Advisories
Open SourceExploitedCISA KEV listedCRITICAL2022-11-28
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
Open SourceExploitedCISA KEV listed2022-11-27
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceExploitedCISA KEV listedCRITICAL2022-11-25
DEBIAN-CVE-2022-4135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleExploitedCISA KEV listedCRITICAL2022-11-24
Heap buffer overflow in GPU
CVEs:CVE-2022-4135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| electron |
affected |
npm |
electron |
— |
GoogleExploitedCISA KEV listedCRITICAL2022-11-24
Heap buffer overflow in GPU
CVEs:CVE-2022-4135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| electron |
affected |
npm |
electron |
— |
Open SourceExploitedCISA KEV listedCRITICAL2022-11-24
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| edge |
affected |
microsoft |
— |
— |
| edge_chromium |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2022-11-24
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4135
GoogleExploitedCISA KEV listedHIGH2022-11-09
CVEs:CVE-2022-41128
GoogleExploitedCISA KEV listedCRITICAL2022-11-08
Windows Scripting Languages Remote Code Execution Vulnerability
CVEs:CVE-2022-41128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1507 |
affected |
microsoft |
— |
— |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_10_20h2 |
affected |
microsoft |
— |
— |
| windows_10_21h1 |
affected |
microsoft |
— |
— |
| windows_10_21h2 |
affected |
microsoft |
— |
— |
| windows_10_22h2 |
affected |
microsoft |
— |
— |
| windows_11_21h2 |
affected |
microsoft |
— |
— |
| windows_11_22h2 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
| windows_server_2022 |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2022-11-08
Windows Scripting Languages Remote Code Execution Vulnerability
CVEs:CVE-2022-41128
Open SourceExploitedCISA KEV listedCRITICAL2022-11-13
Updated chromium-browser-stable packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:8 |
chromium-browser-stable |
— |
Open SourceExploitedCISA KEV listedHIGH2022-11-01
DEBIAN-CVE-2022-3723
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleExploitedCISA KEV listedHIGH2022-11-09
CVEs:CVE-2022-41125
Project ZeroExploitedCISA KEV listed2022-11-08
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
CVEs:CVE-2022-41125
GoogleExploitedCISA KEV listedCRITICAL2022-11-08
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
CVEs:CVE-2022-41125
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1507 |
affected |
microsoft |
— |
— |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_10_20h2 |
affected |
microsoft |
— |
— |
| windows_10_21h1 |
affected |
microsoft |
— |
— |
| windows_10_21h2 |
affected |
microsoft |
— |
— |
| windows_10_22h2 |
affected |
microsoft |
— |
— |
| windows_11_21h2 |
affected |
microsoft |
— |
— |
| windows_11_22h2 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
| windows_server_2022 |
affected |
microsoft |
— |
— |
GoogleExploitedCISA KEV listedHIGH2022-11-09
CVEs:CVE-2022-41073
GoogleExploitedCISA KEV listedCRITICAL2022-11-08
Windows Print Spooler Elevation of Privilege Vulnerability
CVEs:CVE-2022-41073
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1507 |
affected |
microsoft |
— |
— |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_10_20h2 |
affected |
microsoft |
— |
— |
| windows_10_21h1 |
affected |
microsoft |
— |
— |
| windows_10_21h2 |
affected |
microsoft |
— |
— |
| windows_10_22h2 |
affected |
microsoft |
— |
— |
| windows_11_21h2 |
affected |
microsoft |
— |
— |
| windows_11_22h2 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
| windows_server_2022 |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2022-11-08
Windows Print Spooler Elevation of Privilege Vulnerability
CVEs:CVE-2022-41073
GoogleWeaponized exploit2022-11-01
ASB-A-240973083
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
Open SourcePoC exploit2022-11-18
protobuf security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
openEuler:20.03-LTS-SP1 |
protobuf |
— |
Open SourcePoC exploitHIGH2022-11-15
Moderate: protobuf security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
Rocky Linux:9 |
protobuf |
— |
Open SourcePoC exploitHIGH2022-11-15
Moderate: protobuf security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
AlmaLinux:9 |
protobuf |
— |
| protobuf-compiler |
affected |
AlmaLinux:9 |
protobuf-compiler |
— |
| protobuf-devel |
affected |
AlmaLinux:9 |
protobuf-devel |
— |
| protobuf-lite |
affected |
AlmaLinux:9 |
protobuf-lite |
— |
| protobuf-lite-devel |
affected |
AlmaLinux:9 |
protobuf-lite-devel |
— |
| python3-protobuf |
affected |
AlmaLinux:9 |
python3-protobuf |
— |
Open SourcePoC exploitHIGH2022-11-08
Moderate: protobuf security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
Rocky Linux:8 |
protobuf |
— |
Open SourcePoC exploitHIGH2022-11-08
Moderate: protobuf security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
AlmaLinux:8 |
protobuf |
— |
| protobuf-compiler |
affected |
AlmaLinux:8 |
protobuf-compiler |
— |
| protobuf-devel |
affected |
AlmaLinux:8 |
protobuf-devel |
— |
| protobuf-lite |
affected |
AlmaLinux:8 |
protobuf-lite |
— |
| protobuf-lite-devel |
affected |
AlmaLinux:8 |
protobuf-lite-devel |
