Google Security Advisories · August 2022 — Google Security Advisories
649 advisories 388 CVEs 16 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2022-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 16 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

GO-2022-0535

Open SourceExploitedCISA KEV listed2022-08-01

Certificate validation bypass on Windows in crypto/x509

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

DSA-5212-1

Open SourceExploitedCISA KEV listed2022-08-18

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-3038

GoogleExploitedCISA KEV listedCRITICAL2022-08-30

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3038

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-32893

GoogleExploitedCISA KEV listedCRITICAL2022-08-17

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple ...

CVEs:CVE-2022-32893

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
fedora affected fedoraproject
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
webkitgtk affected webkitgtk
wpe_webkit affected wpewebkit
Upstream advisory

CVE-2022-32893

Project ZeroExploitedCISA KEV listed2022-08-17

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2022-32893

Upstream advisory

PUB-A-227638011

GoogleExploitedCISA KEV listed2022-08-01

PUB-A-227638011

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

MGASA-2022-0307

Open SourceExploitedCISA KEV listedCRITICAL2022-08-25

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

openSUSE-SU-2022:10099-1

Open SourceExploitedCISA KEV listedCRITICAL2022-08-25

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.3 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

CVE-2022-2856

Project ZeroExploitedCISA KEV listed2022-08-17

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

CVEs:CVE-2022-2856

Upstream advisory

CVE-2022-2856

GoogleExploitedCISA KEV listedMEDIUM2022-08-17

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

CVEs:CVE-2022-2856

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-32894

Project ZeroExploitedCISA KEV listed2022-08-18

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2022-32894

Upstream advisory

CVE-2022-32894

GoogleExploitedCISA KEV listedCRITICAL2022-08-18

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a repor...

CVEs:CVE-2022-32894

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

GO-2022-0761

Open SourceWeaponized exploitHIGH2022-08-09

Improper input validation in net/http and net/http/cgi

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

openSUSE-SU-2022:10092-1

Open SourceWeaponized exploitCRITICAL2022-08-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

openSUSE-SU-2022:10086-1

Open SourceWeaponized exploitCRITICAL2022-08-12

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5201-1

Open SourceWeaponized exploit2022-08-07

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

MGASA-2022-0277

Open SourceWeaponized exploitCRITICAL2022-08-05

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

DEBIAN-CVE-2022-2623

Open SourceWeaponized exploitHIGH2022-08-12

DEBIAN-CVE-2022-2623

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2623

GoogleWeaponized exploitHIGH2022-08-03

Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

CVEs:CVE-2022-2623

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-20361

Open SourceActive exploitation (sightings)CRITICAL2022-08-02

In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User in...

CVEs:CVE-2022-20361

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-233078742

GoogleActive exploitation (sightings)HIGH2022-08-01

ASB-A-233078742

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20400

Open SourceActive exploitation (sightings)CRITICAL2022-08-02

In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2022-20400

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-225178325

GoogleActive exploitation (sightings)HIGH2022-08-01

PUB-A-225178325

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20375

Open SourceActive exploitation (sightings)HIGH2022-08-02

In LteRrcNrProAsnDecode of LteRrcNr_Codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2022-20375

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-180956894

GoogleActive exploitation (sightings)MEDIUM2022-08-01

PUB-A-180956894

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20401

Open SourceActive exploitation (sightings)HIGH2022-08-02

In SAEMM_RetrievEPLMNList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post-authentication with no additional execution privileges needed. User inte...

CVEs:CVE-2022-20401

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-226446030

GoogleActive exploitation (sightings)MEDIUM2022-08-01

PUB-A-226446030

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20345

Open SourceActive exploitation (sightings)HIGH2022-08-02

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2022-20345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20403

Open SourceActive exploitation (sightings)CRITICAL2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A

CVEs:CVE-2022-20403

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-207975764

GoogleActive exploitation (sightings)2022-08-01

PUB-A-207975764

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20378

Open SourceActive exploitation (sightings)CRITICAL2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A

CVEs:CVE-2022-20378

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-234657153

GoogleActive exploitation (sightings)2022-08-01

PUB-A-234657153

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20381

Open SourceActive exploitation (sightings)CRITICAL2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A

CVEs:CVE-2022-20381

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-188935887

GoogleActive exploitation (sightings)2022-08-01

PUB-A-188935887

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20407

Open SourceActive exploitation (sightings)HIGH2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-210916981References: N/A

CVEs:CVE-2022-20407

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-210916981

GoogleActive exploitation (sightings)2022-08-01

PUB-A-210916981

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20380

Open SourceActive exploitation (sightings)HIGH2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-212625740References: N/A

CVEs:CVE-2022-20380

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20404

Open SourceActive exploitation (sightings)HIGH2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-205714161References: N/A

CVEs:CVE-2022-20404

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20406

Open SourceActive exploitation (sightings)HIGH2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-184676385References: N/A

CVEs:CVE-2022-20406

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20408

Open SourceActive exploitation (sightings)HIGH2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-204782372References: N/A

CVEs:CVE-2022-20408

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0946

Open SourceActive exploitation (sightings)HIGH2022-08-02

The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicAddr, and then copies the buffer to userspace. The method PMR_PDumpSymbolicAddr may fail, and if it does the buf...

CVEs:CVE-2021-0946

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0947

Open SourceActive exploitation (sightings)HIGH2022-08-02

The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspace. The method TLServerDiscoverStreamsKM may fail for several reasons inc...

CVEs:CVE-2021-0947

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-236838960

GoogleActive exploitation (sightings)2022-08-01

ASB-A-236838960

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-236846966

GoogleActive exploitation (sightings)2022-08-01

ASB-A-236846966

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-184676385

GoogleActive exploitation (sightings)2022-08-01

PUB-A-184676385

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-204782372

GoogleActive exploitation (sightings)2022-08-01

PUB-A-204782372

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-205714161

GoogleActive exploitation (sightings)2022-08-01

PUB-A-205714161

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-212625740

GoogleActive exploitation (sightings)2022-08-01

PUB-A-212625740

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0891

Open SourceActive exploitation (sightings)HIGH2022-08-02

An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Product: AndroidVersions: Android SoCAndroid ID: A-236849490

CVEs:CVE-2021-0891

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-236849490

GoogleActive exploitation (sightings)MEDIUM2022-08-01

ASB-A-236849490

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20360

Open SourceActive exploitation (sightings)HIGH2022-08-02

In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2022-20360

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-231156274

GoogleActive exploitation (sightings)2022-08-01

ASB-A-231156274

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-20348

Open SourceActive exploitation (sightings)HIGH2022-08-02

In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. Us...

CVEs:CVE-2022-20348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20356

Open SourceActive exploitation (sightings)HIGH2022-08-02

In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improper input validation. This could lead to local escalation of privilege with no additional execution priv...

CVEs:CVE-2022-20356

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20366

Open SourceActive exploitation (sightings)HIGH2022-08-02

In ioctl_dpm_clk_update of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2022-20366

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-225877745

GoogleActive exploitation (sightings)HIGH2022-08-01

PUB-A-225877745

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20372

Open SourceActive exploitation (sightings)HIGH2022-08-02

In exynos5_i2c_irq of (TBD), there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...

CVEs:CVE-2022-20372

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-195480799

GoogleActive exploitation (sightings)HIGH2022-08-01

PUB-A-195480799

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20377

Open SourceActive exploitation (sightings)HIGH2022-08-02

In TBD of keymaster_ipc.cpp, there is a possible to force gatekeeper, fingerprint, and faceauth to use a known HMAC key. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-20377

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-222339795

GoogleActive exploitation (sightings)HIGH2022-08-01

PUB-A-222339795

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20180

Open SourceActive exploitation (sightings)HIGH2022-08-02

In several functions of mali_gralloc_reference.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2022-20180

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20357

Open SourceActive exploitation (sightings)HIGH2022-08-02

In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2022-20357

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-212804042

GoogleActive exploitation (sightings)HIGH2022-08-01

PUB-A-212804042

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0698

Open SourceActive exploitation (sightings)MEDIUM2022-08-02

In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2021-0698

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0887

Open SourceActive exploitation (sightings)MEDIUM2022-08-02

In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2021-0887

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-236848165

GoogleActive exploitation (sightings)MEDIUM2022-08-01

ASB-A-236848165

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-236848817

GoogleActive exploitation (sightings)MEDIUM2022-08-01

ASB-A-236848817

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20371

Open SourceActive exploitation (sightings)HIGH2022-08-02

In dm_bow_dtr and related functions of dm-bow.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2022-20371

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20373

Open SourceActive exploitation (sightings)HIGH2022-08-02

In st21nfc_loc_set_polaritymode of fc/st21nfc.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2022-20373

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-195565510

GoogleActive exploitation (sightings)HIGH2022-08-01

PUB-A-195565510

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-208269510

GoogleActive exploitation (sightings)HIGH2022-08-01

PUB-A-208269510

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GO-2022-0536

Open SourcePoC exploitHIGH2022-08-01

Reset flood in net/http and golang.org/x/net/http

Affected products

ProductStatusVendorPackageEcosystem
hey affected chainguard hey
hey affected wolfi hey
k3d affected wolfi k3d
k3d affected chainguard k3d
stdlib affected Go stdlib
x/net affected golang.org golang.org/x/net
Upstream advisory

PUB-A-228560328

GooglePoC exploit2022-08-01

PUB-A-228560328

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

RHSA-2022:5068

Open SourcePoC exploitHIGH2022-08-10

Red Hat Security Advisory: OpenShift Container Platform 4.11.0 packages and security update

