N/A
CVEs:CVE-2022-20406
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20406
Product: AndroidVersions: Android kernelAndroid ID: A-204782372References: N/A
CVEs:CVE-2022-20408
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20408
The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicAddr, and then copies the buffer to userspace. The method PMR_PDumpSymbolicAddr may fail, and if it does the buf...
CVEs:CVE-2021-0946
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0946
CVEs:CVE-2021-0947
The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspace. The method TLServerDiscoverStreamsKM may fail for several reasons inc...
CVEs:CVE-2021-0947
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-236838960
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-236846966
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-184676385
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-204782372
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-205714161
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-212625740
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-0891
An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Product: AndroidVersions: Android SoCAndroid ID: A-236849490
CVEs:CVE-2021-0891
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-236849490
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2022-20360
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20360
ASB-A-231156274
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2022-20348
In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. Us...
CVEs:CVE-2022-20348
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improper input validation. This could lead to local escalation of privilege with no additional execution priv...
CVEs:CVE-2022-20356
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20356
In ioctl_dpm_clk_update of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2022-20366
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20366
PUB-A-225877745
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In exynos5_i2c_irq of (TBD), there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...
CVEs:CVE-2022-20372
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20372
PUB-A-195480799
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20377
In TBD of keymaster_ipc.cpp, there is a possible to force gatekeeper, fingerprint, and faceauth to use a known HMAC key. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-20377
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-222339795
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20180
In several functions of mali_gralloc_reference.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2022-20180
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2022-20357
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20357
PUB-A-212804042
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2021-0698
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0698
In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2021-0887
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0887
ASB-A-236848165
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-236848817
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In dm_bow_dtr and related functions of dm-bow.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2022-20371
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20371
CVEs:CVE-2022-20373
In st21nfc_loc_set_polaritymode of fc/st21nfc.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2022-20373
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-195565510
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-208269510
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Reset flood in net/http and golang.org/x/net/http
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| stdlib | affected | Go | stdlib | — |
| x/net | affected | golang.org | golang.org/x/net | — |
PUB-A-228560328
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Red Hat Security Advisory: OpenShift Container Platform 4.11.0 packages and security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| afterburn | affected | Red Hat:openshift:4.11::el8 | afterburn | — |
| afterburn-debuginfo | affected | Red Hat:openshift:4.11::el8 | afterburn-debuginfo | — |
| atomic-openshift-service-idler | affected | Red Hat:openshift:4.11::el8 | atomic-openshift-service-idler | — |
| bootupd | affected | Red Hat:openshift:4.11::el8 | bootupd | — |
| bootupd-debuginfo | affected | Red Hat:openshift:4.11::el8 | bootupd-debuginfo | — |
| buildah | affected | Red Hat:openshift:4.11::el8 | buildah | — |
| buildah-debuginfo | affected | Red Hat:openshift:4.11::el8 | buildah-debuginfo | — |
| buildah-debugsource | affected | Red Hat:openshift:4.11::el8 | buildah-debugsource | — |
| buildah-tests | affected | Red Hat:openshift:4.11::el8 | buildah-tests | — |
| buildah-tests-debuginfo | affected | Red Hat:openshift:4.11::el8 | buildah-tests-debuginfo | — |
| butane | affected | Red Hat:openshift:4.11::el8 | butane | — |
| butane-debuginfo | affected | Red Hat:openshift:4.11::el8 | butane-debuginfo | — |
| butane-debugsource | affected | Red Hat:openshift:4.11::el8 | butane-debugsource | — |
| butane-redistributable | affected | Red Hat:openshift:4.11::el8 | butane-redistributable | — |
| conmon | affected | Red Hat:openshift:4.11::el8 | conmon | — |
| conmon-debuginfo | affected | Red Hat:openshift:4.11::el8 | conmon-debuginfo | — |
| conmon-debugsource | affected | Red Hat:openshift:4.11::el8 | conmon-debugsource | — |
| console-login-helper-messages | affected | Red Hat:openshift:4.11::el8 | console-login-helper-messages | — |
| console-login-helper-messages-issuegen | affected | Red Hat:openshift:4.11::el8 | console-login-helper-messages-issuegen | — |
| console-login-helper-messages-profile | affected | Red Hat:openshift:4.11::el8 | console-login-helper-messages-profile | — |
| containernetworking-plugins | affected | Red Hat:openshift:4.11::el8 | containernetworking-plugins | — |
| containernetworking-plugins-debuginfo | affected | Red Hat:openshift:4.11::el8 | containernetworking-plugins-debuginfo | — |
| containernetworking-plugins-debugsource | affected | Red Hat:openshift:4.11::el8 | containernetworking-plugins-debugsource | — |
| containers-common | affected | Red Hat:openshift:4.11::el8 | containers-common | — |
| container-selinux | affected | Red Hat:openshift:4.11::el8 | container-selinux | — |
| coreos-installer | affected | Red Hat:openshift:4.11::el8 | coreos-installer | — |
| coreos-installer-bootinfra | affected | Red Hat:openshift:4.11::el8 | coreos-installer-bootinfra | — |
| coreos-installer-bootinfra-debuginfo | affected | Red Hat:openshift:4.11::el8 | coreos-installer-bootinfra-debuginfo | — |
| coreos-installer-debuginfo | affected | Red Hat:openshift:4.11::el8 | coreos-installer-debuginfo | — |
| coreos-installer-debugsource | affected | Red Hat:openshift:4.11::el8 | coreos-installer-debugsource | — |
| cri-o | affected | Red Hat:openshift:4.11::el8 | cri-o | — |
| cri-o-debuginfo | affected | Red Hat:openshift:4.11::el8 | cri-o-debuginfo | — |
| cri-o-debugsource | affected | Red Hat:openshift:4.11::el8 | cri-o-debugsource | — |
| crit | affected | Red Hat:openshift:4.11::el8 | crit | — |
| cri-tools | affected | Red Hat:openshift:4.11::el8 | cri-tools | — |
| cri-tools-debuginfo | affected | Red Hat:openshift:4.11::el8 | cri-tools-debuginfo | — |
| cri-tools-debugsource | affected | Red Hat:openshift:4.11::el8 | cri-tools-debugsource | — |
| criu | affected | Red Hat:openshift:4.11::el8 | criu | — |
| criu-debuginfo | affected | Red Hat:openshift:4.11::el8 | criu-debuginfo | — |
| criu-debugsource | affected | Red Hat:openshift:4.11::el8 | criu-debugsource | — |
| criu-devel | affected | Red Hat:openshift:4.11::el8 | criu-devel | — |
| criu-libs | affected | Red Hat:openshift:4.11::el8 | criu-libs | — |
| criu-libs-debuginfo | affected | Red Hat:openshift:4.11::el8 | criu-libs-debuginfo | — |
| crun | affected | Red Hat:openshift:4.11::el8 | crun | — |
| crun-debuginfo | affected | Red Hat:openshift:4.11::el8 | crun-debuginfo | — |
| crun-debugsource | affected | Red Hat:openshift:4.11::el8 | crun-debugsource | — |
| fuse-overlayfs | affected | Red Hat:openshift:4.11::el8 | fuse-overlayfs | — |
| fuse-overlayfs-debuginfo | affected | Red Hat:openshift:4.11::el8 | fuse-overlayfs-debuginfo | — |
| fuse-overlayfs-debugsource | affected | Red Hat:openshift:4.11::el8 | fuse-overlayfs-debugsource | — |
| haproxy | affected | Red Hat:openshift:4.11::el8 | haproxy | — |
| haproxy22 | affected | Red Hat:openshift:4.11::el8 | haproxy22 | — |
| haproxy22-debuginfo | affected | Red Hat:openshift:4.11::el8 | haproxy22-debuginfo | — |
| haproxy-debugsource | affected | Red Hat:openshift:4.11::el8 | haproxy-debugsource | — |
| ignition | affected | Red Hat:openshift:4.11::el8 | ignition | — |