— |
| python3-protobuf |
affected |
AlmaLinux:8 |
python3-protobuf |
— |
Open SourcePoC exploitCRITICAL2022-11-23
Fix CVE(s): CVE-2022-45061
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python3.5 |
— |
| libpython3.5 |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5 |
— |
| libpython3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-dev |
— |
| libpython3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-minimal |
— |
| libpython3.5-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-stdlib |
— |
| libpython3.5-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-testsuite |
— |
| python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
python3.5 |
— |
| python3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-dev |
— |
| python3.5-doc |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-doc |
— |
| python3.5-examples |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-examples |
— |
| python3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-minimal |
— |
| python3.5-venv |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-venv |
— |
Open SourcePoC exploitCRITICAL2022-11-23
Fix CVE(s): CVE-2022-45061
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python2.7 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python2.7 |
— |
| libpython2.7 |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7 |
— |
| libpython2.7-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-dev |
— |
| libpython2.7-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-minimal |
— |
| libpython2.7-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-stdlib |
— |
| libpython2.7-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-testsuite |
— |
| python2.7 |
affected |
TuxCare:Ubuntu:16.04 |
python2.7 |
— |
| python2.7-dev |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-dev |
— |
| python2.7-doc |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-doc |
— |
| python2.7-examples |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-examples |
— |
| python2.7-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-minimal |
— |
GooglePoC exploitHIGH2022-11-08
Low: Image Builder security, bug fix, and enhancement update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
| Go |
affected |
golang |
— |
— |
| math/big |
affected |
golang |
— |
— |
| weldr-client |
affected |
AlmaLinux:8 |
weldr-client |
— |
| weldr-client |
affected |
AlmaLinux |
— |
— |
| weldr-client |
affected |
golang |
— |
— |
Open SourcePoC exploitHIGH2022-11-01
DEBIAN-CVE-2022-3656
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourcePoC exploitHIGH2022-11-09
Security update for protobuf
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Development Tools 15 SP3 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Development Tools 15 SP4 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Package Hub 15 SP3 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Package Hub 15 SP4 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Installer Updates 15 SP2 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Micro 5.3 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Basesystem 15 SP3 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Basesystem 15 SP4 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP2 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP3 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 |
protobuf |
— |
| protobuf |
affected |
SUSE:Manager Server Module 4.1 |
protobuf |
— |
| protobuf |
affected |
SUSE:Manager Server Module 4.2 |
protobuf |
— |
| protobuf |
affected |
SUSE:Manager Server Module 4.3 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Server 15 SP2-BCL |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Server 15 SP2-LTSS |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 |
protobuf |
— |
| protobuf |
affected |
SUSE:Manager Proxy 4.1 |
protobuf |
— |
| protobuf |
affected |
SUSE:Manager Retail Branch Server 4.1 |
protobuf |
— |
| protobuf |
affected |
SUSE:Manager Server 4.1 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Micro 5.1 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Micro 5.2 |
protobuf |
— |
| protobuf |
affected |
SUSE:Enterprise Storage 7 |
protobuf |
— |
| protobuf |
affected |
openSUSE:Leap Micro 5.2 |
protobuf |
— |
| protobuf |
affected |
openSUSE:Leap 15.3 |
protobuf |
— |
| protobuf |
affected |
openSUSE:Leap 15.4 |
protobuf |
— |
Open SourcePoC exploitHIGH2022-11-29
DEBIAN-CVE-2022-46146
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-prometheus-exporter-toolkit |
affected |
Debian:11 |
golang-github-prometheus-exporter-toolkit |
— |
| golang-github-prometheus-exporter-toolkit |
affected |
Debian:12 |
golang-github-prometheus-exporter-toolkit |
— |
| golang-github-prometheus-exporter-toolkit |
affected |
Debian:13 |
golang-github-prometheus-exporter-toolkit |
— |
| golang-github-prometheus-exporter-toolkit |
affected |
Debian:14 |
golang-github-prometheus-exporter-toolkit |
— |
Open SourcePoC exploitMEDIUM2022-11-10
Kubernetes vulnerable to path traversal
CVEs:CVE-2022-3162
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourcePoC exploitCRITICAL2022-11-10
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are tru...
