Google Security Advisories · October 2022 — Google Security Advisories
340 advisories 208 CVEs 13 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2022-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 13 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

SUSE-SU-2022:3706-1

GoogleExploitedCISA KEV listedCRITICAL2022-10-24

Security update for google-gson

Affected products

ProductStatusVendorPackageEcosystem
google-gson affected SUSE:Manager Server Module 4.1 google-gson
Upstream advisory

openSUSE-SU-2022:10180-1

Open SourceExploitedCISA KEV listedCRITICAL2022-10-31

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

openSUSE-SU-2022:10177-1

Open SourceExploitedCISA KEV listedCRITICAL2022-10-31

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

DSA-5263-1

Open SourceExploitedCISA KEV listed2022-10-29

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-3723

Project ZeroExploitedCISA KEV listed2022-10-28

Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3723

Upstream advisory

CVE-2022-3723

GoogleExploitedCISA KEV listedHIGH2022-10-28

Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3723

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-41033

GoogleExploitedCISA KEV listedCRITICAL2022-10-11

Windows COM+ Event System Service Elevation of Privilege Vulnerability

CVEs:CVE-2022-41033

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_10_21h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

CVE-2022-42827

GoogleExploitedCISA KEV listedCRITICAL2022-10-24

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a repo...

CVEs:CVE-2022-42827

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2022-42827

Project ZeroExploitedCISA KEV listed2022-10-24

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CVEs:CVE-2022-42827

Upstream advisory

ASB-A-230867044

GoogleActive exploitation (sightings)HIGH2022-10-01

ASB-A-230867044

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DEBIAN-CVE-2022-39237

Open SourceActive exploitation (sightings)CRITICAL2022-10-06

DEBIAN-CVE-2022-39237

Affected products

ProductStatusVendorPackageEcosystem
golang-github-sylabs-sif affected Debian:11 golang-github-sylabs-sif
golang-github-sylabs-sif affected Debian:12 golang-github-sylabs-sif
golang-github-sylabs-sif affected Debian:13 golang-github-sylabs-sif
golang-github-sylabs-sif affected Debian:14 golang-github-sylabs-sif
Upstream advisory

CVE-2022-20397

Open SourceActive exploitation (sightings)HIGH2022-10-03

In SitRilClient_OnResponse of SitRilSe.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2022-20397

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-223086933

GoogleActive exploitation (sightings)HIGH2022-10-01

PUB-A-223086933

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20464

Open SourceActive exploitation (sightings)MEDIUM2022-10-03

In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not n...

CVEs:CVE-2022-20464

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-236042696

GoogleActive exploitation (sightings)MEDIUM2022-10-01

PUB-A-236042696

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

SUSE-SU-2022:3747-1

Open SourcePoC exploitCRITICAL2022-10-26

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Client Tools 12 golang-github-lusitaniae-apache_exporter
golang-github-prometheus-alertmanager affected SUSE:Manager Client Tools 12 golang-github-prometheus-alertmanager
golang-github-prometheus-node_exporter affected SUSE:Manager Client Tools 12 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:OpenStack Cloud 9 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:OpenStack Cloud Crowbar 9 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 12 SP4 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP3-BCL golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP4-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP5 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 12 SP5 golang-github-prometheus-node_exporter
grafana affected SUSE:Manager Client Tools 12 grafana
kiwi-desc-saltboot affected SUSE:Manager Client Tools 12 kiwi-desc-saltboot
mgr-daemon affected SUSE:Manager Client Tools 12 mgr-daemon
spacecmd affected SUSE:Manager Client Tools 12 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 12 spacewalk-client-tools
uyuni-common-libs affected SUSE:Manager Client Tools 12 uyuni-common-libs
Upstream advisory

DSA-5261-1

Open SourcePoC exploit2022-10-26

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

SUSE-SU-2022:3745-1

Open SourcePoC exploit2022-10-26

Security update for golang-github-prometheus-node_exporter

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Module for Basesystem 15 SP3 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Module for Basesystem 15 SP4 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP1-BCL golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP1-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP2-BCL golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP2-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Proxy 4.1 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Retail Branch Server 4.1 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Server 4.1 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Enterprise Storage 6 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Enterprise Storage 7 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected openSUSE:Leap 15.4 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected openSUSE:Leap 15.3 golang-github-prometheus-node_exporter
Upstream advisory