| ignition-debuginfo | affected | Red Hat:openshift:4.11::el8 | ignition-debuginfo | — |
| ignition-debugsource | affected | Red Hat:openshift:4.11::el8 | ignition-debugsource | — |
| ignition-validate | affected | Red Hat:openshift:4.11::el8 | ignition-validate | — |
| ignition-validate-debuginfo | affected | Red Hat:openshift:4.11::el8 | ignition-validate-debuginfo | — |
| kata-containers | affected | Red Hat:openshift:4.11::el8 | kata-containers | — |
| libslirp | affected | Red Hat:openshift:4.11::el8 | libslirp | — |
| libslirp-debuginfo | affected | Red Hat:openshift:4.11::el8 | libslirp-debuginfo | — |
| libslirp-debugsource | affected | Red Hat:openshift:4.11::el8 | libslirp-debugsource | — |
| libslirp-devel | affected | Red Hat:openshift:4.11::el8 | libslirp-devel | — |
| libsodium | affected | Red Hat:openshift_ironic:4.11::el8 | libsodium | — |
| libsodium-debuginfo | affected | Red Hat:openshift_ironic:4.11::el8 | libsodium-debuginfo | — |
| libsodium-debugsource | affected | Red Hat:openshift_ironic:4.11::el8 | libsodium-debugsource | — |
| libsodium-devel | affected | Red Hat:openshift_ironic:4.11::el8 | libsodium-devel | — |
| libsodium-static | affected | Red Hat:openshift_ironic:4.11::el8 | libsodium-static | — |
| network-scripts-openvswitch2.17 | affected | Red Hat:openshift:4.11::el8 | network-scripts-openvswitch2.17 | — |
| openshift | affected | Red Hat:openshift:4.11::el8 | openshift | — |
| openshift-ansible | affected | Red Hat:openshift:4.11::el8 | openshift-ansible | — |
| openshift-ansible-test | affected | Red Hat:openshift:4.11::el8 | openshift-ansible-test | — |
| openshift-clients | affected | Red Hat:openshift:4.11::el8 | openshift-clients | — |
| openshift-clients-redistributable | affected | Red Hat:openshift:4.11::el8 | openshift-clients-redistributable | — |
| openshift-hyperkube | affected | Red Hat:openshift:4.11::el8 | openshift-hyperkube | — |
| openshift-kuryr | affected | Red Hat:openshift:4.11::el8 | openshift-kuryr | — |
| openshift-kuryr-cni | affected | Red Hat:openshift:4.11::el8 | openshift-kuryr-cni | — |
| openshift-kuryr-common | affected | Red Hat:openshift:4.11::el8 | openshift-kuryr-common | — |
| openshift-kuryr-controller | affected | Red Hat:openshift:4.11::el8 | openshift-kuryr-controller | — |
| openstack-ironic | affected | Red Hat:openshift_ironic:4.11::el8 | openstack-ironic | — |
| openstack-ironic-api | affected | Red Hat:openshift_ironic:4.11::el8 | openstack-ironic-api | — |
| openstack-ironic-common | affected | Red Hat:openshift_ironic:4.11::el8 | openstack-ironic-common | — |
| openstack-ironic-conductor | affected | Red Hat:openshift_ironic:4.11::el8 | openstack-ironic-conductor | — |
| openstack-ironic-inspector | affected | Red Hat:openshift_ironic:4.11::el8 | openstack-ironic-inspector | — |
| openstack-ironic-inspector-api | affected | Red Hat:openshift_ironic:4.11::el8 | openstack-ironic-inspector-api | — |
| openstack-ironic-inspector-conductor | affected | Red Hat:openshift_ironic:4.11::el8 | openstack-ironic-inspector-conductor | — |
| openstack-ironic-inspector-dnsmasq | affected | Red Hat:openshift_ironic:4.11::el8 | openstack-ironic-inspector-dnsmasq | — |
| openstack-ironic-python-agent | affected | Red Hat:openshift_ironic:4.11::el8 | openstack-ironic-python-agent | — |
| openvswitch2.17 | affected | Red Hat:openshift:4.11::el8 | openvswitch2.17 | — |
| openvswitch2.17-debuginfo | affected | Red Hat:openshift:4.11::el8 | openvswitch2.17-debuginfo | — |
| openvswitch2.17-debugsource | affected | Red Hat:openshift:4.11::el8 | openvswitch2.17-debugsource | — |
| openvswitch2.17-devel | affected | Red Hat:openshift:4.11::el8 | openvswitch2.17-devel | — |
| openvswitch2.17-ipsec | affected | Red Hat:openshift:4.11::el8 | openvswitch2.17-ipsec | — |
| openvswitch2.17-test | affected | Red Hat:openshift:4.11::el8 | openvswitch2.17-test | — |
| ovn22.03 | affected | Red Hat:openshift:4.11::el8 | ovn22.03 | — |
| ovn22.03-central | affected | Red Hat:openshift:4.11::el8 | ovn22.03-central | — |
| ovn22.03-central-debuginfo | affected | Red Hat:openshift:4.11::el8 | ovn22.03-central-debuginfo | — |
| ovn22.03-debuginfo | affected | Red Hat:openshift:4.11::el8 | ovn22.03-debuginfo | — |
| ovn22.03-debugsource | affected | Red Hat:openshift:4.11::el8 | ovn22.03-debugsource | — |
| ovn22.03-host | affected | Red Hat:openshift:4.11::el8 | ovn22.03-host | — |
| ovn22.03-host-debuginfo | affected | Red Hat:openshift:4.11::el8 | ovn22.03-host-debuginfo | — |
| ovn22.03-vtep | affected | Red Hat:openshift:4.11::el8 | ovn22.03-vtep | — |
| ovn22.03-vtep-debuginfo | affected | Red Hat:openshift:4.11::el8 | ovn22.03-vtep-debuginfo | — |
| ovn22.06 | affected | Red Hat:openshift:4.11::el8 | ovn22.06 | — |
| ovn22.06-central | affected | Red Hat:openshift:4.11::el8 | ovn22.06-central | — |
| ovn22.06-central-debuginfo | affected | Red Hat:openshift:4.11::el8 | ovn22.06-central-debuginfo | — |
| ovn22.06-debuginfo | affected | Red Hat:openshift:4.11::el8 | ovn22.06-debuginfo | — |
| ovn22.06-debugsource | affected | Red Hat:openshift:4.11::el8 | ovn22.06-debugsource | — |
| ovn22.06-host | affected | Red Hat:openshift:4.11::el8 | ovn22.06-host | — |
| ovn22.06-host-debuginfo | affected | Red Hat:openshift:4.11::el8 | ovn22.06-host-debuginfo | — |
| ovn22.06-vtep | affected | Red Hat:openshift:4.11::el8 | ovn22.06-vtep | — |
| ovn22.06-vtep-debuginfo | affected | Red Hat:openshift:4.11::el8 | ovn22.06-vtep-debuginfo | — |
| podman | affected | Red Hat:openshift:4.11::el8 | podman | — |
| podman-catatonit | affected | Red Hat:openshift:4.11::el8 | podman-catatonit | — |
| podman-catatonit-debuginfo | affected | Red Hat:openshift:4.11::el8 | podman-catatonit-debuginfo | — |
| podman-debuginfo | affected | Red Hat:openshift:4.11::el8 | podman-debuginfo | — |
| podman-debugsource | affected | Red Hat:openshift:4.11::el8 | podman-debugsource | — |
| podman-docker | affected | Red Hat:openshift:4.11::el8 | podman-docker | — |
| podman-gvproxy-debuginfo | affected | Red Hat:openshift:4.11::el8 | podman-gvproxy-debuginfo | — |
| podman-plugins | affected | Red Hat:openshift:4.11::el8 | podman-plugins | — |
| podman-plugins-debuginfo | affected | Red Hat:openshift:4.11::el8 | podman-plugins-debuginfo | — |
| podman-remote | affected | Red Hat:openshift:4.11::el8 | podman-remote | — |
| podman-remote-debuginfo | affected | Red Hat:openshift:4.11::el8 | podman-remote-debuginfo | — |
| podman-tests | affected | Red Hat:openshift:4.11::el8 | podman-tests | — |
| pycdlib-tools | affected | Red Hat:openshift_ironic:4.11::el8 | pycdlib-tools | — |
| pyparsing | affected | Red Hat:openshift_ironic:4.11::el8 | pyparsing | — |
| pysnmp | affected | Red Hat:openshift_ironic:4.11::el8 | pysnmp | — |
| python2-pyparsing | affected | Red Hat:openshift_ironic:4.11::el8 | python2-pyparsing | — |
| python3-alembic | affected | Red Hat:openshift_ironic:4.11::el8 | python3-alembic | — |
| python3-amqp | affected | Red Hat:openshift_ironic:4.11::el8 | python3-amqp | — |
| python3-appdirs | affected | Red Hat:openshift_ironic:4.11::el8 | python3-appdirs | — |
| python3-automaton | affected | Red Hat:openshift_ironic:4.11::el8 | python3-automaton | — |
| python3-bcrypt | affected | Red Hat:openshift_ironic:4.11::el8 | python3-bcrypt | — |
| python3-bcrypt-debuginfo | affected | Red Hat:openshift_ironic:4.11::el8 | python3-bcrypt-debuginfo | — |
| python3-beautifulsoup4 | affected | Red Hat:openshift_ironic:4.11::el8 | python3-beautifulsoup4 | — |
| python3-cachetools | affected | Red Hat:openshift_ironic:4.11::el8 | python3-cachetools | — |
| python3-cinderclient | affected | Red Hat:openshift_ironic:4.11::el8 | python3-cinderclient | — |
| python3-cliff | affected | Red Hat:openshift_ironic:4.11::el8 | python3-cliff | — |
| python3-cliff-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-cliff-tests | — |
| python3-colorama | affected | Red Hat:openshift_ironic:4.11::el8 | python3-colorama | — |
| python3-construct | affected | Red Hat:openshift_ironic:4.11::el8 | python3-construct | — |
| python3-criu | affected | Red Hat:openshift:4.11::el8 | python3-criu | — |
| python3-dataclasses | affected | Red Hat:openshift_ironic:4.11::el8 | python3-dataclasses | — |
| python3-debtcollector | affected | Red Hat:openshift_ironic:4.11::el8 | python3-debtcollector | — |
| python3-decorator | affected | Red Hat:openshift_ironic:4.11::el8 | python3-decorator | — |
| python3-dogpile-cache | affected | Red Hat:openshift_ironic:4.11::el8 | python3-dogpile-cache | — |
| python3-dracclient | affected | Red Hat:openshift_ironic:4.11::el8 | python3-dracclient | — |
| python3-editor | affected | Red Hat:openshift_ironic:4.11::el8 | python3-editor | — |
| python3-fasteners | affected | Red Hat:openshift_ironic:4.11::el8 | python3-fasteners | — |
| python3-flask | affected | Red Hat:openshift_ironic:4.11::el8 | python3-flask | — |