CVEs:CVE-2022-3162
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
Open SourcePoC exploitMEDIUM2022-11-10
Kubernetes vulnerable to path traversal
CVEs:CVE-2022-3162
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/kubernetes |
affected |
github.com |
github.com/kubernetes/kubernetes |
— |
Open SourcePoC exploitHIGH2022-11-30
DEBIAN-CVE-2022-4174
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitHIGH2022-11-29
Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4174
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitHIGH2022-11-29
CVEs:CVE-2022-4174
Open SourcePoC exploitCRITICAL2022-11-30
DEBIAN-CVE-2022-4192
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitCRITICAL2022-11-29
Use after free in Live Caption in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: Medium)
CVEs:CVE-2022-4192
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitHIGH2022-11-29
CVEs:CVE-2022-4192
Open SourcePoC exploitHIGH2022-11-01
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messa...
CVEs:CVE-2022-3509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf-java |
affected |
google |
— |
— |
| protobuf-javalite |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2022-11-01
Protobuf Java vulnerable to Uncontrolled Resource Consumption
CVEs:CVE-2022-3509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.google.protobuf:protobuf-java |
affected |
Maven |
com.google.protobuf:protobuf-java |
— |
| com.google.protobuf:protobuf-javalite |
affected |
Maven |
com.google.protobuf:protobuf-javalite |
— |
Open SourcePoC exploit2022-11-27
Updated golang packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Mageia:8 |
golang |
— |
Open SourcePoC exploit2022-11-25
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:22.03-LTS |
golang |
— |
| golang |
affected |
openEuler:20.03-LTS-SP1 |
golang |
— |
| golang |
affected |
openEuler:20.03-LTS-SP3 |
golang |
— |
Open SourcePoC exploitHIGH2022-11-02
CVE-2022-41716 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
GooglePoC exploitHIGH2022-11-02
CVEs:CVE-2022-41716
Open SourcePoC exploitHIGH2022-11-02
DEBIAN-CVE-2022-41716
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
GooglePoC exploitHIGH2022-11-01
Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious envir...
CVEs:CVE-2022-41716
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploit2022-11-01
Unsanitized NUL in environment variables on Windows in syscall and os/exec
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploitMEDIUM2022-11-07
In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges need...
CVEs:CVE-2022-20465
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2022-11-07
CVEs:CVE-2022-20465
Open SourcePoC exploitCRITICAL2022-11-01
DEBIAN-CVE-2022-3653
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploitHIGH2022-11-11
Protobuf Java vulnerable to Uncontrolled Resource Consumption
CVEs:CVE-2022-3510
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.google.protobuf:protobuf-java |
affected |
Maven |
com.google.protobuf:protobuf-java |
— |
| com.google.protobuf:protobuf-javalite |
affected |
Maven |
com.google.protobuf:protobuf-javalite |
— |
Open SourcePoC exploitHIGH2022-11-11
A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated e...
CVEs:CVE-2022-3510
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf-java |
affected |
google |
— |
— |
| protobuf-javalite |
affected |
google |
— |
— |
Open SourcePoC exploitMEDIUM2022-11-01
DEBIAN-CVE-2022-3317
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitMEDIUM2022-11-08
CVEs:CVE-2022-20572
Open SourcePoC exploitMEDIUM2022-11-08
In verity_target of dm-verity-target.c, there is a possible way to modify read-only files due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2022-20572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2022-11-07
CVEs:CVE-2022-20452
Open SourcePoC exploitHIGH2022-11-07
In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee...