Affected products

ProductStatusVendorPackageEcosystem
afterburn affected Red Hat:openshift:4.11::el8 afterburn
afterburn-debuginfo affected Red Hat:openshift:4.11::el8 afterburn-debuginfo
atomic-openshift-service-idler affected Red Hat:openshift:4.11::el8 atomic-openshift-service-idler
bootupd affected Red Hat:openshift:4.11::el8 bootupd
bootupd-debuginfo affected Red Hat:openshift:4.11::el8 bootupd-debuginfo
buildah affected Red Hat:openshift:4.11::el8 buildah
buildah-debuginfo affected Red Hat:openshift:4.11::el8 buildah-debuginfo
buildah-debugsource affected Red Hat:openshift:4.11::el8 buildah-debugsource
buildah-tests affected Red Hat:openshift:4.11::el8 buildah-tests
buildah-tests-debuginfo affected Red Hat:openshift:4.11::el8 buildah-tests-debuginfo
butane affected Red Hat:openshift:4.11::el8 butane
butane-debuginfo affected Red Hat:openshift:4.11::el8 butane-debuginfo
butane-debugsource affected Red Hat:openshift:4.11::el8 butane-debugsource
butane-redistributable affected Red Hat:openshift:4.11::el8 butane-redistributable
conmon affected Red Hat:openshift:4.11::el8 conmon
conmon-debuginfo affected Red Hat:openshift:4.11::el8 conmon-debuginfo
conmon-debugsource affected Red Hat:openshift:4.11::el8 conmon-debugsource
console-login-helper-messages affected Red Hat:openshift:4.11::el8 console-login-helper-messages
console-login-helper-messages-issuegen affected Red Hat:openshift:4.11::el8 console-login-helper-messages-issuegen
console-login-helper-messages-profile affected Red Hat:openshift:4.11::el8 console-login-helper-messages-profile
containernetworking-plugins affected Red Hat:openshift:4.11::el8 containernetworking-plugins
containernetworking-plugins-debuginfo affected Red Hat:openshift:4.11::el8 containernetworking-plugins-debuginfo
containernetworking-plugins-debugsource affected Red Hat:openshift:4.11::el8 containernetworking-plugins-debugsource
containers-common affected Red Hat:openshift:4.11::el8 containers-common
container-selinux affected Red Hat:openshift:4.11::el8 container-selinux
coreos-installer affected Red Hat:openshift:4.11::el8 coreos-installer
coreos-installer-bootinfra affected Red Hat:openshift:4.11::el8 coreos-installer-bootinfra
coreos-installer-bootinfra-debuginfo affected Red Hat:openshift:4.11::el8 coreos-installer-bootinfra-debuginfo
coreos-installer-debuginfo affected Red Hat:openshift:4.11::el8 coreos-installer-debuginfo
coreos-installer-debugsource affected Red Hat:openshift:4.11::el8 coreos-installer-debugsource
cri-o affected Red Hat:openshift:4.11::el8 cri-o
cri-o-debuginfo affected Red Hat:openshift:4.11::el8 cri-o-debuginfo
cri-o-debugsource affected Red Hat:openshift:4.11::el8 cri-o-debugsource
crit affected Red Hat:openshift:4.11::el8 crit
cri-tools affected Red Hat:openshift:4.11::el8 cri-tools
cri-tools-debuginfo affected Red Hat:openshift:4.11::el8 cri-tools-debuginfo
cri-tools-debugsource affected Red Hat:openshift:4.11::el8 cri-tools-debugsource
criu affected Red Hat:openshift:4.11::el8 criu
criu-debuginfo affected Red Hat:openshift:4.11::el8 criu-debuginfo
criu-debugsource affected Red Hat:openshift:4.11::el8 criu-debugsource
criu-devel affected Red Hat:openshift:4.11::el8 criu-devel
criu-libs affected Red Hat:openshift:4.11::el8 criu-libs
criu-libs-debuginfo affected Red Hat:openshift:4.11::el8 criu-libs-debuginfo
crun affected Red Hat:openshift:4.11::el8 crun
crun-debuginfo affected Red Hat:openshift:4.11::el8 crun-debuginfo
crun-debugsource affected Red Hat:openshift:4.11::el8 crun-debugsource
fuse-overlayfs affected Red Hat:openshift:4.11::el8 fuse-overlayfs
fuse-overlayfs-debuginfo affected Red Hat:openshift:4.11::el8 fuse-overlayfs-debuginfo
fuse-overlayfs-debugsource affected Red Hat:openshift:4.11::el8 fuse-overlayfs-debugsource
haproxy affected Red Hat:openshift:4.11::el8 haproxy
haproxy22 affected Red Hat:openshift:4.11::el8 haproxy22
haproxy22-debuginfo affected Red Hat:openshift:4.11::el8 haproxy22-debuginfo
haproxy-debugsource affected Red Hat:openshift:4.11::el8 haproxy-debugsource
ignition affected Red Hat:openshift:4.11::el8 ignition
ignition-debuginfo affected Red Hat:openshift:4.11::el8 ignition-debuginfo
ignition-debugsource affected Red Hat:openshift:4.11::el8 ignition-debugsource
ignition-validate affected Red Hat:openshift:4.11::el8 ignition-validate
ignition-validate-debuginfo affected Red Hat:openshift:4.11::el8 ignition-validate-debuginfo
kata-containers affected Red Hat:openshift:4.11::el8 kata-containers
libslirp affected Red Hat:openshift:4.11::el8 libslirp
libslirp-debuginfo affected Red Hat:openshift:4.11::el8 libslirp-debuginfo
libslirp-debugsource affected Red Hat:openshift:4.11::el8 libslirp-debugsource
libslirp-devel affected Red Hat:openshift:4.11::el8 libslirp-devel
libsodium affected Red Hat:openshift_ironic:4.11::el8 libsodium
libsodium-debuginfo affected Red Hat:openshift_ironic:4.11::el8 libsodium-debuginfo
libsodium-debugsource affected Red Hat:openshift_ironic:4.11::el8 libsodium-debugsource
libsodium-devel affected Red Hat:openshift_ironic:4.11::el8 libsodium-devel
libsodium-static affected Red Hat:openshift_ironic:4.11::el8 libsodium-static
network-scripts-openvswitch2.17 affected Red Hat:openshift:4.11::el8 network-scripts-openvswitch2.17
openshift affected Red Hat:openshift:4.11::el8 openshift
openshift-ansible affected Red Hat:openshift:4.11::el8 openshift-ansible
openshift-ansible-test affected Red Hat:openshift:4.11::el8 openshift-ansible-test
openshift-clients affected Red Hat:openshift:4.11::el8 openshift-clients
openshift-clients-redistributable affected Red Hat:openshift:4.11::el8 openshift-clients-redistributable
openshift-hyperkube affected Red Hat:openshift:4.11::el8 openshift-hyperkube
openshift-kuryr affected Red Hat:openshift:4.11::el8 openshift-kuryr
openshift-kuryr-cni affected Red Hat:openshift:4.11::el8 openshift-kuryr-cni
openshift-kuryr-common affected Red Hat:openshift:4.11::el8 openshift-kuryr-common
openshift-kuryr-controller affected Red Hat:openshift:4.11::el8 openshift-kuryr-controller
openstack-ironic affected Red Hat:openshift_ironic:4.11::el8 openstack-ironic
openstack-ironic-api affected Red Hat:openshift_ironic:4.11::el8 openstack-ironic-api
openstack-ironic-common affected Red Hat:openshift_ironic:4.11::el8 openstack-ironic-common
openstack-ironic-conductor affected Red Hat:openshift_ironic:4.11::el8 openstack-ironic-conductor
openstack-ironic-inspector affected Red Hat:openshift_ironic:4.11::el8 openstack-ironic-inspector
openstack-ironic-inspector-api affected Red Hat:openshift_ironic:4.11::el8 openstack-ironic-inspector-api
openstack-ironic-inspector-conductor affected Red Hat:openshift_ironic:4.11::el8 openstack-ironic-inspector-conductor
openstack-ironic-inspector-dnsmasq affected Red Hat:openshift_ironic:4.11::el8 openstack-ironic-inspector-dnsmasq
openstack-ironic-python-agent affected Red Hat:openshift_ironic:4.11::el8 openstack-ironic-python-agent
openvswitch2.17 affected Red Hat:openshift:4.11::el8 openvswitch2.17
openvswitch2.17-debuginfo affected Red Hat:openshift:4.11::el8 openvswitch2.17-debuginfo
openvswitch2.17-debugsource affected Red Hat:openshift:4.11::el8 openvswitch2.17-debugsource
openvswitch2.17-devel affected Red Hat:openshift:4.11::el8 openvswitch2.17-devel
openvswitch2.17-ipsec affected Red Hat:openshift:4.11::el8 openvswitch2.17-ipsec
openvswitch2.17-test affected Red Hat:openshift:4.11::el8 openvswitch2.17-test
ovn22.03 affected Red Hat:openshift:4.11::el8 ovn22.03
ovn22.03-central affected Red Hat:openshift:4.11::el8 ovn22.03-central
ovn22.03-central-debuginfo affected Red Hat:openshift:4.11::el8 ovn22.03-central-debuginfo
ovn22.03-debuginfo affected Red Hat:openshift:4.11::el8 ovn22.03-debuginfo
ovn22.03-debugsource affected Red Hat:openshift:4.11::el8 ovn22.03-debugsource
ovn22.03-host affected Red Hat:openshift:4.11::el8 ovn22.03-host
ovn22.03-host-debuginfo affected Red Hat:openshift:4.11::el8 ovn22.03-host-debuginfo
ovn22.03-vtep affected Red Hat:openshift:4.11::el8 ovn22.03-vtep
ovn22.03-vtep-debuginfo affected Red Hat:openshift:4.11::el8 ovn22.03-vtep-debuginfo
ovn22.06 affected Red Hat:openshift:4.11::el8 ovn22.06
ovn22.06-central affected Red Hat:openshift:4.11::el8 ovn22.06-central
ovn22.06-central-debuginfo affected Red Hat:openshift:4.11::el8 ovn22.06-central-debuginfo
ovn22.06-debuginfo affected Red Hat:openshift:4.11::el8 ovn22.06-debuginfo
ovn22.06-debugsource affected Red Hat:openshift:4.11::el8 ovn22.06-debugsource
ovn22.06-host affected Red Hat:openshift:4.11::el8 ovn22.06-host
ovn22.06-host-debuginfo affected Red Hat:openshift:4.11::el8 ovn22.06-host-debuginfo
ovn22.06-vtep affected Red Hat:openshift:4.11::el8 ovn22.06-vtep
ovn22.06-vtep-debuginfo affected Red Hat:openshift:4.11::el8 ovn22.06-vtep-debuginfo
podman affected Red Hat:openshift:4.11::el8 podman
podman-catatonit affected Red Hat:openshift:4.11::el8 podman-catatonit
podman-catatonit-debuginfo affected Red Hat:openshift:4.11::el8 podman-catatonit-debuginfo
podman-debuginfo affected Red Hat:openshift:4.11::el8 podman-debuginfo
podman-debugsource affected Red Hat:openshift:4.11::el8 podman-debugsource
podman-docker affected Red Hat:openshift:4.11::el8 podman-docker
podman-gvproxy-debuginfo affected Red Hat:openshift:4.11::el8 podman-gvproxy-debuginfo
podman-plugins affected Red Hat:openshift:4.11::el8 podman-plugins
podman-plugins-debuginfo affected Red Hat:openshift:4.11::el8 podman-plugins-debuginfo
podman-remote affected Red Hat:openshift:4.11::el8 podman-remote
podman-remote-debuginfo affected Red Hat:openshift:4.11::el8 podman-remote-debuginfo
podman-tests affected Red Hat:openshift:4.11::el8 podman-tests
pycdlib-tools affected Red Hat:openshift_ironic:4.11::el8 pycdlib-tools
pyparsing affected Red Hat:openshift_ironic:4.11::el8 pyparsing
pysnmp affected Red Hat:openshift_ironic:4.11::el8 pysnmp
python2-pyparsing affected Red Hat:openshift_ironic:4.11::el8 python2-pyparsing
python3-alembic affected Red Hat:openshift_ironic:4.11::el8 python3-alembic
python3-amqp affected Red Hat:openshift_ironic:4.11::el8 python3-amqp
python3-appdirs affected Red Hat:openshift_ironic:4.11::el8 python3-appdirs
python3-automaton affected Red Hat:openshift_ironic:4.11::el8 python3-automaton
python3-bcrypt affected Red Hat:openshift_ironic:4.11::el8 python3-bcrypt
python3-bcrypt-debuginfo affected Red Hat:openshift_ironic:4.11::el8 python3-bcrypt-debuginfo
python3-beautifulsoup4 affected Red Hat:openshift_ironic:4.11::el8 python3-beautifulsoup4
python3-cachetools affected Red Hat:openshift_ironic:4.11::el8 python3-cachetools
python3-cinderclient affected Red Hat:openshift_ironic:4.11::el8 python3-cinderclient
python3-cliff affected Red Hat:openshift_ironic:4.11::el8 python3-cliff
python3-cliff-tests affected Red Hat:openshift_ironic:4.11::el8 python3-cliff-tests
python3-colorama affected Red Hat:openshift_ironic:4.11::el8 python3-colorama
python3-construct affected Red Hat:openshift_ironic:4.11::el8 python3-construct
python3-criu affected Red Hat:openshift:4.11::el8 python3-criu
python3-dataclasses affected Red Hat:openshift_ironic:4.11::el8 python3-dataclasses
python3-debtcollector affected Red Hat:openshift_ironic:4.11::el8 python3-debtcollector
python3-decorator affected Red Hat:openshift_ironic:4.11::el8 python3-decorator
python3-dogpile-cache affected Red Hat:openshift_ironic:4.11::el8 python3-dogpile-cache
python3-dracclient affected Red Hat:openshift_ironic:4.11::el8 python3-dracclient
python3-editor affected Red Hat:openshift_ironic:4.11::el8 python3-editor
python3-fasteners affected Red Hat:openshift_ironic:4.11::el8 python3-fasteners
python3-flask affected Red Hat:openshift_ironic:4.11::el8 python3-flask