| python3-funcsigs | affected | Red Hat:openshift_ironic:4.11::el8 | python3-funcsigs | — |
| python3-futurist | affected | Red Hat:openshift_ironic:4.11::el8 | python3-futurist | — |
| python3-glanceclient | affected | Red Hat:openshift_ironic:4.11::el8 | python3-glanceclient | — |
| python3-greenlet | affected | Red Hat:openshift_ironic:4.11::el8 | python3-greenlet | — |
| python3-greenlet-debuginfo | affected | Red Hat:openshift_ironic:4.11::el8 | python3-greenlet-debuginfo | — |
| python3-greenlet-devel | affected | Red Hat:openshift_ironic:4.11::el8 | python3-greenlet-devel | — |
| python3-hardware | affected | Red Hat:openshift_ironic:4.11::el8 | python3-hardware | — |
| python3-hardware-detect | affected | Red Hat:openshift_ironic:4.11::el8 | python3-hardware-detect | — |
| python3-ifaddr | affected | Red Hat:openshift_ironic:4.11::el8 | python3-ifaddr | — |
| python3-importlib-metadata | affected | Red Hat:openshift_ironic:4.11::el8 | python3-importlib-metadata | — |
| python3-ironic-inspector-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-ironic-inspector-tests | — |
| python3-ironic-lib | affected | Red Hat:openshift_ironic:4.11::el8 | python3-ironic-lib | — |
| python3-ironic-prometheus-exporter | affected | Red Hat:openshift_ironic:4.11::el8 | python3-ironic-prometheus-exporter | — |
| python3-ironic-python-agent | affected | Red Hat:openshift_ironic:4.11::el8 | python3-ironic-python-agent | — |
| python3-ironic-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-ironic-tests | — |
| python3-iso8601 | affected | Red Hat:openshift_ironic:4.11::el8 | python3-iso8601 | — |
| python3-jsonpath-rw | affected | Red Hat:openshift_ironic:4.11::el8 | python3-jsonpath-rw | — |
| python3-jsonschema | affected | Red Hat:openshift_ironic:4.11::el8 | python3-jsonschema | — |
| python3-kazoo | affected | Red Hat:openshift_ironic:4.11::el8 | python3-kazoo | — |
| python3-keyring | affected | Red Hat:openshift_ironic:4.11::el8 | python3-keyring | — |
| python3-keystoneauth1 | affected | Red Hat:openshift_ironic:4.11::el8 | python3-keystoneauth1 | — |
| python3-keystoneclient | affected | Red Hat:openshift_ironic:4.11::el8 | python3-keystoneclient | — |
| python3-keystoneclient-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-keystoneclient-tests | — |
| python3-keystonemiddleware | affected | Red Hat:openshift_ironic:4.11::el8 | python3-keystonemiddleware | — |
| python3-kombu | affected | Red Hat:openshift_ironic:4.11::el8 | python3-kombu | — |
| python3-kuryr-kubernetes | affected | Red Hat:openshift:4.11::el8 | python3-kuryr-kubernetes | — |
| python3-logutils | affected | Red Hat:openshift_ironic:4.11::el8 | python3-logutils | — |
| python3-memcached | affected | Red Hat:openshift_ironic:4.11::el8 | python3-memcached | — |
| python3-migrate | affected | Red Hat:openshift_ironic:4.11::el8 | python3-migrate | — |
| python3-msgpack | affected | Red Hat:openshift_ironic:4.11::el8 | python3-msgpack | — |
| python3-msgpack-debuginfo | affected | Red Hat:openshift_ironic:4.11::el8 | python3-msgpack-debuginfo | — |
| python3-munch | affected | Red Hat:openshift_ironic:4.11::el8 | python3-munch | — |
| python3-openstacksdk | affected | Red Hat:openshift_ironic:4.11::el8 | python3-openstacksdk | — |
| python3-openstacksdk-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-openstacksdk-tests | — |
| python3-openvswitch2.17 | affected | Red Hat:openshift:4.11::el8 | python3-openvswitch2.17 | — |
| python3-openvswitch2.17-debuginfo | affected | Red Hat:openshift:4.11::el8 | python3-openvswitch2.17-debuginfo | — |
| python3-osc-lib | affected | Red Hat:openshift_ironic:4.11::el8 | python3-osc-lib | — |
| python3-osc-lib-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-osc-lib-tests | — |
| python3-oslo-cache | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-cache | — |
| python3-oslo-cache-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-cache-tests | — |
| python3-oslo-concurrency | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-concurrency | — |
| python3-oslo-concurrency-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-concurrency-tests | — |
| python3-oslo-config | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-config | — |
| python3-oslo-context | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-context | — |
| python3-oslo-context-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-context-tests | — |
| python3-oslo-db | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-db | — |
| python3-oslo-db-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-db-tests | — |
| python3-oslo-i18n | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-i18n | — |
| python3-oslo-log | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-log | — |
| python3-oslo-log-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-log-tests | — |
| python3-oslo-messaging | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-messaging | — |
| python3-oslo-messaging-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-messaging-tests | — |
| python3-oslo-metrics | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-metrics | — |
| python3-oslo-metrics-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-metrics-tests | — |
| python3-oslo-middleware | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-middleware | — |
| python3-oslo-middleware-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-middleware-tests | — |
| python3-oslo-policy | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-policy | — |
| python3-oslo-policy-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-policy-tests | — |
| python3-oslo-rootwrap | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-rootwrap | — |
| python3-oslo-rootwrap-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-rootwrap-tests | — |
| python3-oslo-serialization | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-serialization | — |
| python3-oslo-serialization-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-serialization-tests | — |
| python3-oslo-service | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-service | — |
| python3-oslo-service-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-service-tests | — |
| python3-oslo-upgradecheck | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-upgradecheck | — |
| python3-oslo-utils | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-utils | — |
| python3-oslo-utils-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-utils-tests | — |
| python3-oslo-versionedobjects | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-versionedobjects | — |
| python3-oslo-versionedobjects-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-oslo-versionedobjects-tests | — |
| python3-osprofiler | affected | Red Hat:openshift_ironic:4.11::el8 | python3-osprofiler | — |
| python3-os-service-types | affected | Red Hat:openshift_ironic:4.11::el8 | python3-os-service-types | — |
| python3-os-traits | affected | Red Hat:openshift_ironic:4.11::el8 | python3-os-traits | — |
| python3-os-traits-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-os-traits-tests | — |
| python3-packaging | affected | Red Hat:openshift_ironic:4.11::el8 | python3-packaging | — |
| python3-paste | affected | Red Hat:openshift_ironic:4.11::el8 | python3-paste | — |
| python3-paste-deploy | affected | Red Hat:openshift_ironic:4.11::el8 | python3-paste-deploy | — |
| python3-pbr | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pbr | — |
| python3-pecan | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pecan | — |
| python3-pexpect | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pexpect | — |
| python3-pint | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pint | — |
| python3-proliantutils | affected | Red Hat:openshift_ironic:4.11::el8 | python3-proliantutils | — |
| python3-prometheus_client | affected | Red Hat:openshift_ironic:4.11::el8 | python3-prometheus_client | — |
| python3-pycadf | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pycadf | — |
| python3-pycdlib | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pycdlib | — |
| python3-pynacl | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pynacl | — |
| python3-pynacl-debuginfo | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pynacl-debuginfo | — |
| python3-pyparsing | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pyparsing | — |
| python3-pyperclip | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pyperclip | — |
| python3-pyrsistent | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pyrsistent | — |
| python3-pyrsistent-debuginfo | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pyrsistent-debuginfo | — |
| python3-pysnmp | affected | Red Hat:openshift_ironic:4.11::el8 | python3-pysnmp | — |
| python3-redis | affected | Red Hat:openshift_ironic:4.11::el8 | python3-redis | — |
