Google Security Advisories · November 2022 — Google Security Advisories
442 advisories 268 CVEs 18 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2022-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 18 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

openSUSE-SU-2022:10221-1

Open SourceExploitedCISA KEV listedCRITICAL2022-11-28

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.3 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5289-1

Open SourceExploitedCISA KEV listed2022-11-27

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2022-4135

Open SourceExploitedCISA KEV listedCRITICAL2022-11-25

DEBIAN-CVE-2022-4135

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-4135

GoogleExploitedCISA KEV listedCRITICAL2022-11-24

Heap buffer overflow in GPU

CVEs:CVE-2022-4135

Affected products

ProductStatusVendorPackageEcosystem
electron affected npm electron
Upstream advisory

CVE-2022-4135

GoogleExploitedCISA KEV listedCRITICAL2022-11-24

Heap buffer overflow in GPU

CVEs:CVE-2022-4135

Affected products

ProductStatusVendorPackageEcosystem
electron affected npm electron
Upstream advisory

CVE-2022-4135

Open SourceExploitedCISA KEV listedCRITICAL2022-11-24

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4135

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge affected microsoft
edge_chromium affected microsoft
Upstream advisory

CVE-2022-4135

Project ZeroExploitedCISA KEV listed2022-11-24

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4135

Upstream advisory

CVE-2022-41128

GoogleExploitedCISA KEV listedCRITICAL2022-11-08

Windows Scripting Languages Remote Code Execution Vulnerability

CVEs:CVE-2022-41128

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

MGASA-2022-0419

Open SourceExploitedCISA KEV listedCRITICAL2022-11-13

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

DEBIAN-CVE-2022-3723

Open SourceExploitedCISA KEV listedHIGH2022-11-01

DEBIAN-CVE-2022-3723

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-41125

GoogleExploitedCISA KEV listedCRITICAL2022-11-08

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVEs:CVE-2022-41125

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_8.1 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

CVE-2022-41073

GoogleExploitedCISA KEV listedCRITICAL2022-11-08

Windows Print Spooler Elevation of Privilege Vulnerability

CVEs:CVE-2022-41073

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h1 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

ASB-A-240973083

GoogleWeaponized exploit2022-11-01

ASB-A-240973083

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

OESA-2022-2106

Open SourcePoC exploit2022-11-18

protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected openEuler:20.03-LTS-SP1 protobuf
Upstream advisory

RLSA-2022:7970

Open SourcePoC exploitHIGH2022-11-15

Moderate: protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Rocky Linux:9 protobuf
Upstream advisory

ALSA-2022:7970

Open SourcePoC exploitHIGH2022-11-15

Moderate: protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected AlmaLinux:9 protobuf
protobuf-compiler affected AlmaLinux:9 protobuf-compiler
protobuf-devel affected AlmaLinux:9 protobuf-devel
protobuf-lite affected AlmaLinux:9 protobuf-lite
protobuf-lite-devel affected AlmaLinux:9 protobuf-lite-devel
python3-protobuf affected AlmaLinux:9 python3-protobuf
Upstream advisory

RLSA-2022:7464

Open SourcePoC exploitHIGH2022-11-08

Moderate: protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Rocky Linux:8 protobuf
Upstream advisory

ALSA-2022:7464

Open SourcePoC exploitHIGH2022-11-08

Moderate: protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected AlmaLinux:8 protobuf
protobuf-compiler affected AlmaLinux:8 protobuf-compiler
protobuf-devel affected AlmaLinux:8 protobuf-devel
protobuf-lite affected AlmaLinux:8 protobuf-lite
protobuf-lite-devel affected AlmaLinux:8 protobuf-lite-devel
python3-protobuf affected AlmaLinux:8 python3-protobuf
Upstream advisory

CLSA-2022-1669241475

Open SourcePoC exploitCRITICAL2022-11-23

Fix CVE(s): CVE-2022-45061

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

CLSA-2022-1669241032

Open SourcePoC exploitCRITICAL2022-11-23

Fix CVE(s): CVE-2022-45061

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

ALSA-2022:7548

GooglePoC exploitHIGH2022-11-08

Low: Image Builder security, bug fix, and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Go affected golang
math/big affected golang
weldr-client affected AlmaLinux:8 weldr-client
weldr-client affected AlmaLinux
weldr-client affected golang
Upstream advisory

DEBIAN-CVE-2022-3656

Open SourcePoC exploitHIGH2022-11-01

DEBIAN-CVE-2022-3656

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

SUSE-SU-2022:3922-1

Open SourcePoC exploitHIGH2022-11-09

Security update for protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected SUSE:Linux Enterprise Module for Development Tools 15 SP3 protobuf
protobuf affected SUSE:Linux Enterprise Module for Development Tools 15 SP4 protobuf
protobuf affected SUSE:Linux Enterprise Module for Package Hub 15 SP3 protobuf
protobuf affected SUSE:Linux Enterprise Module for Package Hub 15 SP4 protobuf
protobuf affected SUSE:Linux Enterprise Installer Updates 15 SP2 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.3 protobuf
protobuf affected SUSE:Linux Enterprise Module for Basesystem 15 SP3 protobuf
protobuf affected SUSE:Linux Enterprise Module for Basesystem 15 SP4 protobuf
protobuf affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 protobuf
protobuf affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 protobuf
protobuf affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 protobuf
protobuf affected SUSE:Manager Server Module 4.1 protobuf
protobuf affected SUSE:Manager Server Module 4.2 protobuf
protobuf affected SUSE:Manager Server Module 4.3 protobuf
protobuf affected SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS protobuf
protobuf affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS protobuf
protobuf affected SUSE:Linux Enterprise Server 15 SP2-BCL protobuf
protobuf affected SUSE:Linux Enterprise Server 15 SP2-LTSS protobuf
protobuf affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 protobuf
protobuf affected SUSE:Manager Proxy 4.1 protobuf
protobuf affected SUSE:Manager Retail Branch Server 4.1 protobuf
protobuf affected SUSE:Manager Server 4.1 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.1 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.2 protobuf
protobuf affected SUSE:Enterprise Storage 7 protobuf
protobuf affected openSUSE:Leap Micro 5.2 protobuf
protobuf affected openSUSE:Leap 15.3 protobuf
protobuf affected openSUSE:Leap 15.4 protobuf
Upstream advisory