MGASA-2022-0356

Open SourcePoC exploitHIGH2022-10-05

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

AZL-38185

Open SourcePoC exploitCRITICAL2022-10-29

CVE-2022-42915 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

SUSE-SU-2022:1040-3

Open SourcePoC exploit2022-10-06

Security update for protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected SUSE:Manager Server Module 4.3 protobuf
protobuf affected SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS protobuf
protobuf affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS protobuf
protobuf affected SUSE:Linux Enterprise Server 15 SP2-BCL protobuf
protobuf affected SUSE:Linux Enterprise Server 15 SP2-LTSS protobuf
protobuf affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 protobuf
protobuf affected SUSE:Manager Proxy 4.1 protobuf
protobuf affected SUSE:Manager Retail Branch Server 4.1 protobuf
protobuf affected SUSE:Manager Server 4.1 protobuf
protobuf affected SUSE:Enterprise Storage 7 protobuf
Upstream advisory

OESA-2022-1979

Open SourcePoC exploit2022-10-14

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:20.03-LTS-SP1 kubernetes
kubernetes affected openEuler:20.03-LTS-SP3 kubernetes
kubernetes affected openEuler:22.03-LTS kubernetes
Upstream advisory

CVE-2022-3656

GooglePoC exploitHIGH2022-10-25

Insufficient data validation in File System in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-3656

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

AZL-38722

Open SourcePoC exploitHIGH2022-10-29

CVE-2022-42916 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

OESA-2022-2004

Open SourcePoC exploitCRITICAL2022-10-21

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP3 golang
golang affected openEuler:22.03-LTS golang
Upstream advisory

MGASA-2022-0377

Open SourcePoC exploit2022-10-18

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

AZL-11128

Open SourcePoC exploitCRITICAL2022-10-14

CVE-2022-2879 affecting package golang for versions less than 1.19.10-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37526

Open SourcePoC exploitCRITICAL2022-10-14

CVE-2022-2879 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79006

Open SourcePoC exploitCRITICAL2022-10-14

CVE-2022-2879 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-2879

Open SourcePoC exploitCRITICAL2022-10-14

DEBIAN-CVE-2022-2879

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-2879

GooglePoC exploitCRITICAL2022-10-06

Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum s...

CVEs:CVE-2022-2879

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2022-1037

Open SourcePoC exploitCRITICAL2022-10-06

Unbounded memory consumption when reading headers in archive/tar

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

GHSA-69ch-w2m2-3vjp

Open SourcePoC exploitCRITICAL2022-10-14

golang.org/x/text/language Denial of service via crafted Accept-Language header

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
gitleaks affected chainguard gitleaks
gitleaks affected wolfi gitleaks
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
hey affected wolfi hey
hey affected chainguard hey
k3d affected chainguard k3d
k3d affected wolfi k3d
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
php-fpm_exporter affected wolfi php-fpm_exporter
php-fpm_exporter affected chainguard php-fpm_exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
vt-cli affected wolfi vt-cli
vt-cli affected chainguard vt-cli
x/text affected golang.org golang.org/x/text
x/text affected golang.org
Upstream advisory

GHSA-69ch-w2m2-3vjp

Open SourcePoC exploitCRITICAL2022-10-14

golang.org/x/text/language Denial of service via crafted Accept-Language header

Affected products

ProductStatusVendorPackageEcosystem
x/text affected golang.org golang.org/x/text
Upstream advisory

AZL-33565

Open SourcePoC exploitHIGH2022-10-14

CVE-2022-32149 affecting package application-gateway-kubernetes-ingress for versions less than 1.4.0-22

Affected products

ProductStatusVendorPackageEcosystem
application-gateway-kubernetes-ingress affected Azure Linux:2 application-gateway-kubernetes-ingress
Upstream advisory

DEBIAN-CVE-2022-32149

Open SourcePoC exploitHIGH2022-10-14

DEBIAN-CVE-2022-32149

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-text affected Debian:12 golang-golang-x-text
golang-golang-x-text affected Debian:13 golang-golang-x-text
golang-golang-x-text affected Debian:11 golang-golang-x-text
golang-golang-x-text affected Debian:14 golang-golang-x-text
Upstream advisory

CVE-2022-32149

Open SourcePoC exploitHIGH2022-10-14

golang.org/x/text/language Denial of service via crafted Accept-Language header

CVEs:CVE-2022-32149

Affected products

ProductStatusVendorPackageEcosystem
x/text affected golang.org golang.org/x/text
Upstream advisory

CVE-2022-32149

GooglePoC exploitHIGH2022-10-11

An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.