| python3-repoze-lru | affected | Red Hat:openshift_ironic:4.11::el8 | python3-repoze-lru | — |
| python3-requestsexceptions | affected | Red Hat:openshift_ironic:4.11::el8 | python3-requestsexceptions | — |
| python3-retrying | affected | Red Hat:openshift_ironic:4.11::el8 | python3-retrying | — |
| python3-rfc3986 | affected | Red Hat:openshift_ironic:4.11::el8 | python3-rfc3986 | — |
| python3-routes | affected | Red Hat:openshift_ironic:4.11::el8 | python3-routes | — |
| python3-scciclient | affected | Red Hat:openshift_ironic:4.11::el8 | python3-scciclient | — |
| python3-SecretStorage | affected | Red Hat:openshift_ironic:4.11::el8 | python3-SecretStorage | — |
| python3-simplegeneric | affected | Red Hat:openshift_ironic:4.11::el8 | python3-simplegeneric | — |
| python3-simplejson | affected | Red Hat:openshift_ironic:4.11::el8 | python3-simplejson | — |
| python3-simplejson-debuginfo | affected | Red Hat:openshift_ironic:4.11::el8 | python3-simplejson-debuginfo | — |
| python3-singledispatch | affected | Red Hat:openshift_ironic:4.11::el8 | python3-singledispatch | — |
| python3-six | affected | Red Hat:openshift_ironic:4.11::el8 | python3-six | — |
| python3-soupsieve | affected | Red Hat:openshift_ironic:4.11::el8 | python3-soupsieve | — |
| python3-sqlparse | affected | Red Hat:openshift_ironic:4.11::el8 | python3-sqlparse | — |
| python3-statsd | affected | Red Hat:openshift_ironic:4.11::el8 | python3-statsd | — |
| python3-stevedore | affected | Red Hat:openshift_ironic:4.11::el8 | python3-stevedore | — |
| python3-sushy | affected | Red Hat:openshift_ironic:4.11::el8 | python3-sushy | — |
| python3-sushy-oem-idrac | affected | Red Hat:openshift_ironic:4.11::el8 | python3-sushy-oem-idrac | — |
| python3-sushy-oem-idrac-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-sushy-oem-idrac-tests | — |
| python3-sushy-tests | affected | Red Hat:openshift_ironic:4.11::el8 | python3-sushy-tests | — |
| python3-swiftclient | affected | Red Hat:openshift_ironic:4.11::el8 | python3-swiftclient | — |
| python3-tempita | affected | Red Hat:openshift_ironic:4.11::el8 | python3-tempita | — |
| python3-tenacity | affected | Red Hat:openshift_ironic:4.11::el8 | python3-tenacity | — |
| python3-tooz | affected | Red Hat:openshift_ironic:4.11::el8 | python3-tooz | — |
| python3-vine | affected | Red Hat:openshift_ironic:4.11::el8 | python3-vine | — |
| python3-voluptuous | affected | Red Hat:openshift_ironic:4.11::el8 | python3-voluptuous | — |
| python3-waitress | affected | Red Hat:openshift_ironic:4.11::el8 | python3-waitress | — |
| python3-warlock | affected | Red Hat:openshift_ironic:4.11::el8 | python3-warlock | — |
| python3-wcwidth | affected | Red Hat:openshift_ironic:4.11::el8 | python3-wcwidth | — |
| python3-webob | affected | Red Hat:openshift_ironic:4.11::el8 | python3-webob | — |
| python3-webtest | affected | Red Hat:openshift_ironic:4.11::el8 | python3-webtest | — |
| python3-werkzeug | affected | Red Hat:openshift_ironic:4.11::el8 | python3-werkzeug | — |
| python3-wrapt | affected | Red Hat:openshift_ironic:4.11::el8 | python3-wrapt | — |
| python3-wrapt-debuginfo | affected | Red Hat:openshift_ironic:4.11::el8 | python3-wrapt-debuginfo | — |
| python3-wsme | affected | Red Hat:openshift_ironic:4.11::el8 | python3-wsme | — |
| python3-yappi | affected | Red Hat:openshift_ironic:4.11::el8 | python3-yappi | — |
| python3-yappi-debuginfo | affected | Red Hat:openshift_ironic:4.11::el8 | python3-yappi-debuginfo | — |
| python3-zake | affected | Red Hat:openshift_ironic:4.11::el8 | python3-zake | — |
| python3-zeroconf | affected | Red Hat:openshift_ironic:4.11::el8 | python3-zeroconf | — |
| python3-zipp | affected | Red Hat:openshift_ironic:4.11::el8 | python3-zipp | — |
| python-alembic | affected | Red Hat:openshift_ironic:4.11::el8 | python-alembic | — |
| python-amqp | affected | Red Hat:openshift_ironic:4.11::el8 | python-amqp | — |
| python-amqp-doc | affected | Red Hat:openshift_ironic:4.11::el8 | python-amqp-doc | — |
| python-appdirs | affected | Red Hat:openshift_ironic:4.11::el8 | python-appdirs | — |
| python-automaton | affected | Red Hat:openshift_ironic:4.11::el8 | python-automaton | — |
| python-bcrypt | affected | Red Hat:openshift_ironic:4.11::el8 | python-bcrypt | — |
| python-bcrypt-debugsource | affected | Red Hat:openshift_ironic:4.11::el8 | python-bcrypt-debugsource | — |
| python-beautifulsoup4 | affected | Red Hat:openshift_ironic:4.11::el8 | python-beautifulsoup4 | — |
| python-cachetools | affected | Red Hat:openshift_ironic:4.11::el8 | python-cachetools | — |
| python-cinderclient | affected | Red Hat:openshift_ironic:4.11::el8 | python-cinderclient | — |
| python-cliff | affected | Red Hat:openshift_ironic:4.11::el8 | python-cliff | — |
| python-colorama | affected | Red Hat:openshift_ironic:4.11::el8 | python-colorama | — |
| python-construct | affected | Red Hat:openshift_ironic:4.11::el8 | python-construct | — |
| python-dataclasses | affected | Red Hat:openshift_ironic:4.11::el8 | python-dataclasses | — |
| python-debtcollector | affected | Red Hat:openshift_ironic:4.11::el8 | python-debtcollector | — |
| python-decorator | affected | Red Hat:openshift_ironic:4.11::el8 | python-decorator | — |
| python-dogpile-cache | affected | Red Hat:openshift_ironic:4.11::el8 | python-dogpile-cache | — |
| python-dracclient | affected | Red Hat:openshift_ironic:4.11::el8 | python-dracclient | — |
| python-editor | affected | Red Hat:openshift_ironic:4.11::el8 | python-editor | — |
| python-fasteners | affected | Red Hat:openshift_ironic:4.11::el8 | python-fasteners | — |
| python-flask | affected | Red Hat:openshift_ironic:4.11::el8 | python-flask | — |
| python-flask-doc | affected | Red Hat:openshift_ironic:4.11::el8 | python-flask-doc | — |
| python-funcsigs | affected | Red Hat:openshift_ironic:4.11::el8 | python-funcsigs | — |
| python-futurist | affected | Red Hat:openshift_ironic:4.11::el8 | python-futurist | — |
| python-glanceclient | affected | Red Hat:openshift_ironic:4.11::el8 | python-glanceclient | — |
| python-greenlet | affected | Red Hat:openshift_ironic:4.11::el8 | python-greenlet | — |
| python-greenlet-debugsource | affected | Red Hat:openshift_ironic:4.11::el8 | python-greenlet-debugsource | — |
| python-hardware | affected | Red Hat:openshift_ironic:4.11::el8 | python-hardware | — |
| python-ifaddr | affected | Red Hat:openshift_ironic:4.11::el8 | python-ifaddr | — |
| python-importlib-metadata | affected | Red Hat:openshift_ironic:4.11::el8 | python-importlib-metadata | — |
| python-ironic-lib | affected | Red Hat:openshift_ironic:4.11::el8 | python-ironic-lib | — |
| python-ironic-prometheus-exporter | affected | Red Hat:openshift_ironic:4.11::el8 | python-ironic-prometheus-exporter | — |
| python-iso8601 | affected | Red Hat:openshift_ironic:4.11::el8 | python-iso8601 | — |
| python-jsonpath-rw | affected | Red Hat:openshift_ironic:4.11::el8 | python-jsonpath-rw | — |
| python-jsonschema | affected | Red Hat:openshift_ironic:4.11::el8 | python-jsonschema | — |
| python-kazoo | affected | Red Hat:openshift_ironic:4.11::el8 | python-kazoo | — |
| python-keyring | affected | Red Hat:openshift_ironic:4.11::el8 | python-keyring | — |
| python-keystoneauth1 | affected | Red Hat:openshift_ironic:4.11::el8 | python-keystoneauth1 | — |
| python-keystoneclient | affected | Red Hat:openshift_ironic:4.11::el8 | python-keystoneclient | — |
| python-keystonemiddleware | affected | Red Hat:openshift_ironic:4.11::el8 | python-keystonemiddleware | — |
| python-kombu | affected | Red Hat:openshift_ironic:4.11::el8 | python-kombu | — |
| python-logutils | affected | Red Hat:openshift_ironic:4.11::el8 | python-logutils | — |
| python-memcached | affected | Red Hat:openshift_ironic:4.11::el8 | python-memcached | — |
| python-migrate | affected | Red Hat:openshift_ironic:4.11::el8 | python-migrate | — |
| python-msgpack | affected | Red Hat:openshift_ironic:4.11::el8 | python-msgpack | — |
| python-msgpack-debugsource | affected | Red Hat:openshift_ironic:4.11::el8 | python-msgpack-debugsource | — |
| python-munch | affected | Red Hat:openshift_ironic:4.11::el8 | python-munch | — |
| python-openstacksdk | affected | Red Hat:openshift_ironic:4.11::el8 | python-openstacksdk | — |
| python-osc-lib | affected | Red Hat:openshift_ironic:4.11::el8 | python-osc-lib | — |
| python-oslo-cache | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-cache | — |
| python-oslo-cache-lang | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-cache-lang | — |
| python-oslo-concurrency | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-concurrency | — |
| python-oslo-concurrency-lang | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-concurrency-lang | — |
| python-oslo-config | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-config | — |