DEBIAN-CVE-2022-46146

Open SourcePoC exploitHIGH2022-11-29

DEBIAN-CVE-2022-46146

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-exporter-toolkit affected Debian:11 golang-github-prometheus-exporter-toolkit
golang-github-prometheus-exporter-toolkit affected Debian:12 golang-github-prometheus-exporter-toolkit
golang-github-prometheus-exporter-toolkit affected Debian:13 golang-github-prometheus-exporter-toolkit
golang-github-prometheus-exporter-toolkit affected Debian:14 golang-github-prometheus-exporter-toolkit
Upstream advisory

CVE-2022-3162

Open SourcePoC exploitMEDIUM2022-11-10

Kubernetes vulnerable to path traversal

CVEs:CVE-2022-3162

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

CVE-2022-3162

Open SourcePoC exploitCRITICAL2022-11-10

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are tru...

CVEs:CVE-2022-3162

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2022-3162

Open SourcePoC exploitMEDIUM2022-11-10

Kubernetes vulnerable to path traversal

CVEs:CVE-2022-3162

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

DEBIAN-CVE-2022-4174

Open SourcePoC exploitHIGH2022-11-30

DEBIAN-CVE-2022-4174

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4174

GooglePoC exploitHIGH2022-11-29

Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4174

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4192

Open SourcePoC exploitCRITICAL2022-11-30

DEBIAN-CVE-2022-4192

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4192

GooglePoC exploitCRITICAL2022-11-29

Use after free in Live Caption in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: Medium)

CVEs:CVE-2022-4192

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-3509

Open SourcePoC exploitHIGH2022-11-01

A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messa...

CVEs:CVE-2022-3509

Affected products

ProductStatusVendorPackageEcosystem
protobuf-java affected google
protobuf-javalite affected google
Upstream advisory

CVE-2022-3509

Open SourcePoC exploitHIGH2022-11-01

Protobuf Java vulnerable to Uncontrolled Resource Consumption

CVEs:CVE-2022-3509

Affected products

ProductStatusVendorPackageEcosystem
com.google.protobuf:protobuf-java affected Maven com.google.protobuf:protobuf-java
com.google.protobuf:protobuf-javalite affected Maven com.google.protobuf:protobuf-javalite
Upstream advisory

MGASA-2022-0444

Open SourcePoC exploit2022-11-27

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

OESA-2022-2115

Open SourcePoC exploit2022-11-25

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS golang
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP3 golang
Upstream advisory

AZL-79026

Open SourcePoC exploitHIGH2022-11-02

CVE-2022-41716 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-41716

Open SourcePoC exploitHIGH2022-11-02

DEBIAN-CVE-2022-41716

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-41716

GooglePoC exploitHIGH2022-11-01

Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious envir...

CVEs:CVE-2022-41716

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2022-1095

Open SourcePoC exploit2022-11-01

Unsanitized NUL in environment variables on Windows in syscall and os/exec

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

CVE-2022-20465

Open SourcePoC exploitMEDIUM2022-11-07

In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges need...

CVEs:CVE-2022-20465

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2022-3653

Open SourcePoC exploitCRITICAL2022-11-01

DEBIAN-CVE-2022-3653

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3510

Open SourcePoC exploitHIGH2022-11-11

Protobuf Java vulnerable to Uncontrolled Resource Consumption

CVEs:CVE-2022-3510

Affected products

ProductStatusVendorPackageEcosystem
com.google.protobuf:protobuf-java affected Maven com.google.protobuf:protobuf-java
com.google.protobuf:protobuf-javalite affected Maven com.google.protobuf:protobuf-javalite
Upstream advisory

CVE-2022-3510

Open SourcePoC exploitHIGH2022-11-11

A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated e...

CVEs:CVE-2022-3510

Affected products

ProductStatusVendorPackageEcosystem
protobuf-java affected google
protobuf-javalite affected google
Upstream advisory

DEBIAN-CVE-2022-3317

Open SourcePoC exploitMEDIUM2022-11-01

DEBIAN-CVE-2022-3317

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-20572

Open SourcePoC exploitMEDIUM2022-11-08

In verity_target of dm-verity-target.c, there is a possible way to modify read-only files due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2022-20572

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20452

Open SourcePoC exploitHIGH2022-11-07

In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2022-20452

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2022-3652

Open SourceCoalition ESS 30-63%HIGH2022-11-01

DEBIAN-CVE-2022-3652

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2022-4178

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4178

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2022-4178

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4178

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3654

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3654

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2022:10201-1

Open SourceCoalition ESS < 30%CRITICAL2022-11-14

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.3 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5275-1

Open SourceCoalition ESS < 30%2022-11-10

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2022-3890

Open SourceCoalition ESS < 30%CRITICAL2022-11-09

DEBIAN-CVE-2022-3890

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3890

GoogleCoalition ESS < 30%CRITICAL2022-11-09

Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3890

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2022-3370

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3370

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3373

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3373

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3446

Open SourceCoalition ESS < 30%CRITICAL2022-11-09

DEBIAN-CVE-2022-3446

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3885

Open SourceCoalition ESS < 30%CRITICAL2022-11-09

DEBIAN-CVE-2022-3885

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3885

GoogleCoalition ESS < 30%CRITICAL2022-11-09

Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3885

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2022-3887

Open SourceCoalition ESS < 30%CRITICAL2022-11-09

DEBIAN-CVE-2022-3887

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3887

GoogleCoalition ESS < 30%CRITICAL2022-11-09

Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3887

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2022-3889

Open SourceCoalition ESS < 30%HIGH2022-11-09

DEBIAN-CVE-2022-3889

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3889

GoogleCoalition ESS < 30%HIGH2022-11-09

Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3889

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2022-4185

Open SourceCoalition ESS < 30%MEDIUM2022-11-30

DEBIAN-CVE-2022-4185

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4185

GoogleCoalition ESS < 30%MEDIUM2022-11-29

Inappropriate implementation in Navigation in Google Chrome on iOS prior to 108.0.5359.71 allowed a remote attacker to spoof the contents of the modal dialogue via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4185