python3-funcsigs affected Red Hat:openshift_ironic:4.11::el8 python3-funcsigs
python3-futurist affected Red Hat:openshift_ironic:4.11::el8 python3-futurist
python3-glanceclient affected Red Hat:openshift_ironic:4.11::el8 python3-glanceclient
python3-greenlet affected Red Hat:openshift_ironic:4.11::el8 python3-greenlet
python3-greenlet-debuginfo affected Red Hat:openshift_ironic:4.11::el8 python3-greenlet-debuginfo
python3-greenlet-devel affected Red Hat:openshift_ironic:4.11::el8 python3-greenlet-devel
python3-hardware affected Red Hat:openshift_ironic:4.11::el8 python3-hardware
python3-hardware-detect affected Red Hat:openshift_ironic:4.11::el8 python3-hardware-detect
python3-ifaddr affected Red Hat:openshift_ironic:4.11::el8 python3-ifaddr
python3-importlib-metadata affected Red Hat:openshift_ironic:4.11::el8 python3-importlib-metadata
python3-ironic-inspector-tests affected Red Hat:openshift_ironic:4.11::el8 python3-ironic-inspector-tests
python3-ironic-lib affected Red Hat:openshift_ironic:4.11::el8 python3-ironic-lib
python3-ironic-prometheus-exporter affected Red Hat:openshift_ironic:4.11::el8 python3-ironic-prometheus-exporter
python3-ironic-python-agent affected Red Hat:openshift_ironic:4.11::el8 python3-ironic-python-agent
python3-ironic-tests affected Red Hat:openshift_ironic:4.11::el8 python3-ironic-tests
python3-iso8601 affected Red Hat:openshift_ironic:4.11::el8 python3-iso8601
python3-jsonpath-rw affected Red Hat:openshift_ironic:4.11::el8 python3-jsonpath-rw
python3-jsonschema affected Red Hat:openshift_ironic:4.11::el8 python3-jsonschema
python3-kazoo affected Red Hat:openshift_ironic:4.11::el8 python3-kazoo
python3-keyring affected Red Hat:openshift_ironic:4.11::el8 python3-keyring
python3-keystoneauth1 affected Red Hat:openshift_ironic:4.11::el8 python3-keystoneauth1
python3-keystoneclient affected Red Hat:openshift_ironic:4.11::el8 python3-keystoneclient
python3-keystoneclient-tests affected Red Hat:openshift_ironic:4.11::el8 python3-keystoneclient-tests
python3-keystonemiddleware affected Red Hat:openshift_ironic:4.11::el8 python3-keystonemiddleware
python3-kombu affected Red Hat:openshift_ironic:4.11::el8 python3-kombu
python3-kuryr-kubernetes affected Red Hat:openshift:4.11::el8 python3-kuryr-kubernetes
python3-logutils affected Red Hat:openshift_ironic:4.11::el8 python3-logutils
python3-memcached affected Red Hat:openshift_ironic:4.11::el8 python3-memcached
python3-migrate affected Red Hat:openshift_ironic:4.11::el8 python3-migrate
python3-msgpack affected Red Hat:openshift_ironic:4.11::el8 python3-msgpack
python3-msgpack-debuginfo affected Red Hat:openshift_ironic:4.11::el8 python3-msgpack-debuginfo
python3-munch affected Red Hat:openshift_ironic:4.11::el8 python3-munch
python3-openstacksdk affected Red Hat:openshift_ironic:4.11::el8 python3-openstacksdk
python3-openstacksdk-tests affected Red Hat:openshift_ironic:4.11::el8 python3-openstacksdk-tests
python3-openvswitch2.17 affected Red Hat:openshift:4.11::el8 python3-openvswitch2.17
python3-openvswitch2.17-debuginfo affected Red Hat:openshift:4.11::el8 python3-openvswitch2.17-debuginfo
python3-osc-lib affected Red Hat:openshift_ironic:4.11::el8 python3-osc-lib
python3-osc-lib-tests affected Red Hat:openshift_ironic:4.11::el8 python3-osc-lib-tests
python3-oslo-cache affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-cache
python3-oslo-cache-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-cache-tests
python3-oslo-concurrency affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-concurrency
python3-oslo-concurrency-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-concurrency-tests
python3-oslo-config affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-config
python3-oslo-context affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-context
python3-oslo-context-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-context-tests
python3-oslo-db affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-db
python3-oslo-db-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-db-tests
python3-oslo-i18n affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-i18n
python3-oslo-log affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-log
python3-oslo-log-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-log-tests
python3-oslo-messaging affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-messaging
python3-oslo-messaging-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-messaging-tests
python3-oslo-metrics affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-metrics
python3-oslo-metrics-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-metrics-tests
python3-oslo-middleware affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-middleware
python3-oslo-middleware-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-middleware-tests
python3-oslo-policy affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-policy
python3-oslo-policy-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-policy-tests
python3-oslo-rootwrap affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-rootwrap
python3-oslo-rootwrap-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-rootwrap-tests
python3-oslo-serialization affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-serialization
python3-oslo-serialization-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-serialization-tests
python3-oslo-service affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-service
python3-oslo-service-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-service-tests
python3-oslo-upgradecheck affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-upgradecheck
python3-oslo-utils affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-utils
python3-oslo-utils-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-utils-tests
python3-oslo-versionedobjects affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-versionedobjects
python3-oslo-versionedobjects-tests affected Red Hat:openshift_ironic:4.11::el8 python3-oslo-versionedobjects-tests
python3-osprofiler affected Red Hat:openshift_ironic:4.11::el8 python3-osprofiler
python3-os-service-types affected Red Hat:openshift_ironic:4.11::el8 python3-os-service-types
python3-os-traits affected Red Hat:openshift_ironic:4.11::el8 python3-os-traits
python3-os-traits-tests affected Red Hat:openshift_ironic:4.11::el8 python3-os-traits-tests
python3-packaging affected Red Hat:openshift_ironic:4.11::el8 python3-packaging
python3-paste affected Red Hat:openshift_ironic:4.11::el8 python3-paste
python3-paste-deploy affected Red Hat:openshift_ironic:4.11::el8 python3-paste-deploy
python3-pbr affected Red Hat:openshift_ironic:4.11::el8 python3-pbr
python3-pecan affected Red Hat:openshift_ironic:4.11::el8 python3-pecan
python3-pexpect affected Red Hat:openshift_ironic:4.11::el8 python3-pexpect
python3-pint affected Red Hat:openshift_ironic:4.11::el8 python3-pint
python3-proliantutils affected Red Hat:openshift_ironic:4.11::el8 python3-proliantutils
python3-prometheus_client affected Red Hat:openshift_ironic:4.11::el8 python3-prometheus_client
python3-pycadf affected Red Hat:openshift_ironic:4.11::el8 python3-pycadf
python3-pycdlib affected Red Hat:openshift_ironic:4.11::el8 python3-pycdlib
python3-pynacl affected Red Hat:openshift_ironic:4.11::el8 python3-pynacl
python3-pynacl-debuginfo affected Red Hat:openshift_ironic:4.11::el8 python3-pynacl-debuginfo
python3-pyparsing affected Red Hat:openshift_ironic:4.11::el8 python3-pyparsing
python3-pyperclip affected Red Hat:openshift_ironic:4.11::el8 python3-pyperclip
python3-pyrsistent affected Red Hat:openshift_ironic:4.11::el8 python3-pyrsistent
python3-pyrsistent-debuginfo affected Red Hat:openshift_ironic:4.11::el8 python3-pyrsistent-debuginfo
python3-pysnmp affected Red Hat:openshift_ironic:4.11::el8 python3-pysnmp
python3-redis affected Red Hat:openshift_ironic:4.11::el8 python3-redis
python3-repoze-lru affected Red Hat:openshift_ironic:4.11::el8 python3-repoze-lru
python3-requestsexceptions affected Red Hat:openshift_ironic:4.11::el8 python3-requestsexceptions
python3-retrying affected Red Hat:openshift_ironic:4.11::el8 python3-retrying
python3-rfc3986 affected Red Hat:openshift_ironic:4.11::el8 python3-rfc3986
python3-routes affected Red Hat:openshift_ironic:4.11::el8 python3-routes
python3-scciclient affected Red Hat:openshift_ironic:4.11::el8 python3-scciclient
python3-SecretStorage affected Red Hat:openshift_ironic:4.11::el8 python3-SecretStorage
python3-simplegeneric affected Red Hat:openshift_ironic:4.11::el8 python3-simplegeneric
python3-simplejson affected Red Hat:openshift_ironic:4.11::el8 python3-simplejson
python3-simplejson-debuginfo affected Red Hat:openshift_ironic:4.11::el8 python3-simplejson-debuginfo
python3-singledispatch affected Red Hat:openshift_ironic:4.11::el8 python3-singledispatch
python3-six affected Red Hat:openshift_ironic:4.11::el8 python3-six
python3-soupsieve affected Red Hat:openshift_ironic:4.11::el8 python3-soupsieve
python3-sqlparse affected Red Hat:openshift_ironic:4.11::el8 python3-sqlparse
python3-statsd affected Red Hat:openshift_ironic:4.11::el8 python3-statsd
python3-stevedore affected Red Hat:openshift_ironic:4.11::el8 python3-stevedore
python3-sushy affected Red Hat:openshift_ironic:4.11::el8 python3-sushy
python3-sushy-oem-idrac affected Red Hat:openshift_ironic:4.11::el8 python3-sushy-oem-idrac
python3-sushy-oem-idrac-tests affected Red Hat:openshift_ironic:4.11::el8 python3-sushy-oem-idrac-tests
python3-sushy-tests affected Red Hat:openshift_ironic:4.11::el8 python3-sushy-tests
python3-swiftclient affected Red Hat:openshift_ironic:4.11::el8 python3-swiftclient
python3-tempita affected Red Hat:openshift_ironic:4.11::el8 python3-tempita
python3-tenacity affected Red Hat:openshift_ironic:4.11::el8 python3-tenacity
python3-tooz affected Red Hat:openshift_ironic:4.11::el8 python3-tooz
python3-vine affected Red Hat:openshift_ironic:4.11::el8 python3-vine
python3-voluptuous affected Red Hat:openshift_ironic:4.11::el8 python3-voluptuous
python3-waitress affected Red Hat:openshift_ironic:4.11::el8 python3-waitress
python3-warlock affected Red Hat:openshift_ironic:4.11::el8 python3-warlock
python3-wcwidth affected Red Hat:openshift_ironic:4.11::el8 python3-wcwidth
python3-webob affected Red Hat:openshift_ironic:4.11::el8 python3-webob
python3-webtest affected Red Hat:openshift_ironic:4.11::el8 python3-webtest
python3-werkzeug affected Red Hat:openshift_ironic:4.11::el8 python3-werkzeug
python3-wrapt affected Red Hat:openshift_ironic:4.11::el8 python3-wrapt
python3-wrapt-debuginfo affected Red Hat:openshift_ironic:4.11::el8 python3-wrapt-debuginfo
python3-wsme affected Red Hat:openshift_ironic:4.11::el8 python3-wsme
python3-yappi affected Red Hat:openshift_ironic:4.11::el8 python3-yappi
python3-yappi-debuginfo affected Red Hat:openshift_ironic:4.11::el8 python3-yappi-debuginfo
python3-zake affected Red Hat:openshift_ironic:4.11::el8 python3-zake
python3-zeroconf affected Red Hat:openshift_ironic:4.11::el8 python3-zeroconf
python3-zipp affected Red Hat:openshift_ironic:4.11::el8 python3-zipp
python-alembic affected Red Hat:openshift_ironic:4.11::el8 python-alembic
python-amqp affected Red Hat:openshift_ironic:4.11::el8 python-amqp
python-amqp-doc affected Red Hat:openshift_ironic:4.11::el8 python-amqp-doc
python-appdirs affected Red Hat:openshift_ironic:4.11::el8 python-appdirs
python-automaton affected Red Hat:openshift_ironic:4.11::el8 python-automaton
python-bcrypt affected Red Hat:openshift_ironic:4.11::el8 python-bcrypt
python-bcrypt-debugsource affected Red Hat:openshift_ironic:4.11::el8 python-bcrypt-debugsource