| python-oslo-context | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-context | — |
| python-oslo-db | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-db | — |
| python-oslo-db-lang | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-db-lang | — |
| python-oslo-i18n | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-i18n | — |
| python-oslo-i18n-lang | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-i18n-lang | — |
| python-oslo-log | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-log | — |
| python-oslo-log-lang | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-log-lang | — |
| python-oslo-messaging | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-messaging | — |
| python-oslo-metrics | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-metrics | — |
| python-oslo-middleware | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-middleware | — |
| python-oslo-middleware-lang | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-middleware-lang | — |
| python-oslo-policy | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-policy | — |
| python-oslo-policy-lang | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-policy-lang | — |
| python-oslo-rootwrap | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-rootwrap | — |
| python-oslo-serialization | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-serialization | — |
| python-oslo-service | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-service | — |
| python-oslo-upgradecheck | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-upgradecheck | — |
| python-oslo-utils | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-utils | — |
| python-oslo-utils-lang | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-utils-lang | — |
| python-oslo-versionedobjects | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-versionedobjects | — |
| python-oslo-versionedobjects-lang | affected | Red Hat:openshift_ironic:4.11::el8 | python-oslo-versionedobjects-lang | — |
| python-osprofiler | affected | Red Hat:openshift_ironic:4.11::el8 | python-osprofiler | — |
| python-os-service-types | affected | Red Hat:openshift_ironic:4.11::el8 | python-os-service-types | — |
| python-os-traits | affected | Red Hat:openshift_ironic:4.11::el8 | python-os-traits | — |
| python-packaging | affected | Red Hat:openshift_ironic:4.11::el8 | python-packaging | — |
| python-packaging-doc | affected | Red Hat:openshift_ironic:4.11::el8 | python-packaging-doc | — |
| python-paste | affected | Red Hat:openshift_ironic:4.11::el8 | python-paste | — |
| python-paste-deploy | affected | Red Hat:openshift_ironic:4.11::el8 | python-paste-deploy | — |
| python-pbr | affected | Red Hat:openshift_ironic:4.11::el8 | python-pbr | — |
| python-pecan | affected | Red Hat:openshift_ironic:4.11::el8 | python-pecan | — |
| python-pexpect | affected | Red Hat:openshift_ironic:4.11::el8 | python-pexpect | — |
| python-pint | affected | Red Hat:openshift_ironic:4.11::el8 | python-pint | — |
| python-proliantutils | affected | Red Hat:openshift_ironic:4.11::el8 | python-proliantutils | — |
| python-prometheus_client | affected | Red Hat:openshift_ironic:4.11::el8 | python-prometheus_client | — |
| python-pycadf | affected | Red Hat:openshift_ironic:4.11::el8 | python-pycadf | — |
| python-pycadf-common | affected | Red Hat:openshift_ironic:4.11::el8 | python-pycadf-common | — |
| python-pycdlib | affected | Red Hat:openshift_ironic:4.11::el8 | python-pycdlib | — |
| python-pynacl | affected | Red Hat:openshift_ironic:4.11::el8 | python-pynacl | — |
| python-pynacl-debugsource | affected | Red Hat:openshift_ironic:4.11::el8 | python-pynacl-debugsource | — |
| python-pyperclip | affected | Red Hat:openshift_ironic:4.11::el8 | python-pyperclip | — |
| python-pyperclip-doc | affected | Red Hat:openshift_ironic:4.11::el8 | python-pyperclip-doc | — |
| python-pyrsistent | affected | Red Hat:openshift_ironic:4.11::el8 | python-pyrsistent | — |
| python-pyrsistent-debugsource | affected | Red Hat:openshift_ironic:4.11::el8 | python-pyrsistent-debugsource | — |
| python-redis | affected | Red Hat:openshift_ironic:4.11::el8 | python-redis | — |
| python-repoze-lru | affected | Red Hat:openshift_ironic:4.11::el8 | python-repoze-lru | — |
| python-requestsexceptions | affected | Red Hat:openshift_ironic:4.11::el8 | python-requestsexceptions | — |
| python-retrying | affected | Red Hat:openshift_ironic:4.11::el8 | python-retrying | — |
| python-rfc3986 | affected | Red Hat:openshift_ironic:4.11::el8 | python-rfc3986 | — |
| python-routes | affected | Red Hat:openshift_ironic:4.11::el8 | python-routes | — |
| python-scciclient | affected | Red Hat:openshift_ironic:4.11::el8 | python-scciclient | — |
| python-SecretStorage | affected | Red Hat:openshift_ironic:4.11::el8 | python-SecretStorage | — |
| python-simplegeneric | affected | Red Hat:openshift_ironic:4.11::el8 | python-simplegeneric | — |
| python-simplejson | affected | Red Hat:openshift_ironic:4.11::el8 | python-simplejson | — |
| python-simplejson-debugsource | affected | Red Hat:openshift_ironic:4.11::el8 | python-simplejson-debugsource | — |
| python-singledispatch | affected | Red Hat:openshift_ironic:4.11::el8 | python-singledispatch | — |
| python-six | affected | Red Hat:openshift_ironic:4.11::el8 | python-six | — |
| python-soupsieve | affected | Red Hat:openshift_ironic:4.11::el8 | python-soupsieve | — |
| python-sqlparse | affected | Red Hat:openshift_ironic:4.11::el8 | python-sqlparse | — |
| python-statsd | affected | Red Hat:openshift_ironic:4.11::el8 | python-statsd | — |
| python-stevedore | affected | Red Hat:openshift_ironic:4.11::el8 | python-stevedore | — |
| python-sushy | affected | Red Hat:openshift_ironic:4.11::el8 | python-sushy | — |
| python-sushy-oem-idrac | affected | Red Hat:openshift_ironic:4.11::el8 | python-sushy-oem-idrac | — |
| python-swiftclient | affected | Red Hat:openshift_ironic:4.11::el8 | python-swiftclient | — |
| python-tempita | affected | Red Hat:openshift_ironic:4.11::el8 | python-tempita | — |
| python-tenacity | affected | Red Hat:openshift_ironic:4.11::el8 | python-tenacity | — |
| python-tooz | affected | Red Hat:openshift_ironic:4.11::el8 | python-tooz | — |
| python-vine | affected | Red Hat:openshift_ironic:4.11::el8 | python-vine | — |
| python-voluptuous | affected | Red Hat:openshift_ironic:4.11::el8 | python-voluptuous | — |
| python-waitress | affected | Red Hat:openshift_ironic:4.11::el8 | python-waitress | — |
| python-warlock | affected | Red Hat:openshift_ironic:4.11::el8 | python-warlock | — |
| python-wcwidth | affected | Red Hat:openshift_ironic:4.11::el8 | python-wcwidth | — |
| python-webob | affected | Red Hat:openshift_ironic:4.11::el8 | python-webob | — |
| python-webtest | affected | Red Hat:openshift_ironic:4.11::el8 | python-webtest | — |
| python-werkzeug | affected | Red Hat:openshift_ironic:4.11::el8 | python-werkzeug | — |
| python-wrapt | affected | Red Hat:openshift_ironic:4.11::el8 | python-wrapt | — |
| python-wrapt-debugsource | affected | Red Hat:openshift_ironic:4.11::el8 | python-wrapt-debugsource | — |
| python-wrapt-doc | affected | Red Hat:openshift_ironic:4.11::el8 | python-wrapt-doc | — |
| python-wsme | affected | Red Hat:openshift_ironic:4.11::el8 | python-wsme | — |
| python-yappi | affected | Red Hat:openshift_ironic:4.11::el8 | python-yappi | — |
| python-yappi-debugsource | affected | Red Hat:openshift_ironic:4.11::el8 | python-yappi-debugsource | — |
| python-zake | affected | Red Hat:openshift_ironic:4.11::el8 | python-zake | — |
| python-zeroconf | affected | Red Hat:openshift_ironic:4.11::el8 | python-zeroconf | — |
| python-zipp | affected | Red Hat:openshift_ironic:4.11::el8 | python-zipp | — |
| runc | affected | Red Hat:openshift:4.11::el8 | runc | — |
| runc-debuginfo | affected | Red Hat:openshift:4.11::el8 | runc-debuginfo | — |
| runc-debugsource | affected | Red Hat:openshift:4.11::el8 | runc-debugsource | — |
| rust-afterburn | affected | Red Hat:openshift:4.11::el8 | rust-afterburn | — |
| rust-afterburn-debugsource | affected | Red Hat:openshift:4.11::el8 | rust-afterburn-debugsource | — |
| rust-bootupd | affected | Red Hat:openshift:4.11::el8 | rust-bootupd | — |
| rust-bootupd-debugsource | affected | Red Hat:openshift:4.11::el8 | rust-bootupd-debugsource | — |
| skopeo | affected | Red Hat:openshift:4.11::el8 | skopeo | — |
| skopeo-debuginfo | affected | Red Hat:openshift:4.11::el8 | skopeo-debuginfo | — |
| skopeo-debugsource | affected | Red Hat:openshift:4.11::el8 | skopeo-debugsource | — |
| skopeo-tests | affected | Red Hat:openshift:4.11::el8 | skopeo-tests | — |
| slirp4netns | affected | Red Hat:openshift:4.11::el8 | slirp4netns | — |
| slirp4netns-debuginfo | affected | Red Hat:openshift:4.11::el8 | slirp4netns-debuginfo | — |
| slirp4netns-debugsource | affected | Red Hat:openshift:4.11::el8 | slirp4netns-debugsource | — |