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3445

Open SourceCoalition ESS < 30%CRITICAL2022-11-09

DEBIAN-CVE-2022-3445

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3886

Open SourceCoalition ESS < 30%CRITICAL2022-11-09

DEBIAN-CVE-2022-3886

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3886

GoogleCoalition ESS < 30%CRITICAL2022-11-09

Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3886

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2022-3443

Open SourceCoalition ESS < 30%MEDIUM2022-11-01

DEBIAN-CVE-2022-3443

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3888

Open SourceCoalition ESS < 30%CRITICAL2022-11-09

DEBIAN-CVE-2022-3888

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-3888

GoogleCoalition ESS < 30%CRITICAL2022-11-09

Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-3888

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2022-43549

GoogleCoalition ESS < 30%CRITICAL2022-11-09

Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.

CVEs:CVE-2022-43549

Affected products

ProductStatusVendorPackageEcosystem
veeam_backup_for_google_cloud affected veeam
Upstream advisory

DEBIAN-CVE-2022-3444

Open SourceCoalition ESS < 30%MEDIUM2022-11-01

DEBIAN-CVE-2022-3444

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3308

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3308

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4175

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4175

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4175

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Use after free in Camera Capture in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4175

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3304

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3304

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3448

Open SourceCoalition ESS < 30%CRITICAL2022-11-09

DEBIAN-CVE-2022-3448

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-42461

GoogleCoalition ESS < 30%HIGH2022-11-18

Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.

CVEs:CVE-2022-42461

Affected products

ProductStatusVendorPackageEcosystem
google_authenticator affected miniorange
Upstream advisory

DEBIAN-CVE-2022-4181

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4181

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4181

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Use after free in Forms in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4181

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4190

Open SourceCoalition ESS < 30%HIGH2022-11-30

DEBIAN-CVE-2022-4190

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4193

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4193

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4190

GoogleCoalition ESS < 30%HIGH2022-11-29

Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4190

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4193

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Insufficient policy enforcement in File System API in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4193

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3450

Open SourceCoalition ESS < 30%CRITICAL2022-11-09

DEBIAN-CVE-2022-3450

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3447

Open SourceCoalition ESS < 30%MEDIUM2022-11-09

DEBIAN-CVE-2022-3447

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2022-3307

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3307

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3313

Open SourceCoalition ESS < 30%MEDIUM2022-11-01

DEBIAN-CVE-2022-3313

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4194

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4194

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4194

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Use after free in Accessibility in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4194

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3306

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3306

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2022-4187

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4187

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3311

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3311

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3315

Open SourceCoalition ESS < 30%HIGH2022-11-01

DEBIAN-CVE-2022-3315

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2022-4184

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4184

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2022-4184

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4184

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3305

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3305

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-xvwp-h6jv-7472

Open SourceCoalition ESS < 30%HIGH2022-11-21

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xvwp-h6jv-7472

Open SourceCoalition ESS < 30%HIGH2022-11-21

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-11539

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41900 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41900

Open SourceCoalition ESS < 30%HIGH2022-11-18

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

CVEs:CVE-2022-41900

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41900

Open SourceCoalition ESS < 30%HIGH2022-11-18

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

CVEs:CVE-2022-41900

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41900

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool with illegal pooling_ratio. Attackers using Tensorflow can exploit the vulnerability. They can access heap memory which is not in t...

CVEs:CVE-2022-41900

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

DEBIAN-CVE-2022-4176

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4176

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4176

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chr...

CVEs:CVE-2022-4176

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3309

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3309

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4191

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4191

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4191

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Use after free in Sign-In in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via profile destruction. (Chromium security severity: Medium)

CVEs:CVE-2022-4191

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3659

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3659

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4188

Open SourceCoalition ESS < 30%MEDIUM2022-11-30

DEBIAN-CVE-2022-4188

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4188

GoogleCoalition ESS < 30%MEDIUM2022-11-29

Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4188

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3660

Open SourceCoalition ESS < 30%MEDIUM2022-11-01

DEBIAN-CVE-2022-3660

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4182

Open SourceCoalition ESS < 30%MEDIUM2022-11-30

DEBIAN-CVE-2022-4182

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4182

GoogleCoalition ESS < 30%MEDIUM2022-11-29

Inappropriate implementation in Fenced Frames in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass fenced frame restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4182

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-h6q3-vv32-2cq5

Open SourceCoalition ESS < 30%CRITICAL2022-11-21

Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

GHSA-h6q3-vv32-2cq5

Open SourceCoalition ESS < 30%CRITICAL2022-11-21

Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
Upstream advisory

AZL-11532

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41894 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41894

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. The reference kernel of the `CONV_3D_TRANSPOSE` TensorFlow Lite operator wrongly increments the data_ptr when adding the bias to the result. Instead of `data_ptr += num_channels;` it should be...

CVEs:CVE-2022-41894

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41894

Open SourceCoalition ESS < 30%HIGH2022-11-18

Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite

CVEs:CVE-2022-41894

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

CVE-2022-41894

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite

CVEs:CVE-2022-41894

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
Upstream advisory

DEBIAN-CVE-2022-4183

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4183

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4183

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Insufficient policy enforcement in Popup Blocker in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4183

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3316

Open SourceCoalition ESS < 30%MEDIUM2022-11-01

DEBIAN-CVE-2022-3316

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3310

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3310

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-45369

GoogleCoalition ESS < 30%MEDIUM2022-11-18

Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.