CVEs:CVE-2022-32149

Affected products

ProductStatusVendorPackageEcosystem
text affected golang
Upstream advisory

GO-2022-1059

Open SourcePoC exploitHIGH2022-10-11

Denial of service via crafted Accept-Language header in golang.org/x/text/language

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
gitleaks affected wolfi gitleaks
gitleaks affected chainguard gitleaks
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
hey affected chainguard hey
hey affected wolfi hey
k3d affected chainguard k3d
k3d affected wolfi k3d
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
php-fpm_exporter affected chainguard php-fpm_exporter
php-fpm_exporter affected wolfi php-fpm_exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
vt-cli affected chainguard vt-cli
vt-cli affected wolfi vt-cli
x/text affected golang.org golang.org/x/text
Upstream advisory

OESA-2022-2010

Open SourcePoC exploitHIGH2022-10-21

protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected openEuler:20.03-LTS-SP1 protobuf
Upstream advisory

OESA-2022-2011

Open SourcePoC exploitHIGH2022-10-21

protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected openEuler:20.03-LTS-SP3 protobuf
Upstream advisory

OESA-2022-2012

Open SourcePoC exploitHIGH2022-10-21

protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected openEuler:22.03-LTS protobuf
Upstream advisory

AZL-11130

Open SourcePoC exploitCRITICAL2022-10-14

CVE-2022-41715 affecting package golang for versions less than 1.19.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37407

Open SourcePoC exploitCRITICAL2022-10-14

CVE-2022-41715 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-78964

Open SourcePoC exploitCRITICAL2022-10-14

CVE-2022-41715 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-41715

Open SourcePoC exploitCRITICAL2022-10-14

DEBIAN-CVE-2022-41715

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-41715

GooglePoC exploitCRITICAL2022-10-06

Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as ...

CVEs:CVE-2022-41715

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2022-1039

Open SourcePoC exploitCRITICAL2022-10-06

Memory exhaustion when compiling regular expressions in regexp/syntax

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

AZL-11129

Open SourcePoC exploitHIGH2022-10-14

CVE-2022-2880 affecting package golang for versions less than 1.19.10-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37469

Open SourcePoC exploitHIGH2022-10-14

CVE-2022-2880 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79010

Open SourcePoC exploitHIGH2022-10-14

CVE-2022-2880 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-2880

Open SourcePoC exploitHIGH2022-10-14

DEBIAN-CVE-2022-2880

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-2880

GooglePoC exploitHIGH2022-10-06

Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable valu...

CVEs:CVE-2022-2880

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2022-1038

Open SourcePoC exploitHIGH2022-10-06

Incorrect sanitization of forwarded query parameters in net/http/httputil

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

openSUSE-SU-2022:10139-1

Open SourcePoC exploitCRITICAL2022-10-03

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

openSUSE-SU-2022:10138-1

Open SourcePoC exploitCRITICAL2022-10-03

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

CVE-2022-3653

GooglePoC exploitCRITICAL2022-10-25

Heap buffer overflow in Vulkan in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3653

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MGASA-2022-0357

Open SourcePoC exploitCRITICAL2022-10-05

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

CVE-2022-20421

Open SourcePoC exploitHIGH2022-10-03

In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20421

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

ASB-A-239630375

GooglePoC exploitHIGH2022-10-01

ASB-A-239630375

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20409

Open SourcePoC exploitHIGH2022-10-03

In io_identity_cow of io_uring.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2022-20409

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-238177383

GooglePoC exploitHIGH2022-10-01

ASB-A-238177383

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20413

Open SourcePoC exploitMEDIUM2022-10-03

In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2022-20413

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-228095839

GooglePoC exploit2022-10-01

PUB-A-228095839

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-20422

Open SourcePoC exploitHIGH2022-10-03

In emulation_proc_handler of armv8_deprecated.c, there is a possible way to corrupt memory due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2022-20422

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

ASB-A-237540956

GooglePoC exploitNONE2022-10-01

ASB-A-237540956

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-238108281

GooglePoC exploit2022-10-01

ASB-A-238108281

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-3652

GoogleCoalition ESS 30-63%HIGH2022-10-25

Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3652

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

SUSE-SU-2022:3751-1

Open SourceEPSS 49-79%CRITICAL2022-10-26

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
dracut-saltboot affected openSUSE:Leap 15.3 dracut-saltboot
dracut-saltboot affected SUSE:Manager Client Tools 15 dracut-saltboot
dracut-saltboot affected openSUSE:Leap 15.4 dracut-saltboot
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Server Module 4.3 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Client Tools 15 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Proxy Module 4.2 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Proxy Module 4.3 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Server Module 4.2 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected openSUSE:Leap 15.3 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected openSUSE:Leap 15.4 golang-github-lusitaniae-apache_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15-ESPOS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 15 golang-github-prometheus-node_exporter
grafana affected SUSE:Manager Client Tools 15 grafana
mgr-daemon affected SUSE:Manager Client Tools 15 mgr-daemon
spacecmd affected openSUSE:Leap 15.4 spacecmd
spacecmd affected openSUSE:Leap 15.3 spacecmd
spacecmd affected SUSE:Manager Client Tools 15 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 15 spacewalk-client-tools
uyuni-common-libs affected SUSE:Manager Client Tools 15 uyuni-common-libs
Upstream advisory

CVE-2022-3654

GoogleCoalition ESS < 30%CRITICAL2022-10-25

Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3654

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-37968

Open SourceCoalition ESS < 30%CRITICAL2022-10-11

Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over...