python-beautifulsoup4 affected Red Hat:openshift_ironic:4.11::el8 python-beautifulsoup4
python-cachetools affected Red Hat:openshift_ironic:4.11::el8 python-cachetools
python-cinderclient affected Red Hat:openshift_ironic:4.11::el8 python-cinderclient
python-cliff affected Red Hat:openshift_ironic:4.11::el8 python-cliff
python-colorama affected Red Hat:openshift_ironic:4.11::el8 python-colorama
python-construct affected Red Hat:openshift_ironic:4.11::el8 python-construct
python-dataclasses affected Red Hat:openshift_ironic:4.11::el8 python-dataclasses
python-debtcollector affected Red Hat:openshift_ironic:4.11::el8 python-debtcollector
python-decorator affected Red Hat:openshift_ironic:4.11::el8 python-decorator
python-dogpile-cache affected Red Hat:openshift_ironic:4.11::el8 python-dogpile-cache
python-dracclient affected Red Hat:openshift_ironic:4.11::el8 python-dracclient
python-editor affected Red Hat:openshift_ironic:4.11::el8 python-editor
python-fasteners affected Red Hat:openshift_ironic:4.11::el8 python-fasteners
python-flask affected Red Hat:openshift_ironic:4.11::el8 python-flask
python-flask-doc affected Red Hat:openshift_ironic:4.11::el8 python-flask-doc
python-funcsigs affected Red Hat:openshift_ironic:4.11::el8 python-funcsigs
python-futurist affected Red Hat:openshift_ironic:4.11::el8 python-futurist
python-glanceclient affected Red Hat:openshift_ironic:4.11::el8 python-glanceclient
python-greenlet affected Red Hat:openshift_ironic:4.11::el8 python-greenlet
python-greenlet-debugsource affected Red Hat:openshift_ironic:4.11::el8 python-greenlet-debugsource
python-hardware affected Red Hat:openshift_ironic:4.11::el8 python-hardware
python-ifaddr affected Red Hat:openshift_ironic:4.11::el8 python-ifaddr
python-importlib-metadata affected Red Hat:openshift_ironic:4.11::el8 python-importlib-metadata
python-ironic-lib affected Red Hat:openshift_ironic:4.11::el8 python-ironic-lib
python-ironic-prometheus-exporter affected Red Hat:openshift_ironic:4.11::el8 python-ironic-prometheus-exporter
python-iso8601 affected Red Hat:openshift_ironic:4.11::el8 python-iso8601
python-jsonpath-rw affected Red Hat:openshift_ironic:4.11::el8 python-jsonpath-rw
python-jsonschema affected Red Hat:openshift_ironic:4.11::el8 python-jsonschema
python-kazoo affected Red Hat:openshift_ironic:4.11::el8 python-kazoo
python-keyring affected Red Hat:openshift_ironic:4.11::el8 python-keyring
python-keystoneauth1 affected Red Hat:openshift_ironic:4.11::el8 python-keystoneauth1
python-keystoneclient affected Red Hat:openshift_ironic:4.11::el8 python-keystoneclient
python-keystonemiddleware affected Red Hat:openshift_ironic:4.11::el8 python-keystonemiddleware
python-kombu affected Red Hat:openshift_ironic:4.11::el8 python-kombu
python-logutils affected Red Hat:openshift_ironic:4.11::el8 python-logutils
python-memcached affected Red Hat:openshift_ironic:4.11::el8 python-memcached
python-migrate affected Red Hat:openshift_ironic:4.11::el8 python-migrate
python-msgpack affected Red Hat:openshift_ironic:4.11::el8 python-msgpack
python-msgpack-debugsource affected Red Hat:openshift_ironic:4.11::el8 python-msgpack-debugsource
python-munch affected Red Hat:openshift_ironic:4.11::el8 python-munch
python-openstacksdk affected Red Hat:openshift_ironic:4.11::el8 python-openstacksdk
python-osc-lib affected Red Hat:openshift_ironic:4.11::el8 python-osc-lib
python-oslo-cache affected Red Hat:openshift_ironic:4.11::el8 python-oslo-cache
python-oslo-cache-lang affected Red Hat:openshift_ironic:4.11::el8 python-oslo-cache-lang
python-oslo-concurrency affected Red Hat:openshift_ironic:4.11::el8 python-oslo-concurrency
python-oslo-concurrency-lang affected Red Hat:openshift_ironic:4.11::el8 python-oslo-concurrency-lang
python-oslo-config affected Red Hat:openshift_ironic:4.11::el8 python-oslo-config
python-oslo-context affected Red Hat:openshift_ironic:4.11::el8 python-oslo-context
python-oslo-db affected Red Hat:openshift_ironic:4.11::el8 python-oslo-db
python-oslo-db-lang affected Red Hat:openshift_ironic:4.11::el8 python-oslo-db-lang
python-oslo-i18n affected Red Hat:openshift_ironic:4.11::el8 python-oslo-i18n
python-oslo-i18n-lang affected Red Hat:openshift_ironic:4.11::el8 python-oslo-i18n-lang
python-oslo-log affected Red Hat:openshift_ironic:4.11::el8 python-oslo-log
python-oslo-log-lang affected Red Hat:openshift_ironic:4.11::el8 python-oslo-log-lang
python-oslo-messaging affected Red Hat:openshift_ironic:4.11::el8 python-oslo-messaging
python-oslo-metrics affected Red Hat:openshift_ironic:4.11::el8 python-oslo-metrics
python-oslo-middleware affected Red Hat:openshift_ironic:4.11::el8 python-oslo-middleware
python-oslo-middleware-lang affected Red Hat:openshift_ironic:4.11::el8 python-oslo-middleware-lang
python-oslo-policy affected Red Hat:openshift_ironic:4.11::el8 python-oslo-policy
python-oslo-policy-lang affected Red Hat:openshift_ironic:4.11::el8 python-oslo-policy-lang
python-oslo-rootwrap affected Red Hat:openshift_ironic:4.11::el8 python-oslo-rootwrap
python-oslo-serialization affected Red Hat:openshift_ironic:4.11::el8 python-oslo-serialization
python-oslo-service affected Red Hat:openshift_ironic:4.11::el8 python-oslo-service
python-oslo-upgradecheck affected Red Hat:openshift_ironic:4.11::el8 python-oslo-upgradecheck
python-oslo-utils affected Red Hat:openshift_ironic:4.11::el8 python-oslo-utils
python-oslo-utils-lang affected Red Hat:openshift_ironic:4.11::el8 python-oslo-utils-lang
python-oslo-versionedobjects affected Red Hat:openshift_ironic:4.11::el8 python-oslo-versionedobjects
python-oslo-versionedobjects-lang affected Red Hat:openshift_ironic:4.11::el8 python-oslo-versionedobjects-lang
python-osprofiler affected Red Hat:openshift_ironic:4.11::el8 python-osprofiler
python-os-service-types affected Red Hat:openshift_ironic:4.11::el8 python-os-service-types
python-os-traits affected Red Hat:openshift_ironic:4.11::el8 python-os-traits
python-packaging affected Red Hat:openshift_ironic:4.11::el8 python-packaging
python-packaging-doc affected Red Hat:openshift_ironic:4.11::el8 python-packaging-doc
python-paste affected Red Hat:openshift_ironic:4.11::el8 python-paste
python-paste-deploy affected Red Hat:openshift_ironic:4.11::el8 python-paste-deploy
python-pbr affected Red Hat:openshift_ironic:4.11::el8 python-pbr
python-pecan affected Red Hat:openshift_ironic:4.11::el8 python-pecan
python-pexpect affected Red Hat:openshift_ironic:4.11::el8 python-pexpect
python-pint affected Red Hat:openshift_ironic:4.11::el8 python-pint
python-proliantutils affected Red Hat:openshift_ironic:4.11::el8 python-proliantutils
python-prometheus_client affected Red Hat:openshift_ironic:4.11::el8 python-prometheus_client
python-pycadf affected Red Hat:openshift_ironic:4.11::el8 python-pycadf
python-pycadf-common affected Red Hat:openshift_ironic:4.11::el8 python-pycadf-common
python-pycdlib affected Red Hat:openshift_ironic:4.11::el8 python-pycdlib
python-pynacl affected Red Hat:openshift_ironic:4.11::el8 python-pynacl
python-pynacl-debugsource affected Red Hat:openshift_ironic:4.11::el8 python-pynacl-debugsource
python-pyperclip affected Red Hat:openshift_ironic:4.11::el8 python-pyperclip
python-pyperclip-doc affected Red Hat:openshift_ironic:4.11::el8 python-pyperclip-doc
python-pyrsistent affected Red Hat:openshift_ironic:4.11::el8 python-pyrsistent
python-pyrsistent-debugsource affected Red Hat:openshift_ironic:4.11::el8 python-pyrsistent-debugsource
python-redis affected Red Hat:openshift_ironic:4.11::el8 python-redis
python-repoze-lru affected Red Hat:openshift_ironic:4.11::el8 python-repoze-lru
python-requestsexceptions affected Red Hat:openshift_ironic:4.11::el8 python-requestsexceptions
python-retrying affected Red Hat:openshift_ironic:4.11::el8 python-retrying
python-rfc3986 affected Red Hat:openshift_ironic:4.11::el8 python-rfc3986
python-routes affected Red Hat:openshift_ironic:4.11::el8 python-routes
python-scciclient affected Red Hat:openshift_ironic:4.11::el8 python-scciclient
python-SecretStorage affected Red Hat:openshift_ironic:4.11::el8 python-SecretStorage
python-simplegeneric affected Red Hat:openshift_ironic:4.11::el8 python-simplegeneric
python-simplejson affected Red Hat:openshift_ironic:4.11::el8 python-simplejson
python-simplejson-debugsource affected Red Hat:openshift_ironic:4.11::el8 python-simplejson-debugsource
python-singledispatch affected Red Hat:openshift_ironic:4.11::el8 python-singledispatch
python-six affected Red Hat:openshift_ironic:4.11::el8 python-six
python-soupsieve affected Red Hat:openshift_ironic:4.11::el8 python-soupsieve
python-sqlparse affected Red Hat:openshift_ironic:4.11::el8 python-sqlparse
python-statsd affected Red Hat:openshift_ironic:4.11::el8 python-statsd
python-stevedore affected Red Hat:openshift_ironic:4.11::el8 python-stevedore
python-sushy affected Red Hat:openshift_ironic:4.11::el8 python-sushy
python-sushy-oem-idrac affected Red Hat:openshift_ironic:4.11::el8 python-sushy-oem-idrac
python-swiftclient affected Red Hat:openshift_ironic:4.11::el8 python-swiftclient
python-tempita affected Red Hat:openshift_ironic:4.11::el8 python-tempita
python-tenacity affected Red Hat:openshift_ironic:4.11::el8 python-tenacity
python-tooz affected Red Hat:openshift_ironic:4.11::el8 python-tooz
python-vine affected Red Hat:openshift_ironic:4.11::el8 python-vine
python-voluptuous affected Red Hat:openshift_ironic:4.11::el8 python-voluptuous
python-waitress affected Red Hat:openshift_ironic:4.11::el8 python-waitress
python-warlock affected Red Hat:openshift_ironic:4.11::el8 python-warlock
python-wcwidth affected Red Hat:openshift_ironic:4.11::el8 python-wcwidth
python-webob affected Red Hat:openshift_ironic:4.11::el8 python-webob
python-webtest affected Red Hat:openshift_ironic:4.11::el8 python-webtest
python-werkzeug affected Red Hat:openshift_ironic:4.11::el8 python-werkzeug
python-wrapt affected Red Hat:openshift_ironic:4.11::el8 python-wrapt
python-wrapt-debugsource affected Red Hat:openshift_ironic:4.11::el8 python-wrapt-debugsource
python-wrapt-doc affected Red Hat:openshift_ironic:4.11::el8 python-wrapt-doc
python-wsme affected Red Hat:openshift_ironic:4.11::el8 python-wsme
python-yappi affected Red Hat:openshift_ironic:4.11::el8 python-yappi
python-yappi-debugsource affected Red Hat:openshift_ironic:4.11::el8 python-yappi-debugsource
python-zake affected Red Hat:openshift_ironic:4.11::el8 python-zake
python-zeroconf affected Red Hat:openshift_ironic:4.11::el8 python-zeroconf
python-zipp affected Red Hat:openshift_ironic:4.11::el8 python-zipp
runc affected Red Hat:openshift:4.11::el8 runc
runc-debuginfo affected Red Hat:openshift:4.11::el8 runc-debuginfo
runc-debugsource affected Red Hat:openshift:4.11::el8 runc-debugsource
rust-afterburn affected Red Hat:openshift:4.11::el8 rust-afterburn
rust-afterburn-debugsource affected Red Hat:openshift:4.11::el8 rust-afterburn-debugsource
rust-bootupd affected Red Hat:openshift:4.11::el8 rust-bootupd
rust-bootupd-debugsource affected Red Hat:openshift:4.11::el8 rust-bootupd-debugsource
skopeo affected Red Hat:openshift:4.11::el8 skopeo
skopeo-debuginfo affected Red Hat:openshift:4.11::el8 skopeo-debuginfo
skopeo-debugsource affected Red Hat:openshift:4.11::el8 skopeo-debugsource
skopeo-tests affected Red Hat:openshift:4.11::el8 skopeo-tests
slirp4netns affected Red Hat:openshift:4.11::el8 slirp4netns
slirp4netns-debuginfo affected Red Hat:openshift:4.11::el8 slirp4netns-debuginfo
slirp4netns-debugsource affected Red Hat:openshift:4.11::el8 slirp4netns-debugsource
toolbox affected Red Hat:openshift:4.11::el8 toolbox
Upstream advisory