| toolbox | affected | Red Hat:openshift:4.11::el8 | toolbox | — |
Red Hat Security Advisory: go-toolset and golang security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Red Hat:enterprise_linux:9::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:9::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:9::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:9::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:9::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:9::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:9::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:9::appstream | go-toolset | — |
Important: go-toolset and golang security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Rocky Linux:9 | golang | — |
| go-toolset | affected | Rocky Linux:9 | go-toolset | — |
PUB-A-227452856
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
| golang | affected | openEuler:22.03-LTS | golang | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:22.03-LTS | golang | — |
Updated golang packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:8 | golang | — |
CVE-2022-32189 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
DEBIAN-CVE-2022-32189
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
CVEs:CVE-2022-32189
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
CVEs:CVE-2022-32189
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
Panic when decoding Float and Rat types in math/big
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| stdlib | affected | Go | stdlib | — |
CVE-2022-28131 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-28131 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2022-28131
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
Red Hat Security Advisory: go-toolset-1.17 and go-toolset-1.17-golang security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go-toolset-1.17 | affected | Red Hat:devtools:2022 | go-toolset-1.17 | — |
| go-toolset-1.17-build | affected | Red Hat:devtools:2022 | go-toolset-1.17-build | — |
| go-toolset-1.17-golang | affected | Red Hat:devtools:2022 | go-toolset-1.17-golang | — |
| go-toolset-1.17-golang-bin | affected | Red Hat:devtools:2022 | go-toolset-1.17-golang-bin | — |
| go-toolset-1.17-golang-docs | affected | Red Hat:devtools:2022 | go-toolset-1.17-golang-docs | — |
| go-toolset-1.17-golang-misc | affected | Red Hat:devtools:2022 | go-toolset-1.17-golang-misc | — |
| go-toolset-1.17-golang-race | affected | Red Hat:devtools:2022 | go-toolset-1.17-golang-race | — |
| go-toolset-1.17-golang-src | affected | Red Hat:devtools:2022 | go-toolset-1.17-golang-src | — |
| go-toolset-1.17-golang-tests | affected | Red Hat:devtools:2022 | go-toolset-1.17-golang-tests | — |
| go-toolset-1.17-runtime | affected | Red Hat:devtools:2022 | go-toolset-1.17-runtime | — |
| go-toolset-1.17-scldevel | affected | Red Hat:devtools:2022 | go-toolset-1.17-scldevel | — |
Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:8::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Important: go-toolset:rhel8 security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
Important: go-toolset:rhel8 security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | AlmaLinux:8 | delve | — |
| golang | affected | AlmaLinux:8 | golang | — |
| golang-bin | affected | AlmaLinux:8 | golang-bin | — |
| golang-docs | affected | AlmaLinux:8 | golang-docs | — |
| golang-misc | affected | AlmaLinux:8 | golang-misc | — |
| golang-race | affected | AlmaLinux:8 | golang-race | — |
| golang-src | affected | AlmaLinux:8 | golang-src | — |
| golang-tests | affected | AlmaLinux:8 | golang-tests | — |
| go-toolset | affected | AlmaLinux:8 | go-toolset | — |
Important: go-toolset and golang security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | AlmaLinux:9 | golang | — |
| golang-bin | affected | AlmaLinux:9 | golang-bin | — |
| golang-docs | affected | AlmaLinux:9 | golang-docs | — |
| golang-misc | affected | AlmaLinux:9 | golang-misc | — |
| golang-race | affected | AlmaLinux:9 | golang-race | — |
| golang-src | affected | AlmaLinux:9 | golang-src | — |
| golang-tests | affected | AlmaLinux:9 | golang-tests | — |
CVE-2022-29804 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVE-2022-30633 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-30633 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2022-30633
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
CVE-2022-30632 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-30632 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2022-30632
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
CVE-2022-30630 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
DEBIAN-CVE-2022-30630
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:22.03-LTS | golang | — |
CVE-2022-30631 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-30631 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2022-30631
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
Excessive resource consumption in gopkg.in/yaml.v2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| yaml.v2 | affected | gopkg.in | gopkg.in/yaml.v2 | — |
CVE-2022-30635 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-30635 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2022-30635
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
PUB-A-226679409
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interacti...
CVEs:CVE-2022-20347
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20347
PUB-A-233075473
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVE-2022-30580 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-30580 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
PUB-A-223967238
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
ASB-A-232440670
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-232441339
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2021-39696
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-39696
CVEs:CVE-2022-20338
In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to a local escalation of privilege, preventing processes from validating URIs correctly, with no addition...
CVEs:CVE-2022-20338
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-20369
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| debian_linux | affected | debian | — | — |
CVEs:CVE-2022-20369
PUB-A-223375145
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-21789
In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478101; Issue ID: AL...
CVEs:CVE-2022-21789
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-224546354
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2022-20355
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20355
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
CVEs:CVE-2022-2852
Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2852
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVEs:CVE-2022-33649
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2022-33649
Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2853
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2853
CVE-2022-1705 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-1705 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2022-1705
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
CVE-2022-32148 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-32148 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2022-32148
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
CVEs:CVE-2022-35796
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-35796
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2022-33636
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2022-33636
CVE-2022-30629 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
DEBIAN-CVE-2022-30629
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
CVEs:CVE-2022-3045
Insufficient validation of untrusted input in V8 in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3045
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVEs:CVE-2022-3056
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3056
DEBIAN-CVE-2022-2613
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
CVEs:CVE-2022-2613
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2613
CVE-2022-1962 affecting package golang for versions less than 1.18.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-1962 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2022-1962
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
DEBIAN-CVE-2022-2624
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
Heap buffer overflow in PDF in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file.
CVEs:CVE-2022-2624
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2624
CVEs:CVE-2022-3044
Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
CVEs:CVE-2022-3044
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page.