CVEs:CVE-2022-37968

Affected products

ProductStatusVendorPackageEcosystem
azure_arc-enabled_kubernetes affected microsoft
azure_stack_edge affected microsoft
Upstream advisory

GHSA-c6w8-7mp3-34j9

Open SourceCoalition ESS < 30%HIGH2022-10-18

.NET Remote Code Execution Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

GHSA-c6w8-7mp3-34j9

Open SourceCoalition ESS < 30%HIGH2022-10-18

.NET Remote Code Execution Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.linux-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.ios-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.iossimulator-x86
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.maccatalyst-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvos-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.osx-x64.Cross.tvossimulator-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.AOT.win-x64.Cross.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet
Microsoft.NETCore.App.Runtime.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-arm
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-arm64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-arm64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-musl-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.linux-x64
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.android-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.browser-wasm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.ios-arm.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.iossimulator-x86.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-musl-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.AOT.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-arm64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.linux-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.LLVM.osx-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.maccatalyst-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-arm64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.osx-x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvos-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.arm64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x64
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.tvossimulator-x64.Msi.x86
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x64
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.Mono.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.Mono.win-x86
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-arm64 affected NuGet Microsoft.NETCore.App.Runtime.osx-arm64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.osx-x64 affected NuGet Microsoft.NETCore.App.Runtime.osx-x64
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm affected NuGet Microsoft.NETCore.App.Runtime.win-arm
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-arm64 affected NuGet Microsoft.NETCore.App.Runtime.win-arm64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x64 affected NuGet Microsoft.NETCore.App.Runtime.win-x64
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Microsoft.NETCore.App.Runtime.win-x86 affected NuGet Microsoft.NETCore.App.Runtime.win-x86
Upstream advisory

CVE-2022-41035

Open SourceCoalition ESS < 30%MEDIUM2022-10-04

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2022-41035

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-39278

Open SourceCoalition ESS < 30%CRITICAL2022-10-13

Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions 1.15.2, 1.14.5, and 1.13.9, the Istio control plane, istiod, is vulnerable to a request processing erro...

CVEs:CVE-2022-39278

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

DEBIAN-CVE-2022-3171

Open SourceCoalition ESS < 30%HIGH2022-10-12

DEBIAN-CVE-2022-3171

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Debian:11 protobuf
protobuf affected Debian:12 protobuf
protobuf affected Debian:13 protobuf
protobuf affected Debian:14 protobuf
Upstream advisory

GHSA-h4h5-3hr4-j3g2

Open SourceCoalition ESS < 30%HIGH2022-10-04

protobuf-java has a potential Denial of Service issue

Affected products

ProductStatusVendorPackageEcosystem
com.google.protobuf:protobuf-java affected Maven com.google.protobuf:protobuf-java
com.google.protobuf:protobuf-javalite affected Maven com.google.protobuf:protobuf-javalite
com.google.protobuf:protobuf-kotlin affected Maven com.google.protobuf:protobuf-kotlin
com.google.protobuf:protobuf-kotlin-lite affected Maven com.google.protobuf:protobuf-kotlin-lite
google-protobuf affected RubyGems google-protobuf
Upstream advisory

GHSA-h4h5-3hr4-j3g2

Open SourceCoalition ESS < 30%HIGH2022-10-04

protobuf-java has a potential Denial of Service issue

Affected products

ProductStatusVendorPackageEcosystem
celeborn-0.5 affected chainguard celeborn-0.5
celeborn-0.5 affected wolfi celeborn-0.5
celeborn-0.6 affected chainguard celeborn-0.6
celeborn-0.6 affected wolfi celeborn-0.6
com.google.protobuf:protobuf-java affected Maven com.google.protobuf:protobuf-java
com.google.protobuf:protobuf-javalite affected Maven com.google.protobuf:protobuf-javalite
com.google.protobuf:protobuf-kotlin affected Maven com.google.protobuf:protobuf-kotlin
com.google.protobuf:protobuf-kotlin-lite affected Maven com.google.protobuf:protobuf-kotlin-lite
dotty affected chainguard dotty
dotty affected wolfi dotty
druid affected wolfi druid
druid affected chainguard druid
emsdk affected chainguard emsdk
google-protobuf affected RubyGems google-protobuf
hadoop-client-modules affected chainguard hadoop-client-modules
spark-3.5.0-compat affected chainguard spark-3.5.0-compat
trino affected wolfi trino
trino affected chainguard trino
Upstream advisory