CVEs:CVE-2022-45369

Affected products

ProductStatusVendorPackageEcosystem
plugin_for_google_reviews affected richplugins
Upstream advisory

DEBIAN-CVE-2022-3661

Open SourceCoalition ESS < 30%MEDIUM2022-11-01

DEBIAN-CVE-2022-3661

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-rjx6-v474-2ch9

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Segfault in `CompositeTensorVariantToComponents`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rjx6-v474-2ch9

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Segfault in `CompositeTensorVariantToComponents`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-11543

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41909 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41909

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVariant` tensor will trigger a segfault in `tf.raw_ops.CompositeTensorVariantToComponents`. We have patched the issue in GitHub commits b...

CVEs:CVE-2022-41909

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41909

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Segfault in `CompositeTensorVariantToComponents`

CVEs:CVE-2022-41909

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41909

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Segfault in `CompositeTensorVariantToComponents`

CVEs:CVE-2022-41909

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-3834

GoogleCoalition ESS < 30%CRITICAL2022-11-28

The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...

CVEs:CVE-2022-3834

Affected products

ProductStatusVendorPackageEcosystem
google_forms affected google_forms_project
Upstream advisory

DEBIAN-CVE-2022-4179

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4179

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2022-4179

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Use after free in Audio in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

CVEs:CVE-2022-4179

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3658

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3658

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4177

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4177

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2022-4180

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4180

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4177

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install an extension to potentially exploit heap corruption via a crafted Chrome Extension and UI interaction. (Chromium security severity:...

CVEs:CVE-2022-4177

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4180

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

CVEs:CVE-2022-4180

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4195

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4195

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4195

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass Safe Browsing warnings via a malicious file. (Chromium security severity: Medium)

CVEs:CVE-2022-4195

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-mv77-9g28-cwg3

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

`CHECK` fail via inputs in `PyFunc`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-mv77-9g28-cwg3

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

`CHECK` fail via inputs in `PyFunc`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-11542

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41908 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41908

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`CHECK` fail via inputs in `PyFunc`

CVEs:CVE-2022-41908

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41908

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. An input `token` that is not a UTF-8 bytestring will trigger a `CHECK` fail in `tf.raw_ops.PyFunc`. We have patched the issue in GitHub commit 9f03a9d3bafe902c1e6beb105b2f24172f238645. The fix...

CVEs:CVE-2022-41908

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41908

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`CHECK` fail via inputs in `PyFunc`

CVEs:CVE-2022-41908

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-3318

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3318

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3655

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3655

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-3314

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3314

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-6c6p-h79f-g6p4

Open SourceCoalition ESS < 30%HIGH2022-11-09

Istio may allow identity impersonation if user has localhost access

Affected products

ProductStatusVendorPackageEcosystem
istio/istio affected github.com github.com/istio/istio
Upstream advisory

GHSA-6c6p-h79f-g6p4

Open SourceCoalition ESS < 30%HIGH2022-11-09

Istio may allow identity impersonation if user has localhost access

Affected products

ProductStatusVendorPackageEcosystem
istio/istio affected github.com github.com/istio/istio
Upstream advisory

CVE-2022-39388

Open SourceCoalition ESS < 30%HIGH2022-11-09

Istio may allow identity impersonation if user has localhost access

CVEs:CVE-2022-39388

Affected products

ProductStatusVendorPackageEcosystem
istio/istio affected github.com github.com/istio/istio
Upstream advisory

CVE-2022-39388

Open SourceCoalition ESS < 30%HIGH2022-11-09

Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Ve...

CVEs:CVE-2022-39388

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

GHSA-368v-7v32-52fx

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Overflow in `ResizeNearestNeighborGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-368v-7v32-52fx

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Overflow in `ResizeNearestNeighborGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cg88-rpvp-cjv5

Open SourceCoalition ESS < 30%CRITICAL2022-11-21

Out of bounds write in grappler in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cg88-rpvp-cjv5

Open SourceCoalition ESS < 30%CRITICAL2022-11-21

Out of bounds write in grappler in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g9fm-r5mm-rf9f

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

`CHECK_EQ` fail via input in `SparseMatrixNNZ`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-g9fm-r5mm-rf9f

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

`CHECK_EQ` fail via input in `SparseMatrixNNZ`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-27rc-728f-x5w2

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

`CHECK` fail via inputs in `SdcaOptimizer`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-27rc-728f-x5w2

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

`CHECK` fail via inputs in `SdcaOptimizer`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hq7g-wwwp-q46h

Open SourceCoalition ESS < 30%HIGH2022-11-21

`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-hq7g-wwwp-q46h

Open SourceCoalition ESS < 30%HIGH2022-11-21

`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f2w8-jw48-fr7j

Open SourceCoalition ESS < 30%HIGH2022-11-21

`FractionalMaxPoolGrad` Heap out of bounds read

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f2w8-jw48-fr7j

Open SourceCoalition ESS < 30%HIGH2022-11-21

`FractionalMaxPoolGrad` Heap out of bounds read

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rmg2-f698-wq35

Open SourceCoalition ESS < 30%HIGH2022-11-21

`tf.raw_ops.Mfcc` crashes

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rmg2-f698-wq35

Open SourceCoalition ESS < 30%HIGH2022-11-21

`tf.raw_ops.Mfcc` crashes

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gq2j-cr96-gvqx

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

`MirrorPadGrad` heap out of bounds read

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gq2j-cr96-gvqx

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

`MirrorPadGrad` heap out of bounds read

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8fvv-46hw-vpg3

Open SourceCoalition ESS < 30%HIGH2022-11-21

Overflow in `tf.keras.losses.poisson`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8fvv-46hw-vpg3

Open SourceCoalition ESS < 30%HIGH2022-11-21

Overflow in `tf.keras.losses.poisson`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41902

Open SourceCoalition ESS < 30%CRITICAL2022-11-21

TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bound...