RHSA-2022:5799

Open SourcePoC exploitHIGH2022-08-01

Red Hat Security Advisory: go-toolset and golang security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:9::appstream golang
golang-bin affected Red Hat:enterprise_linux:9::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:9::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:9::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:9::appstream golang-race
golang-src affected Red Hat:enterprise_linux:9::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:9::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:9::appstream go-toolset
Upstream advisory

RLSA-2022:5799

Open SourcePoC exploitHIGH2022-08-01

Important: go-toolset and golang security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Rocky Linux:9 golang
go-toolset affected Rocky Linux:9 go-toolset
Upstream advisory

PUB-A-227452856

GooglePoC exploit2022-08-01

PUB-A-227452856

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

OESA-2022-1857

Open SourcePoC exploitHIGH2022-08-26

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP3 golang
golang affected openEuler:22.03-LTS golang
Upstream advisory

OESA-2022-1830

Open SourcePoC exploitHIGH2022-08-13

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP3 golang
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:22.03-LTS golang
Upstream advisory

MGASA-2022-0283

Open SourcePoC exploitHIGH2022-08-13

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

AZL-10539

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-32189 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

DEBIAN-CVE-2022-32189

Open SourcePoC exploitHIGH2022-08-10

DEBIAN-CVE-2022-32189

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-32189

GooglePoC exploitHIGH2022-08-01

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.

CVEs:CVE-2022-32189

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2022-0537

Open SourcePoC exploitHIGH2022-08-01

Panic when decoding Float and Rat types in math/big

Affected products

ProductStatusVendorPackageEcosystem
stdlib affected Go stdlib
Upstream advisory

AZL-10531

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-28131 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79000

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-28131 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-28131

Open SourcePoC exploitHIGH2022-08-10

DEBIAN-CVE-2022-28131

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

RHSA-2022:5866

Open SourcePoC exploitHIGH2022-08-02

Red Hat Security Advisory: go-toolset-1.17 and go-toolset-1.17-golang security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
go-toolset-1.17 affected Red Hat:devtools:2022 go-toolset-1.17
go-toolset-1.17-build affected Red Hat:devtools:2022 go-toolset-1.17-build
go-toolset-1.17-golang affected Red Hat:devtools:2022 go-toolset-1.17-golang
go-toolset-1.17-golang-bin affected Red Hat:devtools:2022 go-toolset-1.17-golang-bin
go-toolset-1.17-golang-docs affected Red Hat:devtools:2022 go-toolset-1.17-golang-docs
go-toolset-1.17-golang-misc affected Red Hat:devtools:2022 go-toolset-1.17-golang-misc
go-toolset-1.17-golang-race affected Red Hat:devtools:2022 go-toolset-1.17-golang-race
go-toolset-1.17-golang-src affected Red Hat:devtools:2022 go-toolset-1.17-golang-src
go-toolset-1.17-golang-tests affected Red Hat:devtools:2022 go-toolset-1.17-golang-tests
go-toolset-1.17-runtime affected Red Hat:devtools:2022 go-toolset-1.17-runtime
go-toolset-1.17-scldevel affected Red Hat:devtools:2022 go-toolset-1.17-scldevel
Upstream advisory

RHSA-2022:5775

Open SourcePoC exploitHIGH2022-08-01

Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

RLSA-2022:5775

Open SourcePoC exploitHIGH2022-08-01

Important: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

ALSA-2022:5775

Open SourcePoC exploit2022-08-01

Important: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected AlmaLinux:8 delve
golang affected AlmaLinux:8 golang
golang-bin affected AlmaLinux:8 golang-bin
golang-docs affected AlmaLinux:8 golang-docs
golang-misc affected AlmaLinux:8 golang-misc
golang-race affected AlmaLinux:8 golang-race
golang-src affected AlmaLinux:8 golang-src
golang-tests affected AlmaLinux:8 golang-tests
go-toolset affected AlmaLinux:8 go-toolset
Upstream advisory

ALSA-2022:5799

Open SourcePoC exploit2022-08-01

Important: go-toolset and golang security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
golang affected AlmaLinux:9 golang
golang-bin affected AlmaLinux:9 golang-bin
golang-docs affected AlmaLinux:9 golang-docs
golang-misc affected AlmaLinux:9 golang-misc
golang-race affected AlmaLinux:9 golang-race
golang-src affected AlmaLinux:9 golang-src
golang-tests affected AlmaLinux:9 golang-tests
Upstream advisory

AZL-79118

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-29804 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-10536

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30633 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79040

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30633 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-30633

Open SourcePoC exploitHIGH2022-08-10

DEBIAN-CVE-2022-30633

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

AZL-10535

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30632 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79096

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30632 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-30632

Open SourcePoC exploitHIGH2022-08-10

DEBIAN-CVE-2022-30632

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

AZL-10533

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30630 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

DEBIAN-CVE-2022-30630

Open SourcePoC exploitHIGH2022-08-10

DEBIAN-CVE-2022-30630

Affected products

ProductStatusVendorPackageEcosystem
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

OESA-2022-1797

Open SourcePoC exploit2022-08-05

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS golang
Upstream advisory

AZL-10534

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30631 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79092

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30631 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-30631

Open SourcePoC exploitHIGH2022-08-10

DEBIAN-CVE-2022-30631

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GO-2022-0956

Open SourcePoC exploitCRITICAL2022-08-29

Excessive resource consumption in gopkg.in/yaml.v2

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
k3d affected wolfi k3d
k3d affected chainguard k3d
yaml.v2 affected gopkg.in gopkg.in/yaml.v2
Upstream advisory

AZL-10537

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30635 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79086

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30635 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-30635

Open SourcePoC exploitHIGH2022-08-10

DEBIAN-CVE-2022-30635

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

PUB-A-226679409

GooglePoC exploit2022-08-01

PUB-A-226679409

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20347

Open SourcePoC exploitHIGH2022-08-02

In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interacti...