CVE-2022-3171

Open SourceCoalition ESS < 30%MEDIUM2022-10-04

protobuf-java has a potential Denial of Service issue

CVEs:CVE-2022-3171

Affected products

ProductStatusVendorPackageEcosystem
com.google.protobuf:protobuf-java affected Maven com.google.protobuf:protobuf-java
com.google.protobuf:protobuf-javalite affected Maven com.google.protobuf:protobuf-javalite
com.google.protobuf:protobuf-kotlin affected Maven com.google.protobuf:protobuf-kotlin
com.google.protobuf:protobuf-kotlin-lite affected Maven com.google.protobuf:protobuf-kotlin-lite
google-protobuf affected RubyGems google-protobuf
Upstream advisory

CVE-2022-3171

Open SourceCoalition ESS < 30%HIGH2022-10-04

A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown ...

CVEs:CVE-2022-3171

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
google-protobuf affected google
protobuf-java affected google
protobuf-javalite affected google
protobuf-kotlin affected google
protobuf-kotlin-lite affected google
Upstream advisory

CVE-2022-3095

Open SourceCoalition ESS < 30%CRITICAL2022-10-27

The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC 3986 syntax, which creates incompatibilities with the '\' characters in...

CVEs:CVE-2022-3095

Affected products

ProductStatusVendorPackageEcosystem
dart_software_development_kit affected dart
flutter affected flutter
Upstream advisory

CVE-2022-3370

GoogleCoalition ESS < 30%CRITICAL2022-10-03

Use after free in Custom Elements in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3370

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3373

GoogleCoalition ESS < 30%CRITICAL2022-10-03

Out of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3373

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DSA-5245-1

Open SourceCoalition ESS < 30%2022-10-02

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

MGASA-2022-0376

Open SourceCoalition ESS < 30%CRITICAL2022-10-18

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

openSUSE-SU-2022:10151-1

Open SourceCoalition ESS < 30%CRITICAL2022-10-17

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
Upstream advisory

openSUSE-SU-2022:10146-1

Open SourceCoalition ESS < 30%CRITICAL2022-10-13

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5253-1

Open SourceCoalition ESS < 30%2022-10-13

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-3446

GoogleCoalition ESS < 30%CRITICAL2022-10-12

Heap buffer overflow in WebSQL in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3446

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3445

GoogleCoalition ESS < 30%CRITICAL2022-10-12

Use after free in Skia in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3445

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-9jjw-hf72-3mxw

Open SourceCoalition ESS < 30%CRITICAL2022-10-07

TensorFlow vulnerable to heap out of bounds read in filesystem glob matching

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-9jjw-hf72-3mxw

Open SourceCoalition ESS < 30%CRITICAL2022-10-07

TensorFlow vulnerable to heap out of bounds read in filesystem glob matching

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-3448

GoogleCoalition ESS < 30%CRITICAL2022-10-12

Use after free in Permissions API in Google Chrome prior to 106.0.5249.119 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3448

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-20410

Open SourceCoalition ESS < 30%HIGH2022-10-03

In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2022-20410

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32589

Open SourceCoalition ESS < 30%HIGH2022-10-07

In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP...

CVEs:CVE-2022-32589

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2022-32591

Open SourceCoalition ESS < 30%HIGH2022-10-07

In ril, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07257259; Issue ID: AL...

CVEs:CVE-2022-32591

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-3447

GoogleCoalition ESS < 30%MEDIUM2022-10-12

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3447

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3450

GoogleCoalition ESS < 30%CRITICAL2022-10-12

Use after free in Peer Connection in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3450

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3659

GoogleCoalition ESS < 30%CRITICAL2022-10-25

Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium sec...

CVEs:CVE-2022-3659

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-40764

Open SourceCoalition ESS < 30%CRITICAL2022-10-03

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original d...