CVEs:CVE-2022-41902

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41902

Open SourceCoalition ESS < 30%HIGH2022-11-21

Out of bounds write in grappler in Tensorflow

CVEs:CVE-2022-41902

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41902

Open SourceCoalition ESS < 30%CRITICAL2022-11-21

Out of bounds write in grappler in Tensorflow

CVEs:CVE-2022-41902

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-11541

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41907 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-11540

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41901 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-11535

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41897 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-11537

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41898 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-11538

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41899 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-11533

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41895 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-11534

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41896 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41887

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Overflow in `tf.keras.losses.poisson`

CVEs:CVE-2022-41887

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41887

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. `tf.keras.losses.poisson` receives a `y_pred` and `y_true` that are passed through `functor::mul` in `BinaryOp`. If the resulting dimensions overflow an `int32`, TensorFlow will crash due to a...

CVEs:CVE-2022-41887

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41887

Open SourceCoalition ESS < 30%HIGH2022-11-18

Overflow in `tf.keras.losses.poisson`

CVEs:CVE-2022-41887

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41895

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`MirrorPadGrad` heap out of bounds read

CVEs:CVE-2022-41895

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41895

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. If `MirrorPadGrad` is given outsize input `paddings`, TensorFlow will give a heap OOB error. We have patched the issue in GitHub commit 717ca98d8c3bba348ff62281fdf38dcb5ea1ec92. The fix will b...

CVEs:CVE-2022-41895

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41895

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`MirrorPadGrad` heap out of bounds read

CVEs:CVE-2022-41895

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41896

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`tf.raw_ops.Mfcc` crashes

CVEs:CVE-2022-41896

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41896

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. If `ThreadUnsafeUnigramCandidateSampler` is given input `filterbank_channel_count` greater than the allowed max size, TensorFlow will crash. We have patched the issue in GitHub commit 39ec7eaf...

CVEs:CVE-2022-41896

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41896

Open SourceCoalition ESS < 30%HIGH2022-11-18

`tf.raw_ops.Mfcc` crashes

CVEs:CVE-2022-41896

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41897

Open SourceCoalition ESS < 30%HIGH2022-11-18

`FractionalMaxPoolGrad` Heap out of bounds read

CVEs:CVE-2022-41897

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41897

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`FractionalMaxPoolGrad` Heap out of bounds read

CVEs:CVE-2022-41897

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41897

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. If `FractionMaxPoolGrad` is given outsize inputs `row_pooling_sequence` and `col_pooling_sequence`, TensorFlow will crash. We have patched the issue in GitHub commit d71090c3e5ca325bdf4b02eb23...

CVEs:CVE-2022-41897

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41898

Open SourceCoalition ESS < 30%HIGH2022-11-18

`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`

CVEs:CVE-2022-41898

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41898

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. If `SparseFillEmptyRowsGrad` is given empty inputs, TensorFlow will crash. We have patched the issue in GitHub commit af4a6a3c8b95022c351edae94560acc61253a1b8. The fix will be included in Tens...

CVEs:CVE-2022-41898

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41898

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`

CVEs:CVE-2022-41898

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41899

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`CHECK` fail via inputs in `SdcaOptimizer`

CVEs:CVE-2022-41899

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41899

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`CHECK` fail via inputs in `SdcaOptimizer`

CVEs:CVE-2022-41899

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41899

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. Inputs `dense_features` or `example_state_data` not of rank 2 will trigger a `CHECK` fail in `SdcaOptimizer`. We have patched the issue in GitHub commit 80ff197d03db2a70c6a111f97dcdacad1b0babf...

CVEs:CVE-2022-41899

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41901

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`CHECK_EQ` fail via input in `SparseMatrixNNZ`

CVEs:CVE-2022-41901

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41901

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. An input `sparse_matrix` that is not a matrix with a shape with rank 0 will trigger a `CHECK` fail in `tf.raw_ops.SparseMatrixNNZ`. We have patched the issue in GitHub commit f856d02e5322821aa...

CVEs:CVE-2022-41901

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41901

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`CHECK_EQ` fail via input in `SparseMatrixNNZ`

CVEs:CVE-2022-41901

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41907

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Overflow in `ResizeNearestNeighborGrad`

CVEs:CVE-2022-41907

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41907

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. When `tf.raw_ops.ResizeNearestNeighborGrad` is given a large `size` input, it overflows. We have patched the issue in GitHub commit 00c821af032ba9e5f5fa3fe14690c8d28a657624. The fix will be in...

CVEs:CVE-2022-41907

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41907

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Overflow in `ResizeNearestNeighborGrad`

CVEs:CVE-2022-41907

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-67pf-62xr-q35m

Open SourceCoalition ESS < 30%HIGH2022-11-21

`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-67pf-62xr-q35m

Open SourceCoalition ESS < 30%HIGH2022-11-21

`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h246-cgh4-7475

Open SourceCoalition ESS < 30%HIGH2022-11-21

`CHECK` fail in `BCast` overflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-h246-cgh4-7475

Open SourceCoalition ESS < 30%HIGH2022-11-21

`CHECK` fail in `BCast` overflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6x99-gv2v-q76v

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

FPE in `tf.image.generate_bounding_box_proposals`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6x99-gv2v-q76v

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

FPE in `tf.image.generate_bounding_box_proposals`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-11531

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41893 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-11529

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41890 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-11527

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41888 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41888

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. When running on GPU, `tf.image.generate_bounding_box_proposals` receives a `scores` input that must be of rank 4 but is not checked. We have patched the issue in GitHub commit cf35502463a88ca7...

CVEs:CVE-2022-41888

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41888

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

FPE in `tf.image.generate_bounding_box_proposals`

CVEs:CVE-2022-41888

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41888

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

FPE in `tf.image.generate_bounding_box_proposals`

CVEs:CVE-2022-41888

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41890

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. If `BCast::ToShape` is given input larger than an `int32`, it will crash, despite being supposed to handle up to an `int64`. An example can be seen in `tf.experimental.numpy.outer` by passing ...

CVEs:CVE-2022-41890

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41890

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`CHECK` fail in `BCast` overflow

CVEs:CVE-2022-41890

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41890

Open SourceCoalition ESS < 30%HIGH2022-11-18

`CHECK` fail in `BCast` overflow

CVEs:CVE-2022-41890

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41893

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`

CVEs:CVE-2022-41893

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41893

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListResize` is given a nonscalar value for input `size`, it results `CHECK` fail which can be used to trigger a denial of service attack. We have patched the issue in GitH...