CVEs:CVE-2022-2860
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2860
Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3040
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3040
CVEs:CVE-2022-3041
Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3041
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Mapbox is vulnerable to Integer Overflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.mapbox.mapboxsdk:mapbox-android-core | affected | Maven | com.mapbox.mapboxsdk:mapbox-android-core | — |
Mapbox is vulnerable to Integer Overflow
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.mapbox.mapboxsdk:mapbox-android-core | affected | Maven | com.mapbox.mapboxsdk:mapbox-android-core | — |
An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating ...
CVEs:CVE-2022-38216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| maps_software_development_kit | affected | mapbox | — | — |
Mapbox is vulnerable to Integer Overflow
CVEs:CVE-2022-38216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.mapbox.mapboxsdk:mapbox-android-core | affected | Maven | com.mapbox.mapboxsdk:mapbox-android-core | — |
Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction.
CVEs:CVE-2022-2858
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2858
Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2855
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2855
CVEs:CVE-2022-2859
Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions.
CVEs:CVE-2022-2859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3046
Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3046
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3039
Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3039
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3052
Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.
CVEs:CVE-2022-3052
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
| linux_and_chrome_os | affected | — | — |
DEBIAN-CVE-2022-2610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-2610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2610
DEBIAN-CVE-2022-2603
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-2603
Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2603
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Heap buffer overflow in WebUI in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.
CVEs:CVE-2022-3050
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3050
Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.
CVEs:CVE-2022-2587
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-2587
DEBIAN-CVE-2022-2614
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2614
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2614
DEBIAN-CVE-2022-2612
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2022-2612
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2612
DEBIAN-CVE-2022-2604
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-2606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2604
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2604
CVEs:CVE-2022-2606
Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enable a specific Enterprise policy to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2022-2615
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-2605
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
CVEs:CVE-2022-2605
Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2605
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2615
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-2615
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2022-2618
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-2618
Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a malicious file .
CVEs:CVE-2022-2618
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2022-2621
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Extensions in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.
CVEs:CVE-2022-2621
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2621
CVEs:CVE-2022-3043
Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3043
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3055
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3055
DEBIAN-CVE-2022-2620
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
CVEs:CVE-2022-2620
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2620
CVEs:CVE-2022-3051
Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.
CVEs:CVE-2022-3051
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
| linux_and_chrome_os | affected | — | — |
Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2854
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2854
DEBIAN-CVE-2022-2622
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-2622
Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file.
CVEs:CVE-2022-2622
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-2857
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2857
Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.
CVEs:CVE-2022-3058
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3058
CVEs:CVE-2022-3054
Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3054
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2022-2611
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-2611
Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2022-2611
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-20237
In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2022-20237
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-229621649
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.
CVEs:CVE-2022-2861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2861
The Google Maps Anywhere WordPress plugin through 1.2.6.3 does not sanitise and escape any of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disal...
CVEs:CVE-2022-2424
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_maps_anywhere | affected | google_maps_anywhere_project | — | — |
CVEs:CVE-2022-2424
CVEs:CVE-2022-20308
In hostapd, there is a possible insecure configuration due to an insecure default value. This could lead to remote denial of service of the wifi hotspot with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2022-20308
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20247
In Media, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2022-20247
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.
CVEs:CVE-2022-3053
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3053
Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3049
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3049
CVEs:CVE-2022-3057
Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2022-3057
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2022-3042
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3042
DEBIAN-CVE-2022-2608
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-2609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-2608
Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
CVEs:CVE-2022-2608
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2609
Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
CVEs:CVE-2022-2609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
PUB-A-228390920
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-20346
In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction...
CVEs:CVE-2022-20346
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
DEBIAN-CVE-2022-2607
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-2607
Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
CVEs:CVE-2022-2607
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3047
Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.
CVEs:CVE-2022-3047
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2022-2616
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to spoof the contents of the Omnibox (URL bar) via a crafted Chrome Extension.
CVEs:CVE-2022-2616
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-2616
Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.
CVEs:CVE-2022-3071
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3071
DEBIAN-CVE-2022-2619
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-2619
Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.
CVEs:CVE-2022-2619
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2022-2617
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-2617
Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.
CVEs:CVE-2022-2617
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A
CVEs:CVE-2022-20402
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20402
PUB-A-218701042
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20365
Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A
CVEs:CVE-2022-20365
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-229632566
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
CVEs:CVE-2022-3048
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-3048
CVEs:CVE-2022-33719
Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.
CVEs:CVE-2022-33719
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20384
Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A
CVEs:CVE-2022-20384
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20405
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A
CVEs:CVE-2022-20405
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-211727306
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-216363416
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Product: AndroidVersions: Android kernelAndroid ID: A-215730643References: N/A
CVEs:CVE-2022-20370
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20370
PUB-A-215730643
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-20239
remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedP...
CVEs:CVE-2022-20239
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-233972091
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2022-20362
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20362
In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2022-20283
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20283
In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2022-20273
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20273
CVEs:CVE-2022-20333
In Bluetooth, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android...
CVEs:CVE-2022-20333
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Bluetooth, there are possible process crashes due to dereferencing a null pointer. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...
CVEs:CVE-2022-20334
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20334
In Bluetooth, there is a possible cleanup failure due to an uncaught exception. This could lead to remote denial of service in Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...
CVEs:CVE-2022-20253
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20253
PUB-A-205573273
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2022-20358
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User in...
CVEs:CVE-2022-20358
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Wi-Fi, there is a permissions bypass. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID...
CVEs:CVE-2022-20254
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20254
CVEs:CVE-2022-20313
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...
CVEs:CVE-2022-20313
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Bluetooth, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...
CVEs:CVE-2022-20269
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20269
CVEs:CVE-2022-33730
Heap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical attackers.
CVEs:CVE-2022-33730
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20302
In Settings, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to local escalation of privilege if the attacker has physical access to the device, with no additional execution privileges needed. User i...
CVEs:CVE-2022-20302
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20244
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if more than 100 bluetooth devices have been connected with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20244
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20280
In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lead to local information disclosure of sms/mms data with User execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2022-20280
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33723
A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
CVEs:CVE-2022-33723
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33727
A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
CVEs:CVE-2022-33727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Settings, there is a possible way to bypass factory reset permissions due to a permissions bypass. This could lead to local escalation of privilege with physical access to the device with no additional execution privileges needed. User interaction i...
CVEs:CVE-2022-20265
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20265
Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.
CVEs:CVE-2022-33720
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33720
In WindowManager, there is a possible method to create a recording of the lock screen due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for explo...
CVEs:CVE-2022-20245
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20245
CVEs:CVE-2022-20330
In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not n...
CVEs:CVE-2022-20330
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In bdi_put and bdi_unregister of backing-dev.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2022-20158
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20158
PUB-A-182815710
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In SystemUI, there is a possible way to unexpectedly enable the external speaker due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitati...
CVEs:CVE-2022-20317
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20317
In PermissionController, there is a possible way to grant some permissions without user consent due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...
CVEs:CVE-2022-20271
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20271
In the Framework, there is a possible way to enable a work profile without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for ...
CVEs:CVE-2022-20331
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20331
A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to access content providers with system privilege.
CVEs:CVE-2022-33725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33725
In Settings, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-20292
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20292
CVEs:CVE-2022-20297
In Settings, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-20297
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20282
In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitati...
CVEs:CVE-2022-20282
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Connectivity, there is a possible bypass the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2022-20286
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20286
Google Play Services SDK leads to apps having incorrectly set mutability flag
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.android.gms:play-services-basement | affected | Maven | com.google.android.gms:play-services-basement | — |
Google Play Services SDK leads to apps having incorrectly set mutability flag
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.android.gms:play-services-basement | affected | Maven | com.google.android.gms:play-services-basement | — |
In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interac...
CVEs:CVE-2022-20321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20321
Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application a...
CVEs:CVE-2022-2390
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_play_services_software_development_kit | affected | — | — |
Google Play Services SDK leads to apps having incorrectly set mutability flag
CVEs:CVE-2022-2390
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.android.gms:play-services-basement | affected | Maven | com.google.android.gms:play-services-basement | — |
In Messaging, there is a possible way to attach files to a message without proper access checks due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is neede...
CVEs:CVE-2022-20250
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20250
In (TBD) of (TBD), there is a possible out of bounds write due to kernel stack overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...
CVEs:CVE-2022-20382
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20382
CVEs:CVE-2022-20354
In onDefaultNetworkChanged of Vpn.java, there is a possible way to disable VPN due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2022-20354
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-214245176
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In DreamServices, there is a possible way to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2022-20319
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20319
CVEs:CVE-2022-20325
In Media, there is a possible code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13A...
CVEs:CVE-2022-20325
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33721
A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege.