CVEs:CVE-2022-40764

Affected products

ProductStatusVendorPackageEcosystem
cli affected snyk
golang_cli affected snyk
Upstream advisory

CVE-2022-40764

GoogleCoalition ESS < 30%HIGH2022-10-03

Snyk CLI affected by Command Injection vulnerability

CVEs:CVE-2022-40764

Affected products

ProductStatusVendorPackageEcosystem
snyk affected npm snyk
snyk-go-plugin affected npm snyk-go-plugin
Upstream advisory

CVE-2022-40764

GoogleCoalition ESS < 30%HIGH2022-10-03

Snyk CLI affected by Command Injection vulnerability

CVEs:CVE-2022-40764

Affected products

ProductStatusVendorPackageEcosystem
snyk affected npm snyk
snyk-go-plugin affected npm snyk-go-plugin
Upstream advisory

CVE-2022-3660

GoogleCoalition ESS < 30%MEDIUM2022-10-25

Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 107.0.5304.62 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-3660

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3661

GoogleCoalition ESS < 30%MEDIUM2022-10-25

Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.62 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)

CVEs:CVE-2022-3661

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3658

GoogleCoalition ESS < 30%CRITICAL2022-10-25

Use after free in Feedback service on Chrome OS in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium...

CVEs:CVE-2022-3658

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-20418

Open SourceCoalition ESS < 30%HIGH2022-10-03

In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2022-20418

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-3655

GoogleCoalition ESS < 30%CRITICAL2022-10-25

Heap buffer overflow in Media Galleries in Google Chrome prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-3655

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3449

GoogleCoalition ESS < 30%CRITICAL2022-10-12

Use after free in Safe Browsing in Google Chrome prior to 106.0.5249.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

CVEs:CVE-2022-3449

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3657

GoogleCoalition ESS < 30%CRITICAL2022-10-25

Use after free in Extensions in Google Chrome prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

CVEs:CVE-2022-3657

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

AZL-11350

Open SourceCoalition ESS < 30%MEDIUM2022-10-26

CVE-2022-3474 affecting package bazel for versions less than 5.3.2-1

Affected products

ProductStatusVendorPackageEcosystem
bazel affected Azure Linux:2 bazel
Upstream advisory

CVE-2022-3474

Open SourceCoalition ESS < 30%MEDIUM2022-10-26

A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4....

CVEs:CVE-2022-3474

Affected products

ProductStatusVendorPackageEcosystem
bazel affected google
Upstream advisory

CVE-2022-20423

Open SourceCoalition ESS < 30%HIGH2022-10-03

In rndis_set_response of rndis.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious USB device is attached with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20423

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-239842288

GoogleCoalition ESS < 30%HIGH2022-10-01

ASB-A-239842288

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-39117

Open SourceCoalition ESS < 30%HIGH2022-10-14

In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-39117

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38689

Open SourceCoalition ESS < 30%HIGH2022-10-14

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-38689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20429

Open SourceCoalition ESS < 30%HIGH2022-10-11

In CarSettings of app packages, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2022-20429

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20437

Open SourceCoalition ESS < 30%MEDIUM2022-10-03

In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242258929

CVEs:CVE-2022-20437

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-242258929

GoogleCoalition ESS < 30%2022-10-01

ASB-A-242258929

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-242259918

GoogleCoalition ESS < 30%2022-10-01

ASB-A-242259918

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-242259920

GoogleCoalition ESS < 30%2022-10-01

ASB-A-242259920

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-242266172

GoogleCoalition ESS < 30%2022-10-01

ASB-A-242266172

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20432

Open SourceCoalition ESS < 30%CRITICAL2022-10-03

There is an missing authorization issue in the system service. Since the component does not have permission check and permission protection,, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221899

CVEs:CVE-2022-20432

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20433

Open SourceCoalition ESS < 30%CRITICAL2022-10-03

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221901

CVEs:CVE-2022-20433

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20434

Open SourceCoalition ESS < 30%CRITICAL2022-10-03

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242244028

CVEs:CVE-2022-20434

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20435

Open SourceCoalition ESS < 30%HIGH2022-10-03

There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission protection, resulting in EoP problem.Product: AndroidVersions: Android SoCAndroid ID: A-242248367

CVEs:CVE-2022-20435

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20436

Open SourceCoalition ESS < 30%CRITICAL2022-10-03

There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242248369

CVEs:CVE-2022-20436

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-242221233

GoogleCoalition ESS < 30%CRITICAL2022-10-01

ASB-A-242221233

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-242221238

GoogleCoalition ESS < 30%CRITICAL2022-10-01

ASB-A-242221238

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-242221899

GoogleCoalition ESS < 30%CRITICAL2022-10-01

ASB-A-242221899

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-242221901

GoogleCoalition ESS < 30%CRITICAL2022-10-01

ASB-A-242221901

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-242244028

GoogleCoalition ESS < 30%CRITICAL2022-10-01

ASB-A-242244028

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-242248367

GoogleCoalition ESS < 30%2022-10-01

ASB-A-242248367

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-242248369

GoogleCoalition ESS < 30%CRITICAL2022-10-01

ASB-A-242248369

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-38669

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

CVEs:CVE-2022-38669

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38670

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

CVEs:CVE-2022-38670

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-2985

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

CVEs:CVE-2022-2985

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39107

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.