CVEs:CVE-2022-41893

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41893

Open SourceCoalition ESS < 30%HIGH2022-11-18

`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`

CVEs:CVE-2022-41893

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-20445

Open SourceCoalition ESS < 30%HIGH2022-11-07

In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2022-20445

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-66vq-54fq-6jvv

Open SourceCoalition ESS < 30%HIGH2022-11-21

Segfault in `tf.raw_ops.TensorListConcat`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-66vq-54fq-6jvv

Open SourceCoalition ESS < 30%HIGH2022-11-21

Segfault in `tf.raw_ops.TensorListConcat`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-54pp-c6pp-7fpx

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Overflow in `ImageProjectiveTransformV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-54pp-c6pp-7fpx

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Overflow in `ImageProjectiveTransformV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-762h-vpvw-3rcx

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Overflow in `FusedResizeAndPadConv2D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-762h-vpvw-3rcx

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Overflow in `FusedResizeAndPadConv2D`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-11530

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41891 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-11526

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41886 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41885

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. When `tf.raw_ops.FusedResizeAndPadConv2D` is given a large tensor shape, it overflows. We have patched the issue in GitHub commit d66e1d568275e6a2947de97dca7a102a211e01ce. The fix will be incl...

CVEs:CVE-2022-41885

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41885

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Overflow in `FusedResizeAndPadConv2D`

CVEs:CVE-2022-41885

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41885

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Overflow in `FusedResizeAndPadConv2D`

CVEs:CVE-2022-41885

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41886

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Overflow in `ImageProjectiveTransformV2`

CVEs:CVE-2022-41886

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41886

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. When `tf.raw_ops.ImageProjectiveTransformV2` is given a large output shape, it overflows. We have patched the issue in GitHub commit 8faa6ea692985dbe6ce10e1a3168e0bd60a723ba. The fix will be i...

CVEs:CVE-2022-41886

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41886

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Overflow in `ImageProjectiveTransformV2`

CVEs:CVE-2022-41886

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41891

Open SourceCoalition ESS < 30%HIGH2022-11-18

Segfault in `tf.raw_ops.TensorListConcat`

CVEs:CVE-2022-41891

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41891

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Segfault in `tf.raw_ops.TensorListConcat`

CVEs:CVE-2022-41891

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41891

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListConcat` is given `element_shape=[]`, it results segmentation fault which can be used to trigger a denial of service attack. We have patched the issue in GitHub commit ...

CVEs:CVE-2022-41891

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

DEBIAN-CVE-2022-4186

Open SourceCoalition ESS < 30%MEDIUM2022-11-30

DEBIAN-CVE-2022-4186

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4186

GoogleCoalition ESS < 30%MEDIUM2022-11-29

Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTML page. (Chromium security sever...

CVEs:CVE-2022-4186

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-3449

Open SourceCoalition ESS < 30%CRITICAL2022-11-09

DEBIAN-CVE-2022-3449

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2022-3657

Open SourceCoalition ESS < 30%CRITICAL2022-11-01

DEBIAN-CVE-2022-3657

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-xxcj-rhqg-m46g

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Segfault via invalid attributes in `pywrap_tfe_src.cc`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xxcj-rhqg-m46g

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Segfault via invalid attributes in `pywrap_tfe_src.cc`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-11528

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41889 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41889

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Segfault via invalid attributes in `pywrap_tfe_src.cc`

CVEs:CVE-2022-41889

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41889

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Segfault via invalid attributes in `pywrap_tfe_src.cc`

CVEs:CVE-2022-41889

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41889

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. If a list of quantized tensors is assigned to an attribute, the pywrap code fails to parse the tensor and returns a `nullptr`, which is not caught. An example can be seen in `tf.compat.v1.extr...

CVEs:CVE-2022-41889

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-pf36-r9c6-h97j

Open SourceCoalition ESS < 30%HIGH2022-11-21

Invalid char to bool conversion when printing a tensor

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-pf36-r9c6-h97j

Open SourceCoalition ESS < 30%HIGH2022-11-21

Invalid char to bool conversion when printing a tensor

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-11544

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41911 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41911

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Invalid char to bool conversion when printing a tensor

CVEs:CVE-2022-41911

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41911

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. When printing a tensor, we get it's data as a `const char*` array (since that's the underlying storage) and then we typecast it to the element type. However, conversions from `char` to `bool` ...

CVEs:CVE-2022-41911

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41911

Open SourceCoalition ESS < 30%HIGH2022-11-18

Invalid char to bool conversion when printing a tensor

CVEs:CVE-2022-41911

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-frqp-wp83-qggv

Open SourceCoalition ESS < 30%CRITICAL2022-11-21

Heap overflow in `QuantizeAndDequantizeV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-frqp-wp83-qggv

Open SourceCoalition ESS < 30%CRITICAL2022-11-21

Heap overflow in `QuantizeAndDequantizeV2`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41910

Open SourceCoalition ESS < 30%CRITICAL2022-11-21

TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bound...

CVEs:CVE-2022-41910

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41910

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Heap overflow in `QuantizeAndDequantizeV2`

CVEs:CVE-2022-41910

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41910

Open SourceCoalition ESS < 30%CRITICAL2022-11-21

Heap overflow in `QuantizeAndDequantizeV2`

CVEs:CVE-2022-41910

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8w5g-3wcv-9g2j

Open SourceCoalition ESS < 30%MEDIUM2022-11-22

Tensorflow vulnerable to Out-of-Bounds Read

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-8w5g-3wcv-9g2j

Open SourceCoalition ESS < 30%MEDIUM2022-11-22

Tensorflow vulnerable to Out-of-Bounds Read

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-11524

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41880 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41880

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. When the `BaseCandidateSamplerOp` function receives a value in `true_classes` larger than `range_max`, a heap oob read occurs. We have patched the issue in GitHub commit b389f5c944cadfdfe599b3...