CVEs:CVE-2022-20347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-233075473

GooglePoC exploitHIGH2022-08-01

PUB-A-233075473

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

AZL-10532

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30580 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79108

Open SourcePoC exploitHIGH2022-08-10

CVE-2022-30580 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

PUB-A-223967238

GooglePoC exploit2022-08-01

PUB-A-223967238

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-232440670

GooglePoC exploit2022-08-01

ASB-A-232440670

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-232441339

GooglePoC exploitHIGH2022-08-01

ASB-A-232441339

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39696

Open SourcePoC exploitHIGH2022-08-02

In Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2021-39696

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20338

Open SourcePoC exploitLOW2022-08-12

In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to a local escalation of privilege, preventing processes from validating URIs correctly, with no addition...

CVEs:CVE-2022-20338

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20369

Open SourcePoC exploitHIGH2022-08-02

In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20369

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

PUB-A-223375145

GooglePoC exploitHIGH2022-08-01

PUB-A-223375145

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-21789

Open SourcePoC exploitHIGH2022-08-01

In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478101; Issue ID: AL...

CVEs:CVE-2022-21789

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-224546354

GooglePoC exploit2022-08-01

PUB-A-224546354

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20355

Open SourcePoC exploitMEDIUM2022-08-02

In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2022-20355

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2022:10073-1

Open SourceCoalition ESS < 30%CRITICAL2022-08-01

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.3 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

CVE-2022-2852

GoogleCoalition ESS < 30%CRITICAL2022-08-17

Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2852

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-33649

Open SourceCoalition ESS < 30%CRITICAL2022-08-08

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVEs:CVE-2022-33649

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-2853

GoogleCoalition ESS < 30%CRITICAL2022-08-17

Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2853

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

AZL-10529

Open SourceCoalition ESS < 30%MEDIUM2022-08-10

CVE-2022-1705 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79116

Open SourceCoalition ESS < 30%MEDIUM2022-08-10

CVE-2022-1705 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-1705

Open SourceCoalition ESS < 30%MEDIUM2022-08-10

DEBIAN-CVE-2022-1705

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

AZL-10538

Open SourceCoalition ESS < 30%MEDIUM2022-08-10

CVE-2022-32148 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79054

Open SourceCoalition ESS < 30%MEDIUM2022-08-10

CVE-2022-32148 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-32148

Open SourceCoalition ESS < 30%MEDIUM2022-08-10

DEBIAN-CVE-2022-32148

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-35796

Open SourceCoalition ESS < 30%CRITICAL2022-08-08

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-35796

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-33636

Open SourceCoalition ESS < 30%CRITICAL2022-08-08

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2022-33636

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

AZL-10550

Open SourceCoalition ESS < 30%LOW2022-08-10

CVE-2022-30629 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

DEBIAN-CVE-2022-30629

Open SourceCoalition ESS < 30%LOW2022-08-10

DEBIAN-CVE-2022-30629

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
Upstream advisory

CVE-2022-3045

GoogleCoalition ESS < 30%HIGH2022-08-30

Insufficient validation of untrusted input in V8 in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3045

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3056

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2022-3056

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2613

Open SourceCoalition ESS < 30%HIGH2022-08-12

DEBIAN-CVE-2022-2613

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2613

GoogleCoalition ESS < 30%HIGH2022-08-03

Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

CVEs:CVE-2022-2613

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

AZL-10530

Open SourceCoalition ESS < 30%MEDIUM2022-08-10

CVE-2022-1962 affecting package golang for versions less than 1.18.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-78972

Open SourceCoalition ESS < 30%MEDIUM2022-08-10

CVE-2022-1962 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-1962

Open SourceCoalition ESS < 30%MEDIUM2022-08-10

DEBIAN-CVE-2022-1962

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

DEBIAN-CVE-2022-2624

Open SourceCoalition ESS < 30%HIGH2022-08-12

DEBIAN-CVE-2022-2624

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2022-2624

GoogleCoalition ESS < 30%HIGH2022-08-03

Heap buffer overflow in PDF in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2022-2624

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3044

GoogleCoalition ESS < 30%MEDIUM2022-08-30

Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

CVEs:CVE-2022-3044

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2860

GoogleCoalition ESS < 30%CRITICAL2022-08-17

Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page.

CVEs:CVE-2022-2860

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3040

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3040

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3041

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3041

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-4696-g7jj-xg2h

Open SourceCoalition ESS < 30%CRITICAL2022-08-17

Mapbox is vulnerable to Integer Overflow

Affected products

ProductStatusVendorPackageEcosystem
com.mapbox.mapboxsdk:mapbox-android-core affected Maven com.mapbox.mapboxsdk:mapbox-android-core
Upstream advisory

GHSA-4696-g7jj-xg2h

Open SourceCoalition ESS < 30%CRITICAL2022-08-17

Mapbox is vulnerable to Integer Overflow

Affected products

ProductStatusVendorPackageEcosystem
com.mapbox.mapboxsdk:mapbox-android-core affected Maven com.mapbox.mapboxsdk:mapbox-android-core
Upstream advisory

CVE-2022-38216

GoogleCoalition ESS < 30%CRITICAL2022-08-16

An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating ...

CVEs:CVE-2022-38216

Affected products

ProductStatusVendorPackageEcosystem
maps_software_development_kit affected mapbox
Upstream advisory

CVE-2022-38216

Open SourceCoalition ESS < 30%HIGH2022-08-16

Mapbox is vulnerable to Integer Overflow

CVEs:CVE-2022-38216

Affected products

ProductStatusVendorPackageEcosystem
com.mapbox.mapboxsdk:mapbox-android-core affected Maven com.mapbox.mapboxsdk:mapbox-android-core
Upstream advisory

CVE-2022-2858

GoogleCoalition ESS < 30%CRITICAL2022-08-17

Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction.

CVEs:CVE-2022-2858

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2855

GoogleCoalition ESS < 30%CRITICAL2022-08-17

Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2855

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2859

GoogleCoalition ESS < 30%CRITICAL2022-08-17

Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions.

CVEs:CVE-2022-2859

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3046

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3046

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3039

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3039

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3052

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.

CVEs:CVE-2022-3052

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
linux_and_chrome_os affected google
Upstream advisory

DEBIAN-CVE-2022-2610

Open SourceCoalition ESS < 30%CRITICAL2022-08-12

DEBIAN-CVE-2022-2610

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2610

GoogleCoalition ESS < 30%CRITICAL2022-08-03

Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-2610

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2603

Open SourceCoalition ESS < 30%CRITICAL2022-08-12

DEBIAN-CVE-2022-2603

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2603

GoogleCoalition ESS < 30%CRITICAL2022-08-03

Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2603

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3050

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Heap buffer overflow in WebUI in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.

CVEs:CVE-2022-3050

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2587

GoogleCoalition ESS < 30%CRITICAL2022-08-12

Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.

CVEs:CVE-2022-2587

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-2614

Open SourceCoalition ESS < 30%CRITICAL2022-08-12

DEBIAN-CVE-2022-2614

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2614

GoogleCoalition ESS < 30%CRITICAL2022-08-03

Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2614

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2612

Open SourceCoalition ESS < 30%HIGH2022-08-12

DEBIAN-CVE-2022-2612

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2612

GoogleCoalition ESS < 30%HIGH2022-08-03

Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2022-2612

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2604

Open SourceCoalition ESS < 30%CRITICAL2022-08-12

DEBIAN-CVE-2022-2604

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-2606

Open SourceCoalition ESS < 30%CRITICAL2022-08-12

DEBIAN-CVE-2022-2606

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2604

GoogleCoalition ESS < 30%CRITICAL2022-08-03

Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2604

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2606

GoogleCoalition ESS < 30%CRITICAL2022-08-03

Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enable a specific Enterprise policy to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2606

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2615

Open SourceCoalition ESS < 30%CRITICAL2022-08-12

DEBIAN-CVE-2022-2615

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-2605

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

DEBIAN-CVE-2022-2605

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2022-2605

GoogleCoalition ESS < 30%MEDIUM2022-08-03

Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2605

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2615

GoogleCoalition ESS < 30%CRITICAL2022-08-03

Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-2615

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2618

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

DEBIAN-CVE-2022-2618

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2618

GoogleCoalition ESS < 30%MEDIUM2022-08-03

Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a malicious file .

CVEs:CVE-2022-2618

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2621

Open SourceCoalition ESS < 30%CRITICAL2022-08-12

DEBIAN-CVE-2022-2621

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2621

GoogleCoalition ESS < 30%CRITICAL2022-08-03

Use after free in Extensions in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.

CVEs:CVE-2022-2621

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3043

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3043

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3055

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3055

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2620

Open SourceCoalition ESS < 30%HIGH2022-08-12

DEBIAN-CVE-2022-2620

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2620

GoogleCoalition ESS < 30%HIGH2022-08-03

Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

CVEs:CVE-2022-2620

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3051

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.

CVEs:CVE-2022-3051

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
linux_and_chrome_os affected google
Upstream advisory

CVE-2022-2854

GoogleCoalition ESS < 30%CRITICAL2022-08-17

Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2854

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2622

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

DEBIAN-CVE-2022-2622

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2622

GoogleCoalition ESS < 30%MEDIUM2022-08-03

Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file.

CVEs:CVE-2022-2622

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2857

GoogleCoalition ESS < 30%CRITICAL2022-08-17

Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-2857

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3058

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.