CVEs:CVE-2022-20452
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS 30-63%HIGH2022-11-01
DEBIAN-CVE-2022-3652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4178
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4178
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4178
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3654
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-14
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
Open SourceCoalition ESS < 30%2022-11-10
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-09
DEBIAN-CVE-2022-3890
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-09
Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3890
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-09
CVEs:CVE-2022-3890
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3370
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3373
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-09
DEBIAN-CVE-2022-3446
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-09
DEBIAN-CVE-2022-3885
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-09
Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3885
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-09
CVEs:CVE-2022-3885
Open SourceCoalition ESS < 30%CRITICAL2022-11-09
DEBIAN-CVE-2022-3887
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-11-09
CVEs:CVE-2022-3887
GoogleCoalition ESS < 30%CRITICAL2022-11-09
Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3887
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-09
DEBIAN-CVE-2022-3889
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-11-09
CVEs:CVE-2022-3889
GoogleCoalition ESS < 30%HIGH2022-11-09
Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3889
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-30
DEBIAN-CVE-2022-4185
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-29
CVEs:CVE-2022-4185
GoogleCoalition ESS < 30%MEDIUM2022-11-29
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 108.0.5359.71 allowed a remote attacker to spoof the contents of the modal dialogue via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4185
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-09
DEBIAN-CVE-2022-3445
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-09
DEBIAN-CVE-2022-3886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-09
Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-09
CVEs:CVE-2022-3886
Open SourceCoalition ESS < 30%MEDIUM2022-11-01
DEBIAN-CVE-2022-3443
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-09
DEBIAN-CVE-2022-3888
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-09
Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-3888
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-09
CVEs:CVE-2022-3888
GoogleCoalition ESS < 30%CRITICAL2022-11-09
CVEs:CVE-2022-43549
GoogleCoalition ESS < 30%CRITICAL2022-11-09
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.
CVEs:CVE-2022-43549
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| veeam_backup_for_google_cloud |
affected |
veeam |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-01
DEBIAN-CVE-2022-3444
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3308
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4175
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Use after free in Camera Capture in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4175
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4175
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3304
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-09
DEBIAN-CVE-2022-3448
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-11-18
CVEs:CVE-2022-42461
GoogleCoalition ESS < 30%HIGH2022-11-18
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
CVEs:CVE-2022-42461
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_authenticator |
affected |
miniorange |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4181
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Use after free in Forms in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4181
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4181
Open SourceCoalition ESS < 30%HIGH2022-11-30
DEBIAN-CVE-2022-4190
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4193
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4190
GoogleCoalition ESS < 30%HIGH2022-11-29
Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4190
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4193
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Insufficient policy enforcement in File System API in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4193
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-09
DEBIAN-CVE-2022-3450
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-09
DEBIAN-CVE-2022-3447
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3307
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-01
DEBIAN-CVE-2022-3313
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4194
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4194
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Use after free in Accessibility in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4194
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3306
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4187
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3311
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-01
DEBIAN-CVE-2022-3315
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4184
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-29
CVEs:CVE-2022-4184
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4184
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3305
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41900 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess
CVEs:CVE-2022-41900
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess
CVEs:CVE-2022-41900
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool with illegal pooling_ratio. Attackers using Tensorflow can exploit the vulnerability. They can access heap memory which is not in t...
CVEs:CVE-2022-41900
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4176
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4176
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chr...
CVEs:CVE-2022-4176
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3309
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4191
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Use after free in Sign-In in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via profile destruction. (Chromium security severity: Medium)
CVEs:CVE-2022-4191
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4191
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3659
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-30
DEBIAN-CVE-2022-4188
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-29
CVEs:CVE-2022-4188
GoogleCoalition ESS < 30%MEDIUM2022-11-29
Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4188
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-01
DEBIAN-CVE-2022-3660
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-30
DEBIAN-CVE-2022-4182
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-29
CVEs:CVE-2022-4182
GoogleCoalition ESS < 30%MEDIUM2022-11-29
Inappropriate implementation in Fenced Frames in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass fenced frame restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4182
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-21
Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-21
Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41894 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. The reference kernel of the `CONV_3D_TRANSPOSE` TensorFlow Lite operator wrongly increments the data_ptr when adding the bias to the result. Instead of `data_ptr += num_channels;` it should be...
CVEs:CVE-2022-41894
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite
CVEs:CVE-2022-41894
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite
CVEs:CVE-2022-41894
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4183
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Insufficient policy enforcement in Popup Blocker in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4183
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-29
CVEs:CVE-2022-4183
Open SourceCoalition ESS < 30%MEDIUM2022-11-01
DEBIAN-CVE-2022-3316
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3310
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-18
CVEs:CVE-2022-45369
GoogleCoalition ESS < 30%MEDIUM2022-11-18
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.