CVEs:CVE-2022-41880

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-41880

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Tensorflow vulnerable to Out-of-Bounds Read

CVEs:CVE-2022-41880

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41880

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Tensorflow vulnerable to Out-of-Bounds Read

CVEs:CVE-2022-41880

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

DEBIAN-CVE-2022-4189

Open SourceCoalition ESS < 30%CRITICAL2022-11-30

DEBIAN-CVE-2022-4189

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2022-4189

GoogleCoalition ESS < 30%CRITICAL2022-11-29

Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity:...

CVEs:CVE-2022-4189

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-w58w-79xv-6vcj

Open SourceCoalition ESS < 30%HIGH2022-11-21

Out of bounds segmentation fault due to unequal op inputs in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-w58w-79xv-6vcj

Open SourceCoalition ESS < 30%HIGH2022-11-21

Out of bounds segmentation fault due to unequal op inputs in Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41883

Open SourceCoalition ESS < 30%HIGH2022-11-18

Out of bounds segmentation fault due to unequal op inputs in Tensorflow

CVEs:CVE-2022-41883

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41883

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Out of bounds segmentation fault due to unequal op inputs in Tensorflow

CVEs:CVE-2022-41883

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41883

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. When ops that have specified input sizes receive a differing number of inputs, the executor will crash. We have patched the issue in GitHub commit f5381e0e10b5a61344109c1b7c174c68110f7629. The...

CVEs:CVE-2022-41883

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

GHSA-jq6x-99hj-q636

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Seg fault in `ndarray_tensor_bridge` due to zero and large inputs

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-jq6x-99hj-q636

Open SourceCoalition ESS < 30%MEDIUM2022-11-21

Seg fault in `ndarray_tensor_bridge` due to zero and large inputs

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-11525

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

CVE-2022-41884 affecting package tensorflow for versions less than 2.11.0-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2022-41884

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Seg fault in `ndarray_tensor_bridge` due to zero and large inputs

CVEs:CVE-2022-41884

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41884

Open SourceCoalition ESS < 30%MEDIUM2022-11-18

Seg fault in `ndarray_tensor_bridge` due to zero and large inputs

CVEs:CVE-2022-41884

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2022-41884

Open SourceCoalition ESS < 30%CRITICAL2022-11-18

TensorFlow is an open source platform for machine learning. If a numpy array is created with a shape such that one element is zero and the others sum to a large number, an error will be raised. We have patched the issue in GitHub commit 2b56169c16e375c...

CVEs:CVE-2022-41884

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2022-4955

GoogleCoalition ESS < 30%MEDIUM2022-11-29

Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4955

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-38137

GoogleCoalition ESS < 30%HIGH2022-11-08

Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.

CVEs:CVE-2022-38137

Affected products

ProductStatusVendorPackageEcosystem
analytify_-_google_analytics_dashboard affected analytify
Upstream advisory

CVE-2022-20447

Open SourceCoalition ESS < 30%HIGH2022-11-07

In PAN_WriteBuf of pan_api.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2022-20447

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2022-3312

Open SourceCoalition ESS < 30%MEDIUM2022-11-01

DEBIAN-CVE-2022-3312

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-32617

Open SourceCoalition ESS < 30%HIGH2022-11-08

In typec, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. U...

CVEs:CVE-2022-32617

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32618

Open SourceCoalition ESS < 30%HIGH2022-11-08

In typec, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. U...

CVEs:CVE-2022-32618

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20453

Open SourceCoalition ESS < 30%HIGH2022-11-07

In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is ne...

CVEs:CVE-2022-20453

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-1050

Open SourceCoalition ESS < 30%HIGH2022-11-07

In MMU_UnmapPages of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2021-1050

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-243825200

GoogleCoalition ESS < 30%HIGH2022-11-01

ASB-A-243825200

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-244657985

GoogleCoalition ESS < 30%CRITICAL2022-11-01

ASB-A-244657985

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-244666286

GoogleCoalition ESS < 30%CRITICAL2022-11-01

ASB-A-244666286

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-244674480

GoogleCoalition ESS < 30%CRITICAL2022-11-01

ASB-A-244674480

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-32614

Open SourceCoalition ESS < 30%HIGH2022-11-08

In audio, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310571; Issue ID: ALPS07310...

CVEs:CVE-2022-32614

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32615

Open SourceCoalition ESS < 30%HIGH2022-11-08

In ccd, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326559; Issue ID: ALPS...

CVEs:CVE-2022-32615

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32616

Open SourceCoalition ESS < 30%HIGH2022-11-08

In isp, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341258; Issue ID: ALPS...

CVEs:CVE-2022-32616

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32611

Open SourceCoalition ESS < 30%HIGH2022-11-08

In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340373; Issue ID: ...

CVEs:CVE-2022-32611

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32603

Open SourceCoalition ESS < 30%HIGH2022-11-08

In gpu drm, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310704; Iss...

CVEs:CVE-2022-32603

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32607

Open SourceCoalition ESS < 30%HIGH2022-11-08

In aee, there is a possible use after free due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07202891; Issue ID: ALPS0...

CVEs:CVE-2022-32607

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20454

Open SourceCoalition ESS < 30%HIGH2022-11-07

In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...

CVEs:CVE-2022-20454

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20462

Open SourceCoalition ESS < 30%HIGH2022-11-07

In phNxpNciHal_write_unlocked of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2022-20462

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32605

Open SourceCoalition ESS < 30%HIGH2022-11-08

In isp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07213898; Issue I...

CVEs:CVE-2022-32605

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-21778

Open SourceCoalition ESS < 30%MEDIUM2022-11-08

In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06382421; Issu...

CVEs:CVE-2022-21778

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39880

Open SourceCoalition ESS < 30%HIGH2022-11-09

Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.

CVEs:CVE-2022-39880

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32602

Open SourceCoalition ESS < 30%MEDIUM2022-11-07

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388790...