CVEs:CVE-2022-3058

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3054

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3054

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2611

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

DEBIAN-CVE-2022-2611

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2611

GoogleCoalition ESS < 30%MEDIUM2022-08-03

Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2022-2611

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-20237

Open SourceCoalition ESS < 30%CRITICAL2022-08-02

In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2022-20237

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-229621649

GoogleCoalition ESS < 30%HIGH2022-08-01

PUB-A-229621649

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-2861

GoogleCoalition ESS < 30%MEDIUM2022-08-17

Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.

CVEs:CVE-2022-2861

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2424

GoogleCoalition ESS < 30%CRITICAL2022-08-08

The Google Maps Anywhere WordPress plugin through 1.2.6.3 does not sanitise and escape any of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disal...

CVEs:CVE-2022-2424

Affected products

ProductStatusVendorPackageEcosystem
google_maps_anywhere affected google_maps_anywhere_project
Upstream advisory

CVE-2022-20308

Open SourceCoalition ESS < 30%HIGH2022-08-12

In hostapd, there is a possible insecure configuration due to an insecure default value. This could lead to remote denial of service of the wifi hotspot with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2022-20308

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20247

Open SourceCoalition ESS < 30%HIGH2022-08-11

In Media, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2022-20247

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-3053

GoogleCoalition ESS < 30%MEDIUM2022-08-30

Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.

CVEs:CVE-2022-3053

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3049

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3049

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3057

GoogleCoalition ESS < 30%MEDIUM2022-08-30

Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2022-3057

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3042

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2022-3042

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2608

Open SourceCoalition ESS < 30%HIGH2022-08-12

DEBIAN-CVE-2022-2608

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-2609

Open SourceCoalition ESS < 30%HIGH2022-08-12

DEBIAN-CVE-2022-2609

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2608

GoogleCoalition ESS < 30%HIGH2022-08-03

Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

CVEs:CVE-2022-2608

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-2609

GoogleCoalition ESS < 30%HIGH2022-08-03

Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

CVEs:CVE-2022-2609

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

PUB-A-228390920

GoogleCoalition ESS < 30%2022-08-01

PUB-A-228390920

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20346

Open SourceCoalition ESS < 30%HIGH2022-08-02

In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction...

CVEs:CVE-2022-20346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2022-2607

Open SourceCoalition ESS < 30%HIGH2022-08-12

DEBIAN-CVE-2022-2607

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2607

GoogleCoalition ESS < 30%HIGH2022-08-03

Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

CVEs:CVE-2022-2607

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3047

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.

CVEs:CVE-2022-3047

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2616

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

DEBIAN-CVE-2022-2616

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2616

GoogleCoalition ESS < 30%MEDIUM2022-08-03

Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to spoof the contents of the Omnibox (URL bar) via a crafted Chrome Extension.

CVEs:CVE-2022-2616

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-3071

GoogleCoalition ESS < 30%CRITICAL2022-08-30

Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.

CVEs:CVE-2022-3071

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2619

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

DEBIAN-CVE-2022-2619

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2619

GoogleCoalition ESS < 30%MEDIUM2022-08-03

Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.

CVEs:CVE-2022-2619

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-2617

Open SourceCoalition ESS < 30%CRITICAL2022-08-12

DEBIAN-CVE-2022-2617

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-2617

GoogleCoalition ESS < 30%CRITICAL2022-08-03

Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.

CVEs:CVE-2022-2617

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-20402

Open SourceCoalition ESS < 30%CRITICAL2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A

CVEs:CVE-2022-20402

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-218701042

GoogleCoalition ESS < 30%2022-08-01

PUB-A-218701042

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20365

Open SourceCoalition ESS < 30%CRITICAL2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A

CVEs:CVE-2022-20365

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-229632566

GoogleCoalition ESS < 30%2022-08-01

PUB-A-229632566

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-3048

GoogleCoalition ESS < 30%MEDIUM2022-08-30

Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.

CVEs:CVE-2022-3048

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2022-33719

Open SourceCoalition ESS < 30%CRITICAL2022-08-05

Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

CVEs:CVE-2022-33719

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20384

Open SourceCoalition ESS < 30%CRITICAL2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A

CVEs:CVE-2022-20384

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20405

Open SourceCoalition ESS < 30%CRITICAL2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A

CVEs:CVE-2022-20405

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-211727306

GoogleCoalition ESS < 30%2022-08-01

PUB-A-211727306

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-216363416

GoogleCoalition ESS < 30%2022-08-01

PUB-A-216363416

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20370

Open SourceCoalition ESS < 30%HIGH2022-08-02

Product: AndroidVersions: Android kernelAndroid ID: A-215730643References: N/A

CVEs:CVE-2022-20370

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-215730643

GoogleCoalition ESS < 30%2022-08-01

PUB-A-215730643

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20239

Open SourceCoalition ESS < 30%CRITICAL2022-08-02

remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedP...

CVEs:CVE-2022-20239

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-233972091

GoogleCoalition ESS < 30%2022-08-01

ASB-A-233972091

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20362

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2022-20362

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20283

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2022-20283

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20273

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2022-20273

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20333

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Bluetooth, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android...

CVEs:CVE-2022-20333

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20334

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Bluetooth, there are possible process crashes due to dereferencing a null pointer. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...

CVEs:CVE-2022-20334

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20253

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Bluetooth, there is a possible cleanup failure due to an uncaught exception. This could lead to remote denial of service in Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...

CVEs:CVE-2022-20253

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-205573273

GoogleCoalition ESS < 30%HIGH2022-08-01

PUB-A-205573273

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20358

Open SourceCoalition ESS < 30%HIGH2022-08-02

In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User in...

CVEs:CVE-2022-20358

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20254

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Wi-Fi, there is a permissions bypass. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID...

CVEs:CVE-2022-20254

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20313

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And...

CVEs:CVE-2022-20313

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20269

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Bluetooth, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...

CVEs:CVE-2022-20269

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33730

Open SourceCoalition ESS < 30%CRITICAL2022-08-05

Heap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical attackers.

CVEs:CVE-2022-33730

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20302

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Settings, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to local escalation of privilege if the attacker has physical access to the device, with no additional execution privileges needed. User i...

CVEs:CVE-2022-20302

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20244

Open SourceCoalition ESS < 30%HIGH2022-08-11

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if more than 100 bluetooth devices have been connected with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20244

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20280

Open SourceCoalition ESS < 30%HIGH2022-08-12

In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lead to local information disclosure of sms/mms data with User execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2022-20280

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33723

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

CVEs:CVE-2022-33723

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33727

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

CVEs:CVE-2022-33727

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20265

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Settings, there is a possible way to bypass factory reset permissions due to a permissions bypass. This could lead to local escalation of privilege with physical access to the device with no additional execution privileges needed. User interaction i...

CVEs:CVE-2022-20265

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33720

Open SourceCoalition ESS < 30%LOW2022-08-05

Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.

CVEs:CVE-2022-33720

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20245

Open SourceCoalition ESS < 30%MEDIUM2022-08-11

In WindowManager, there is a possible method to create a recording of the lock screen due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for explo...

CVEs:CVE-2022-20245

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20330

Open SourceCoalition ESS < 30%LOW2022-08-12

In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not n...

CVEs:CVE-2022-20330

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20158

Open SourceCoalition ESS < 30%HIGH2022-08-02

In bdi_put and bdi_unregister of backing-dev.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2022-20158

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-182815710

GoogleCoalition ESS < 30%HIGH2022-08-01

PUB-A-182815710

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20317

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In SystemUI, there is a possible way to unexpectedly enable the external speaker due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitati...

CVEs:CVE-2022-20317

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20271

Open SourceCoalition ESS < 30%HIGH2022-08-12

In PermissionController, there is a possible way to grant some permissions without user consent due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2022-20271

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20331

Open SourceCoalition ESS < 30%HIGH2022-08-12

In the Framework, there is a possible way to enable a work profile without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for ...

CVEs:CVE-2022-20331

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33725

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to access content providers with system privilege.

CVEs:CVE-2022-33725

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20292

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Settings, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20292

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20297

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Settings, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20297

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20282

Open SourceCoalition ESS < 30%HIGH2022-08-12

In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitati...

CVEs:CVE-2022-20282

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20286

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Connectivity, there is a possible bypass the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2022-20286

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-cm6r-892j-jv2g

Open SourceCoalition ESS < 30%MEDIUM2022-08-13

Google Play Services SDK leads to apps having incorrectly set mutability flag

Affected products

ProductStatusVendorPackageEcosystem
com.google.android.gms:play-services-basement affected Maven com.google.android.gms:play-services-basement
Upstream advisory

GHSA-cm6r-892j-jv2g

Open SourceCoalition ESS < 30%MEDIUM2022-08-13

Google Play Services SDK leads to apps having incorrectly set mutability flag

Affected products

ProductStatusVendorPackageEcosystem
com.google.android.gms:play-services-basement affected Maven com.google.android.gms:play-services-basement
Upstream advisory

CVE-2022-20321

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interac...

CVEs:CVE-2022-20321

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-2390

GoogleCoalition ESS < 30%HIGH2022-08-12

Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application a...

CVEs:CVE-2022-2390

Affected products

ProductStatusVendorPackageEcosystem
google_play_services_software_development_kit affected google
Upstream advisory

CVE-2022-2390

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

Google Play Services SDK leads to apps having incorrectly set mutability flag

CVEs:CVE-2022-2390

Affected products

ProductStatusVendorPackageEcosystem
com.google.android.gms:play-services-basement affected Maven com.google.android.gms:play-services-basement
Upstream advisory

CVE-2022-20250

Open SourceCoalition ESS < 30%HIGH2022-08-11

In Messaging, there is a possible way to attach files to a message without proper access checks due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is neede...

CVEs:CVE-2022-20250

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20382

Open SourceCoalition ESS < 30%HIGH2022-08-02

In (TBD) of (TBD), there is a possible out of bounds write due to kernel stack overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...

CVEs:CVE-2022-20382

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20354

Open SourceCoalition ESS < 30%HIGH2022-08-02

In onDefaultNetworkChanged of Vpn.java, there is a possible way to disable VPN due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2022-20354

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-214245176

GoogleCoalition ESS < 30%HIGH2022-08-01

PUB-A-214245176

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20319

Open SourceCoalition ESS < 30%HIGH2022-08-12

In DreamServices, there is a possible way to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2022-20319

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20325

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Media, there is a possible code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13A...

CVEs:CVE-2022-20325

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33721

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege.

CVEs:CVE-2022-33721

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20258

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Bluetooth, there is a possible way to bypass compiler exploit mitigations due to a configuration error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20258

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20268

Open SourceCoalition ESS < 30%HIGH2022-08-12

In RestrictionsManager, there is a possible way to send a broadcast that should be restricted to system apps due to a permissions bypass. This could lead to local escalation of privilege on an enterprise managed device with no additional execution priv...