CVEs:CVE-2022-39107

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39108

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

CVEs:CVE-2022-39108

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39109

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

CVEs:CVE-2022-39109

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39110

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

CVEs:CVE-2022-39110

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39111

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

CVEs:CVE-2022-39111

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39080

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

CVEs:CVE-2022-39080

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38688

Open SourceCoalition ESS < 30%HIGH2022-10-14

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-38688

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26472

Open SourceCoalition ESS < 30%HIGH2022-10-03

In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0731909...

CVEs:CVE-2022-26472

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-234037216

GoogleCoalition ESS < 30%HIGH2022-10-01

ASB-A-234037216

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-38687

Open SourceCoalition ESS < 30%HIGH2022-10-14

In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional execution privileges needed.

CVEs:CVE-2022-38687

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39852

Open SourceCoalition ESS < 30%CRITICAL2022-10-07

A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform code execution.

CVEs:CVE-2022-39852

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20416

Open SourceCoalition ESS < 30%HIGH2022-10-03

In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2022-20416

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20412

Open SourceCoalition ESS < 30%MEDIUM2022-10-03

In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2022-20412

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39112

Open SourceCoalition ESS < 30%HIGH2022-10-14

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

CVEs:CVE-2022-39112

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39113

Open SourceCoalition ESS < 30%HIGH2022-10-14

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

CVEs:CVE-2022-39113

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39114

Open SourceCoalition ESS < 30%HIGH2022-10-14

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

CVEs:CVE-2022-39114

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32590

Open SourceCoalition ESS < 30%HIGH2022-10-07

In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07299425; Issue ID: A...

CVEs:CVE-2022-32590

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2022-32593

Open SourceCoalition ESS < 30%HIGH2022-10-07

In vowe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138493; Issue ID:...

CVEs:CVE-2022-32593

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20425

Open SourceCoalition ESS < 30%HIGH2022-10-03

In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2022-20425

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26474

Open SourceCoalition ESS < 30%HIGH2022-10-07

In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: A...

CVEs:CVE-2022-26474

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32592

Open SourceCoalition ESS < 30%HIGH2022-10-07

In cpu dvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07139405; Issue...

CVEs:CVE-2022-32592

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2022-39855

Open SourceCoalition ESS < 30%MEDIUM2022-10-07

Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.

CVEs:CVE-2022-39855

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20351

Open SourceCoalition ESS < 30%HIGH2022-10-03

In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2022-20351

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39128

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39128

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39121

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39121

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39122

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39122

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39123

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39123

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39124

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39124

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39125

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39125

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39126

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39126

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39127

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39127

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39120

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39120

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39105

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39105

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39103

Open SourceCoalition ESS < 30%HIGH2022-10-14

In Gallery service, there is a missing permission check. This could lead to local denial of service in Gallery service with no additional execution privileges needed.

CVEs:CVE-2022-39103

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38671

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-38671

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-2984

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-2984

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-36868

Open SourceCoalition ESS < 30%MEDIUM2022-10-07

Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVEs:CVE-2022-36868

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-238103939

GoogleCoalition ESS < 30%2022-10-01

ASB-A-238103939

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-238108282

GoogleCoalition ESS < 30%2022-10-01

ASB-A-238108282

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-3421

GoogleCoalition ESS < 30%HIGH2022-10-17

An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-root user. When the Drive for Desktop installer is run for the first time, it will place a binary in th...

CVEs:CVE-2022-3421

Affected products

ProductStatusVendorPackageEcosystem
drive affected google
Upstream advisory

PUB-A-228095650

GoogleCoalition ESS < 30%2022-10-01

PUB-A-228095650

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-39115

Open SourceCoalition ESS < 30%HIGH2022-10-14

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

CVEs:CVE-2022-39115

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38679

Open SourceCoalition ESS < 30%HIGH2022-10-14

In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privileges needed.

CVEs:CVE-2022-38679

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39856

Open SourceCoalition ESS < 30%MEDIUM2022-10-07

Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call information.

CVEs:CVE-2022-39856

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39848

Open SourceCoalition ESS < 30%MEDIUM2022-10-07

Exposure of sensitive information in AT_Distributor prior to SMR Oct-2022 Release 1 allows local attacker to access SerialNo via log.