CVEs:CVE-2022-32602

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-245050053

GoogleCoalition ESS < 30%MEDIUM2022-11-01

ASB-A-245050053

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20457

Open SourceCoalition ESS < 30%MEDIUM2022-11-07

In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2022-20457

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42533

Open SourceCoalition ESS < 30%HIGH2022-11-17

In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2022-42533

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-239415718

GoogleCoalition ESS < 30%HIGH2022-11-01

PUB-A-239415718

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20414

Open SourceCoalition ESS < 30%MEDIUM2022-11-07

In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-20414

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32609

Open SourceCoalition ESS < 30%HIGH2022-11-08

In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203410; Issue ID: ALPS07203410.

CVEs:CVE-2022-32609

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32610

Open SourceCoalition ESS < 30%HIGH2022-11-08

In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203476; Issue ID: ALPS07203476.

CVEs:CVE-2022-32610

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-238106223

GoogleCoalition ESS < 30%2022-11-01

ASB-A-238106223

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-244673210

GoogleCoalition ESS < 30%CRITICAL2022-11-01

ASB-A-244673210

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-245210875

GoogleCoalition ESS < 30%CRITICAL2022-11-01

ASB-A-245210875

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20441

Open SourceCoalition ESS < 30%HIGH2022-11-07

In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution p...

CVEs:CVE-2022-20441

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-244109033

GoogleCoalition ESS < 30%2022-11-01

ASB-A-244109033

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-244684957

GoogleCoalition ESS < 30%CRITICAL2022-11-01

ASB-A-244684957

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-246482122

GoogleCoalition ESS < 30%CRITICAL2022-11-01

ASB-A-246482122

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-32601

Open SourceCoalition ESS < 30%HIGH2022-11-07

In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0731913...

CVEs:CVE-2022-32601

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-234038598

GoogleCoalition ESS < 30%HIGH2022-11-01

ASB-A-234038598

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20448

Open SourceCoalition ESS < 30%MEDIUM2022-11-07

In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...

CVEs:CVE-2022-20448

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20446

Open SourceCoalition ESS < 30%LOW2022-11-07

In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges...

CVEs:CVE-2022-20446

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20451

Open SourceCoalition ESS < 30%HIGH2022-11-07

In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for...

CVEs:CVE-2022-20451

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39882

Open SourceCoalition ESS < 30%HIGH2022-11-09

Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2022-39882

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-39661

Open SourceCoalition ESS < 30%HIGH2022-11-07

In _PMRLogicalOffsetToPhysicalOffset of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...

CVEs:CVE-2021-39661

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-246824784

GoogleCoalition ESS < 30%HIGH2022-11-01

ASB-A-246824784

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-32612

Open SourceCoalition ESS < 30%HIGH2022-11-08

In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203500; Issue ID: ALPS07203500.

CVEs:CVE-2022-32612

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32613

Open SourceCoalition ESS < 30%HIGH2022-11-08

In vcu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07206340; Issue ID: ALPS0720...

CVEs:CVE-2022-32613

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32608

Open SourceCoalition ESS < 30%HIGH2022-11-08

In jpeg, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388753; Issue ID: ALPS07388753.

CVEs:CVE-2022-32608

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20428

Open SourceCoalition ESS < 30%HIGH2022-11-17

In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...

CVEs:CVE-2022-20428

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20427

Open SourceCoalition ESS < 30%MEDIUM2022-11-17

In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...

CVEs:CVE-2022-20427

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20459

Open SourceCoalition ESS < 30%HIGH2022-11-07

In (TBD) of (TBD), there is a possible way to redirect code execution due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2022-20459

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20460

Open SourceCoalition ESS < 30%MEDIUM2022-11-07

In (TBD) mprot_unmap? of (TBD), there is a possible way to corrupt the memory mapping due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2022-20460

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-239555070

GoogleCoalition ESS < 30%NONE2022-11-01

PUB-A-239555070

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-239555411

GoogleCoalition ESS < 30%HIGH2022-11-01

PUB-A-239555411

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-239556260

GoogleCoalition ESS < 30%HIGH2022-11-01

PUB-A-239556260

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-239557547

GoogleCoalition ESS < 30%NONE2022-11-01

PUB-A-239557547

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20426

Open SourceCoalition ESS < 30%HIGH2022-11-07

In multiple functions of many files, there is a possible obstruction of the user's ability to select a phone account due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction...

CVEs:CVE-2022-20426

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20450

Open SourceCoalition ESS < 30%HIGH2022-11-07

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...

CVEs:CVE-2022-20450

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-244683429

GoogleCoalition ESS < 30%CRITICAL2022-11-01

ASB-A-244683429

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-39884

Open SourceCoalition ESS < 30%MEDIUM2022-11-09

Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.

CVEs:CVE-2022-39884

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39883

Open SourceCoalition ESS < 30%HIGH2022-11-09

Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.

CVEs:CVE-2022-39883

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39885

Open SourceCoalition ESS < 30%MEDIUM2022-11-09

Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.

CVEs:CVE-2022-39885

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39886

Open SourceCoalition ESS < 30%MEDIUM2022-11-09

Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.

CVEs:CVE-2022-39886

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39887

Open SourceCoalition ESS < 30%MEDIUM2022-11-09

Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.

CVEs:CVE-2022-39887

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39879

Open SourceCoalition ESS < 30%MEDIUM2022-11-09

Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.

CVEs:CVE-2022-39879

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-cqvq-fvhr-v6hc

Open SourceAll remainingHIGH2022-11-21

`CHECK` failure in `SobolSample` via missing validation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-cqvq-fvhr-v6hc

Open SourceAll remainingHIGH2022-11-21

`CHECK` failure in `SobolSample` via missing validation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xf83-q765-xm6m

Open SourceAll remainingHIGH2022-11-21

`CHECK` fail in `TensorListScatter` and `TensorListScatterV2` in eager mode

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-xf83-q765-xm6m

Open SourceAll remainingHIGH2022-11-21

`CHECK` fail in `TensorListScatter` and `TensorListScatterV2` in eager mode

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.