CVEs:CVE-2022-33721
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Bluetooth, there is a possible way to bypass compiler exploit mitigations due to a configuration error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-20258
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20258
CVEs:CVE-2022-20268
In RestrictionsManager, there is a possible way to send a broadcast that should be restricted to system apps due to a permissions bypass. This could lead to local escalation of privilege on an enterprise managed device with no additional execution priv...
CVEs:CVE-2022-20268
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20248
In Settings, there is a possible way to connect to an open network bypassing DISALLOW_CONFIG_WIFI restriction due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVEs:CVE-2022-20248
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In KeyChain, there is a possible spoof keychain chooser activity request due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2022-20314
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20314
CVEs:CVE-2022-20306
In Camera Provider HAL, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2022-20306
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20266
In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to improper input validation. This could lead to local escalation of privilege with no additional execution pri...
CVEs:CVE-2022-20266
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20367
In construct_transaction of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2022-20367
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20379
In lwis_buffer_alloc of lwis_buffer.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2022-20379
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20383
In AllocateInternalBuffers of g3aa_buffer_allocator.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2022-20383
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-209436980
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-222408847
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-225877459
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In the Phone app, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
CVEs:CVE-2022-20260
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20260
In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User ...
CVEs:CVE-2022-20324
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20324
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...
CVEs:CVE-2022-20285
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20285
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed...
CVEs:CVE-2022-20318
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20318
In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....
CVEs:CVE-2022-20320
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20320
In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitati...
CVEs:CVE-2022-20327
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20327
CVEs:CVE-2022-33715
Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of One UI.
CVEs:CVE-2022-33715
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085540; Iss...
CVEs:CVE-2022-26427
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26427
In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085410; Iss...
CVEs:CVE-2022-21792
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21792
In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085486; Iss...
CVEs:CVE-2022-26426
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26426
In Content, there is a possible way to learn gmail account name on the device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2022-20270
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20270
CVEs:CVE-2022-20290
In Midi, there is a possible way to learn about private midi devices due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2022-20290
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20339
In Android, there is a possible access of network neighbor table information due to an insecure SEpolicy configuration. This could lead to local information disclosure of network topography with no additional execution privileges needed. User interacti...
CVEs:CVE-2022-20339
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2022-20342
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20342
In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....
CVEs:CVE-2022-20316
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20316
CVEs:CVE-2022-20332
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...
CVEs:CVE-2022-20332
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In LauncherApps, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. Us...
CVEs:CVE-2022-20293
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20293
In Content, there is a possible way to determinate the user's account due to side channel information disclosure. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2022-20304
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20304
In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...
CVEs:CVE-2022-20307
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20307
CVEs:CVE-2022-20309
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed...
CVEs:CVE-2022-20309
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is needed for exploit...
CVEs:CVE-2022-20272
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20272
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...
CVEs:CVE-2022-20275
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20275
CVEs:CVE-2022-20276
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...
CVEs:CVE-2022-20276
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...
CVEs:CVE-2022-20277
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20277
CVEs:CVE-2022-20278
In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2022-20278
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...
CVEs:CVE-2022-20279
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20279
CVEs:CVE-2022-20287
In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges...
CVEs:CVE-2022-20287
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20288
In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges...
CVEs:CVE-2022-20288
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20289
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed...
CVEs:CVE-2022-20289
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20291
In AppOpsService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...
CVEs:CVE-2022-20291
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...
CVEs:CVE-2022-20252
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20252
CVEs:CVE-2022-20350
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution ...
CVEs:CVE-2022-20350
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20353
In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2022-20353
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032521; Issue ID: ALPS...
CVEs:CVE-2022-26430
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | yoctoproject | — | — |
CVEs:CVE-2022-26430
CVEs:CVE-2022-26431
In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032553; Issue ...
CVEs:CVE-2022-26431
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | yoctoproject | — | — |
CVEs:CVE-2022-26432
In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032542; Issue ...
CVEs:CVE-2022-26432
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | yoctoproject | — | — |
In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138400; Issue ID: ALPS...
CVEs:CVE-2022-26433
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | yoctoproject | — | — |
CVEs:CVE-2022-26433
In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138450; Issue ...
CVEs:CVE-2022-26434
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | yoctoproject | — | — |
CVEs:CVE-2022-26434
CVEs:CVE-2022-26435
In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138435; Issue ID: ALPS...
CVEs:CVE-2022-26435
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | yoctoproject | — | — |
In scp, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06988728; Issue ID:...
CVEs:CVE-2022-21788
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21788
In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479306; Issue...
CVEs:CVE-2022-21790
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21790
In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478059; Issue...
CVEs:CVE-2022-21791
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-21791
In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction i...
CVEs:CVE-2022-20340
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20340
CVEs:CVE-2022-20329
In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2022-20329
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2022-20281
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20281
CVEs:CVE-2022-20261
In LocationManager, there is a possible way to get location information due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:...
CVEs:CVE-2022-20261
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26436
In emi mpu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07023666; Issue ID...
CVEs:CVE-2022-26436
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2022-20322
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20322
In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2022-20323
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20323
In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...
CVEs:CVE-2022-20257
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20257
CVEs:CVE-2022-20349
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges need...
CVEs:CVE-2022-20349
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2022-20328
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20328
CVEs:CVE-2022-20274
In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...
CVEs:CVE-2022-20274
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0734
In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side channel information disclosure. This could lead to local information disclosure of an installed package, without proper query permissio...
CVEs:CVE-2021-0734
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0975
In USB Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure of installed packages with no additional execution ...
CVEs:CVE-2021-0975
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User ...
CVEs:CVE-2022-20242
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20242
CVEs:CVE-2022-20341
In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information disclosure of tethering interfaces with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2022-20341
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check. This could lead to local information disclosure without additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2022-20312
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20312
In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2022-20326
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20326
CVEs:CVE-2022-20294
In Content, there is a possible way to learn about an account present on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2022-20294
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2022-20295
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20295
CVEs:CVE-2022-20296
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2022-20296
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20298
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2022-20298
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20299
In ContentService, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2022-20299
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20300
In Content, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2022-20300
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2022-20301
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20301
In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User intera...
CVEs:CVE-2022-20303
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20303
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of phone accounts with User execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2022-20284
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20284
In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
CVEs:CVE-2022-20259
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20259
In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2022-20263
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20263
CVEs:CVE-2022-20249
In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...
CVEs:CVE-2022-20249
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...
CVEs:CVE-2022-20251
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20251
CVEs:CVE-2022-20241
In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2022-20241
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitialized memory.
CVEs:CVE-2022-33716
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33716
CVEs:CVE-2022-33717
A missing input validation before memory read in SEM TA prior to SMR Aug-2022 Release 1 allows local attackers to read out of bound memory.
CVEs:CVE-2022-33717
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a missing permission check. This could lead to local information disclosure with no additional execution p...
CVEs:CVE-2022-20352
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20352
In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2022-26429
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26429
CVEs:CVE-2022-20315
In ActivityManager, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-20315
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20336
In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to local information disclosure of applications allow-listed to use the network during VPN lockdown mode with no additional execution p...
CVEs:CVE-2022-20336
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20305
In ContentService, there is a possible disclosure of available account types due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2022-20305
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20310
In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2022-20310
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20311
In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2022-20311
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2022-20262
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20262
CVEs:CVE-2022-33729
Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.
CVEs:CVE-2022-33729
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20344
In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2022-20344
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20246
In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User...
CVEs:CVE-2022-20246
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2022-20255
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20255
Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via Settings.Gloabal.
CVEs:CVE-2022-33728
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33728
In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been disabled due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...
CVEs:CVE-2022-20335
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20335
In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...
CVEs:CVE-2022-20267
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20267
CVEs:CVE-2022-33714
Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.
CVEs:CVE-2022-33714
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33722
Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.
CVEs:CVE-2022-33722
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0735
In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced in Android 11 due to a missing permission check. This could lead to local information disclosure with no additional execution privile...
CVEs:CVE-2021-0735
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.
CVEs:CVE-2022-33731
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33731
CVEs:CVE-2022-33726
Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.
CVEs:CVE-2022-33726
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33718
An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.
CVEs:CVE-2022-33718
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33732
Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.
CVEs:CVE-2022-33732
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In trusty_log_seq_start of trusty-log.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVEs:CVE-2022-20376
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20376
ASB-A-231271467
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-216130110
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro...
CVEs:CVE-2022-20256
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20256
In video codec, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06521260; Issue ID: ...
CVEs:CVE-2022-26428
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-26428
In Core Utilities, there is a possible log information disclosure. This could lead to local information disclosure of sensitive browsing data with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...
CVEs:CVE-2022-20243
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20243
Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log.
CVEs:CVE-2022-33724
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-33724
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.