CVEs:CVE-2022-39848

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20438

Open SourceCoalition ESS < 30%MEDIUM2022-10-03

In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242259920

CVEs:CVE-2022-20438

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20439

Open SourceCoalition ESS < 30%MEDIUM2022-10-03

In Messaging, There has unauthorized provider, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242266172

CVEs:CVE-2022-20439

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39853

Open SourceCoalition ESS < 30%CRITICAL2022-10-07

A use after free vulnerability in perf-mgr driver prior to SMR Oct-2022 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2022-39853

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39849

Open SourceCoalition ESS < 30%LOW2022-10-07

Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

CVEs:CVE-2022-39849

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39850

Open SourceCoalition ESS < 30%LOW2022-10-07

Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

CVEs:CVE-2022-39850

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20430

Open SourceCoalition ESS < 30%CRITICAL2022-10-03

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221233

CVEs:CVE-2022-20430

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20431

Open SourceCoalition ESS < 30%CRITICAL2022-10-03

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221238

CVEs:CVE-2022-20431

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20440

Open SourceCoalition ESS < 30%MEDIUM2022-10-03

In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242259918

CVEs:CVE-2022-20440

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-211485702

GoogleCoalition ESS < 30%HIGH2022-10-01

PUB-A-211485702

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-233606615

GoogleCoalition ESS < 30%HIGH2022-10-01

PUB-A-233606615

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-26473

Open SourceCoalition ESS < 30%HIGH2022-10-07

In vdec fmt, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342197; Issue ID: ALPS07...

CVEs:CVE-2022-26473

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39854

Open SourceCoalition ESS < 30%HIGH2022-10-07

Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.

CVEs:CVE-2022-39854

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20419

Open SourceCoalition ESS < 30%HIGH2022-10-03

In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher process due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2022-20419

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39851

Open SourceCoalition ESS < 30%MEDIUM2022-10-07

Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.

CVEs:CVE-2022-39851

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20415

Open SourceCoalition ESS < 30%HIGH2022-10-03

In handleFullScreenIntent of StatusBarNotificationActivityStarter.java, there is a possible bypass of the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with no additi...

CVEs:CVE-2022-20415

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20420

Open SourceCoalition ESS < 30%HIGH2022-10-03

In getBackgroundRestrictionExemptionReason of AppRestrictionController.java, there is a possible way to bypass device policy restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr...

CVEs:CVE-2022-20420

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26471

Open SourceCoalition ESS < 30%HIGH2022-10-03

In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...

CVEs:CVE-2022-26471

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-234037999

GoogleCoalition ESS < 30%HIGH2022-10-01

ASB-A-234037999

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0951

Open SourceCoalition ESS < 30%HIGH2022-10-03

In DevmemIntHeapAcquire of TBD, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2021-0951

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20417

Open SourceCoalition ESS < 30%HIGH2022-10-03

In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2022-20417

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-242345085

GoogleCoalition ESS < 30%HIGH2022-10-01

ASB-A-242345085

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0699

Open SourceCoalition ESS < 30%HIGH2022-10-03

In HTBLogKM of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2021-0699

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-242345178

GoogleCoalition ESS < 30%HIGH2022-10-01

ASB-A-242345178

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20394

Open SourceCoalition ESS < 30%MEDIUM2022-10-03

In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due to a missing permission check. This could lead to local information disclosure with no additional execut...

CVEs:CVE-2022-20394

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38690

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.

CVEs:CVE-2022-38690

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26475

Open SourceCoalition ESS < 30%HIGH2022-10-07

In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310743; Issue ID:...

CVEs:CVE-2022-26475

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2022-38672

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-38672

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38673

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-38673

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38676

Open SourceCoalition ESS < 30%CRITICAL2022-10-14

In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-38676

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38677

Open SourceCoalition ESS < 30%HIGH2022-10-14

In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privileges needed.

CVEs:CVE-2022-38677

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39847

Open SourceCoalition ESS < 30%CRITICAL2022-10-07

Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to perform malicious actions.

CVEs:CVE-2022-39847

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-26452

Open SourceCoalition ESS < 30%HIGH2022-10-07

In isp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07262305; Issue ID: ALPS07262305.

CVEs:CVE-2022-26452

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0696

Open SourceCoalition ESS < 30%HIGH2022-10-03

In dllist_remove_node of TBD, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2021-0696

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-242344778

GoogleCoalition ESS < 30%HIGH2022-10-01

ASB-A-242344778

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-3708

GoogleEPSS <= 49%CRITICAL2022-10-28

The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This ma...

CVEs:CVE-2022-3708

Affected products

ProductStatusVendorPackageEcosystem
web_stories affected google
Upstream advisory

CVE-2022-38698

Open SourceEPSS <= 49%CRITICAL2022-10-14

In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

CVEs:CVE-2022-38698

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38697

Open SourceEPSS <= 49%MEDIUM2022-10-14

In messaging service, there is a missing permission check. This could lead to access unexpected provider in contacts service with no additional execution privileges needed.

CVEs:CVE-2022-38697

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.