CVEs:CVE-2022-45369
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| plugin_for_google_reviews |
affected |
richplugins |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-01
DEBIAN-CVE-2022-3661
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Segfault in `CompositeTensorVariantToComponents`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Segfault in `CompositeTensorVariantToComponents`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41909 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVariant` tensor will trigger a segfault in `tf.raw_ops.CompositeTensorVariantToComponents`. We have patched the issue in GitHub commits b...
CVEs:CVE-2022-41909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Segfault in `CompositeTensorVariantToComponents`
CVEs:CVE-2022-41909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Segfault in `CompositeTensorVariantToComponents`
CVEs:CVE-2022-41909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-28
CVEs:CVE-2022-3834
GoogleCoalition ESS < 30%CRITICAL2022-11-28
The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...
CVEs:CVE-2022-3834
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_forms |
affected |
google_forms_project |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4179
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4179
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Use after free in Audio in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CVEs:CVE-2022-4179
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3658
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4177
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4180
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install an extension to potentially exploit heap corruption via a crafted Chrome Extension and UI interaction. (Chromium security severity:...
CVEs:CVE-2022-4177
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4177
GoogleCoalition ESS < 30%HIGH2022-11-29
CVEs:CVE-2022-4180
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CVEs:CVE-2022-4180
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4195
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-29
CVEs:CVE-2022-4195
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass Safe Browsing warnings via a malicious file. (Chromium security severity: Medium)
CVEs:CVE-2022-4195
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
`CHECK` fail via inputs in `PyFunc`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
`CHECK` fail via inputs in `PyFunc`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41908 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`CHECK` fail via inputs in `PyFunc`
CVEs:CVE-2022-41908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. An input `token` that is not a UTF-8 bytestring will trigger a `CHECK` fail in `tf.raw_ops.PyFunc`. We have patched the issue in GitHub commit 9f03a9d3bafe902c1e6beb105b2f24172f238645. The fix...
CVEs:CVE-2022-41908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`CHECK` fail via inputs in `PyFunc`
CVEs:CVE-2022-41908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3318
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3655
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3314
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-09
Istio may allow identity impersonation if user has localhost access
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio/istio |
affected |
github.com |
github.com/istio/istio |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-09
Istio may allow identity impersonation if user has localhost access
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio/istio |
affected |
github.com |
github.com/istio/istio |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-09
Istio may allow identity impersonation if user has localhost access
CVEs:CVE-2022-39388
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio/istio |
affected |
github.com |
github.com/istio/istio |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-09
Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3, a user can impersonate any workload identity within the service mesh if they have localhost access to the Istiod control plane. Ve...
CVEs:CVE-2022-39388
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Overflow in `ResizeNearestNeighborGrad`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Overflow in `ResizeNearestNeighborGrad`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-21
Out of bounds write in grappler in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-21
Out of bounds write in grappler in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
`CHECK_EQ` fail via input in `SparseMatrixNNZ`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
`CHECK_EQ` fail via input in `SparseMatrixNNZ`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
`CHECK` fail via inputs in `SdcaOptimizer`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
`CHECK` fail via inputs in `SdcaOptimizer`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
`FractionalMaxPoolGrad` Heap out of bounds read
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
— |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
`FractionalMaxPoolGrad` Heap out of bounds read
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
`tf.raw_ops.Mfcc` crashes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
`tf.raw_ops.Mfcc` crashes
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
`MirrorPadGrad` heap out of bounds read
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
`MirrorPadGrad` heap out of bounds read
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
Overflow in `tf.keras.losses.poisson`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
Overflow in `tf.keras.losses.poisson`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-21
TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bound...
CVEs:CVE-2022-41902
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
Out of bounds write in grappler in Tensorflow
CVEs:CVE-2022-41902
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-21
Out of bounds write in grappler in Tensorflow
CVEs:CVE-2022-41902
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41907 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41901 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41897 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41898 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41899 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41895 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41896 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Overflow in `tf.keras.losses.poisson`
CVEs:CVE-2022-41887
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. `tf.keras.losses.poisson` receives a `y_pred` and `y_true` that are passed through `functor::mul` in `BinaryOp`. If the resulting dimensions overflow an `int32`, TensorFlow will crash due to a...