CVEs:CVE-2022-20268

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20248

Open SourceCoalition ESS < 30%HIGH2022-08-11

In Settings, there is a possible way to connect to an open network bypassing DISALLOW_CONFIG_WIFI restriction due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2022-20248

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20314

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In KeyChain, there is a possible spoof keychain chooser activity request due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2022-20314

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20306

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Camera Provider HAL, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2022-20306

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20266

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to improper input validation. This could lead to local escalation of privilege with no additional execution pri...

CVEs:CVE-2022-20266

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20367

Open SourceCoalition ESS < 30%HIGH2022-08-02

In construct_transaction of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2022-20367

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20379

Open SourceCoalition ESS < 30%HIGH2022-08-02

In lwis_buffer_alloc of lwis_buffer.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2022-20379

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20383

Open SourceCoalition ESS < 30%HIGH2022-08-02

In AllocateInternalBuffers of g3aa_buffer_allocator.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2022-20383

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-209436980

GoogleCoalition ESS < 30%HIGH2022-08-01

PUB-A-209436980

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-222408847

GoogleCoalition ESS < 30%HIGH2022-08-01

PUB-A-222408847

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-225877459

GoogleCoalition ESS < 30%HIGH2022-08-01

PUB-A-225877459

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20260

Open SourceCoalition ESS < 30%HIGH2022-08-12

In the Phone app, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2022-20260

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20324

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User ...

CVEs:CVE-2022-20324

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20285

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...

CVEs:CVE-2022-20285

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20318

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed...

CVEs:CVE-2022-20318

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20320

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....

CVEs:CVE-2022-20320

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20327

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitati...

CVEs:CVE-2022-20327

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33715

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of One UI.

CVEs:CVE-2022-33715

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26427

Open SourceCoalition ESS < 30%HIGH2022-08-01

In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085540; Iss...

CVEs:CVE-2022-26427

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21792

Open SourceCoalition ESS < 30%HIGH2022-08-01

In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085410; Iss...

CVEs:CVE-2022-21792

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26426

Open SourceCoalition ESS < 30%HIGH2022-08-01

In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085486; Iss...

CVEs:CVE-2022-26426

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20270

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Content, there is a possible way to learn gmail account name on the device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2022-20270

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20290

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Midi, there is a possible way to learn about private midi devices due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2022-20290

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20339

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Android, there is a possible access of network neighbor table information due to an insecure SEpolicy configuration. This could lead to local information disclosure of network topography with no additional execution privileges needed. User interacti...

CVEs:CVE-2022-20339

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20342

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2022-20342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20316

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed....

CVEs:CVE-2022-20316

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20332

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...

CVEs:CVE-2022-20332

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20293

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In LauncherApps, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. Us...

CVEs:CVE-2022-20293

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20304

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Content, there is a possible way to determinate the user's account due to side channel information disclosure. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2022-20304

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20307

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...

CVEs:CVE-2022-20307

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20309

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed...

CVEs:CVE-2022-20309

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20272

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is needed for exploit...

CVEs:CVE-2022-20272

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20275

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...

CVEs:CVE-2022-20275

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20276

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...

CVEs:CVE-2022-20276

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20277

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...

CVEs:CVE-2022-20277

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20278

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2022-20278

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20279

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee...

CVEs:CVE-2022-20279

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20287

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges...

CVEs:CVE-2022-20287

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20288

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges...

CVEs:CVE-2022-20288

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20289

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed...

CVEs:CVE-2022-20289

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20291

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In AppOpsService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...

CVEs:CVE-2022-20291

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20252

Open SourceCoalition ESS < 30%MEDIUM2022-08-11

In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. ...

CVEs:CVE-2022-20252

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20350

Open SourceCoalition ESS < 30%MEDIUM2022-08-02

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution ...

CVEs:CVE-2022-20350

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20353

Open SourceCoalition ESS < 30%MEDIUM2022-08-02

In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2022-20353

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26430

Open SourceCoalition ESS < 30%HIGH2022-08-01

In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032521; Issue ID: ALPS...

CVEs:CVE-2022-26430

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-26431

Open SourceCoalition ESS < 30%HIGH2022-08-01

In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032553; Issue ...

CVEs:CVE-2022-26431

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-26432

Open SourceCoalition ESS < 30%HIGH2022-08-01

In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032542; Issue ...

CVEs:CVE-2022-26432

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-26433

Open SourceCoalition ESS < 30%HIGH2022-08-01

In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138400; Issue ID: ALPS...

CVEs:CVE-2022-26433

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-26434

Open SourceCoalition ESS < 30%HIGH2022-08-01

In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138450; Issue ...

CVEs:CVE-2022-26434

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-26435

Open SourceCoalition ESS < 30%HIGH2022-08-01

In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138435; Issue ID: ALPS...

CVEs:CVE-2022-26435

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-21788

Open SourceCoalition ESS < 30%MEDIUM2022-08-01

In scp, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06988728; Issue ID:...

CVEs:CVE-2022-21788

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21790

Open SourceCoalition ESS < 30%MEDIUM2022-08-01

In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479306; Issue...

CVEs:CVE-2022-21790

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21791

Open SourceCoalition ESS < 30%MEDIUM2022-08-01

In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478059; Issue...

CVEs:CVE-2022-21791

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20340

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction i...

CVEs:CVE-2022-20340

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20329

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2022-20329

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20281

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2022-20281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20261

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In LocationManager, there is a possible way to get location information due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:...

CVEs:CVE-2022-20261

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26436

Open SourceCoalition ESS < 30%MEDIUM2022-08-01

In emi mpu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07023666; Issue ID...

CVEs:CVE-2022-26436

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20322

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2022-20322

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20323

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2022-20323

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20257

Open SourceCoalition ESS < 30%LOW2022-08-12

In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2022-20257

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20349

Open SourceCoalition ESS < 30%HIGH2022-08-02

In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges need...

CVEs:CVE-2022-20349

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20328

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2022-20328

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20274

Open SourceCoalition ESS < 30%HIGH2022-08-12

In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...

CVEs:CVE-2022-20274

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0734

Open SourceCoalition ESS < 30%MEDIUM2022-08-11

In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side channel information disclosure. This could lead to local information disclosure of an installed package, without proper query permissio...

CVEs:CVE-2021-0734

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0975

Open SourceCoalition ESS < 30%MEDIUM2022-08-11

In USB Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure of installed packages with no additional execution ...

CVEs:CVE-2021-0975

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20242

Open SourceCoalition ESS < 30%MEDIUM2022-08-11

In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User ...

CVEs:CVE-2022-20242

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20341

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information disclosure of tethering interfaces with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2022-20341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20312

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check. This could lead to local information disclosure without additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2022-20312

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20326

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2022-20326

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20294

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Content, there is a possible way to learn about an account present on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2022-20294

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20295

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2022-20295

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20296

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2022-20296

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20298

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2022-20298

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20299

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ContentService, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2022-20299

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20300

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Content, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2022-20300

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20301

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2022-20301

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20303

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User intera...

CVEs:CVE-2022-20303

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20284

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of phone accounts with User execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2022-20284

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20259

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2022-20259

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20263

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2022-20263

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20249

Open SourceCoalition ESS < 30%MEDIUM2022-08-11

In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...

CVEs:CVE-2022-20249

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20251

Open SourceCoalition ESS < 30%MEDIUM2022-08-11

In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U...

CVEs:CVE-2022-20251

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20241

Open SourceCoalition ESS < 30%MEDIUM2022-08-11

In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2022-20241

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33716

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitialized memory.

CVEs:CVE-2022-33716

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33717

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

A missing input validation before memory read in SEM TA prior to SMR Aug-2022 Release 1 allows local attackers to read out of bound memory.

CVEs:CVE-2022-33717

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20352

Open SourceCoalition ESS < 30%MEDIUM2022-08-02

In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a missing permission check. This could lead to local information disclosure with no additional execution p...

CVEs:CVE-2022-20352

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26429

Open SourceCoalition ESS < 30%HIGH2022-08-01

In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2022-26429

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20315

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ActivityManager, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20315

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20336

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to local information disclosure of applications allow-listed to use the network during VPN lockdown mode with no additional execution p...

CVEs:CVE-2022-20336

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20305

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ContentService, there is a possible disclosure of available account types due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2022-20305

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20310

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2022-20310

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20311

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2022-20311

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20262

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2022-20262

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33729

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVEs:CVE-2022-33729

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20344

Open SourceCoalition ESS < 30%HIGH2022-08-02

In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2022-20344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20246

Open SourceCoalition ESS < 30%HIGH2022-08-11

In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User...

CVEs:CVE-2022-20246

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20255

Open SourceCoalition ESS < 30%MEDIUM2022-08-12

In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2022-20255

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33728

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via Settings.Gloabal.

CVEs:CVE-2022-33728

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20335

Open SourceCoalition ESS < 30%LOW2022-08-12

In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been disabled due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...

CVEs:CVE-2022-20335

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20267

Open SourceCoalition ESS < 30%LOW2022-08-12

In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...

CVEs:CVE-2022-20267

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33714

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.

CVEs:CVE-2022-33714

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33722

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.

CVEs:CVE-2022-33722

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0735

Open SourceCoalition ESS < 30%MEDIUM2022-08-11

In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced in Android 11 due to a missing permission check. This could lead to local information disclosure with no additional execution privile...

CVEs:CVE-2021-0735

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33731

Open SourceCoalition ESS < 30%HIGH2022-08-05

Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

CVEs:CVE-2022-33731

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33726

Open SourceCoalition ESS < 30%LOW2022-08-05

Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.

CVEs:CVE-2022-33726

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33718

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.

CVEs:CVE-2022-33718

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33732

Open SourceCoalition ESS < 30%HIGH2022-08-05

Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.

CVEs:CVE-2022-33732

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20376

Open SourceCoalition ESS < 30%HIGH2022-08-02

In trusty_log_seq_start of trusty-log.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2022-20376

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-231271467

GoogleCoalition ESS < 30%HIGH2022-08-01

ASB-A-231271467

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-216130110

GoogleCoalition ESS < 30%HIGH2022-08-01

PUB-A-216130110

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20256

Open SourceCoalition ESS < 30%HIGH2022-08-12

In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro...

CVEs:CVE-2022-20256

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26428

Open SourceCoalition ESS < 30%HIGH2022-08-01

In video codec, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06521260; Issue ID: ...

CVEs:CVE-2022-26428

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20243

Open SourceCoalition ESS < 30%MEDIUM2022-08-11

In Core Utilities, there is a possible log information disclosure. This could lead to local information disclosure of sensitive browsing data with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...

CVEs:CVE-2022-20243

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-33724

Open SourceCoalition ESS < 30%MEDIUM2022-08-05

Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log.

CVEs:CVE-2022-33724

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.