CVEs:CVE-2022-41887
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
Overflow in `tf.keras.losses.poisson`
CVEs:CVE-2022-41887
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`MirrorPadGrad` heap out of bounds read
CVEs:CVE-2022-41895
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. If `MirrorPadGrad` is given outsize input `paddings`, TensorFlow will give a heap OOB error. We have patched the issue in GitHub commit 717ca98d8c3bba348ff62281fdf38dcb5ea1ec92. The fix will b...
CVEs:CVE-2022-41895
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`MirrorPadGrad` heap out of bounds read
CVEs:CVE-2022-41895
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`tf.raw_ops.Mfcc` crashes
CVEs:CVE-2022-41896
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. If `ThreadUnsafeUnigramCandidateSampler` is given input `filterbank_channel_count` greater than the allowed max size, TensorFlow will crash. We have patched the issue in GitHub commit 39ec7eaf...
CVEs:CVE-2022-41896
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
`tf.raw_ops.Mfcc` crashes
CVEs:CVE-2022-41896
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
`FractionalMaxPoolGrad` Heap out of bounds read
CVEs:CVE-2022-41897
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`FractionalMaxPoolGrad` Heap out of bounds read
CVEs:CVE-2022-41897
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. If `FractionMaxPoolGrad` is given outsize inputs `row_pooling_sequence` and `col_pooling_sequence`, TensorFlow will crash. We have patched the issue in GitHub commit d71090c3e5ca325bdf4b02eb23...
CVEs:CVE-2022-41897
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`
CVEs:CVE-2022-41898
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. If `SparseFillEmptyRowsGrad` is given empty inputs, TensorFlow will crash. We have patched the issue in GitHub commit af4a6a3c8b95022c351edae94560acc61253a1b8. The fix will be included in Tens...
CVEs:CVE-2022-41898
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`
CVEs:CVE-2022-41898
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`CHECK` fail via inputs in `SdcaOptimizer`
CVEs:CVE-2022-41899
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`CHECK` fail via inputs in `SdcaOptimizer`
CVEs:CVE-2022-41899
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. Inputs `dense_features` or `example_state_data` not of rank 2 will trigger a `CHECK` fail in `SdcaOptimizer`. We have patched the issue in GitHub commit 80ff197d03db2a70c6a111f97dcdacad1b0babf...
CVEs:CVE-2022-41899
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`CHECK_EQ` fail via input in `SparseMatrixNNZ`
CVEs:CVE-2022-41901
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. An input `sparse_matrix` that is not a matrix with a shape with rank 0 will trigger a `CHECK` fail in `tf.raw_ops.SparseMatrixNNZ`. We have patched the issue in GitHub commit f856d02e5322821aa...
CVEs:CVE-2022-41901
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`CHECK_EQ` fail via input in `SparseMatrixNNZ`
CVEs:CVE-2022-41901
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Overflow in `ResizeNearestNeighborGrad`
CVEs:CVE-2022-41907
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. When `tf.raw_ops.ResizeNearestNeighborGrad` is given a large `size` input, it overflows. We have patched the issue in GitHub commit 00c821af032ba9e5f5fa3fe14690c8d28a657624. The fix will be in...
CVEs:CVE-2022-41907
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Overflow in `ResizeNearestNeighborGrad`
CVEs:CVE-2022-41907
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
`CHECK` fail in `BCast` overflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
`CHECK` fail in `BCast` overflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
FPE in `tf.image.generate_bounding_box_proposals`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
FPE in `tf.image.generate_bounding_box_proposals`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41893 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41890 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41888 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. When running on GPU, `tf.image.generate_bounding_box_proposals` receives a `scores` input that must be of rank 4 but is not checked. We have patched the issue in GitHub commit cf35502463a88ca7...
CVEs:CVE-2022-41888
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
FPE in `tf.image.generate_bounding_box_proposals`
CVEs:CVE-2022-41888
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
FPE in `tf.image.generate_bounding_box_proposals`
CVEs:CVE-2022-41888
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. If `BCast::ToShape` is given input larger than an `int32`, it will crash, despite being supposed to handle up to an `int64`. An example can be seen in `tf.experimental.numpy.outer` by passing ...
CVEs:CVE-2022-41890
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`CHECK` fail in `BCast` overflow
CVEs:CVE-2022-41890
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
`CHECK` fail in `BCast` overflow
CVEs:CVE-2022-41890
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`
CVEs:CVE-2022-41893
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListResize` is given a nonscalar value for input `size`, it results `CHECK` fail which can be used to trigger a denial of service attack. We have patched the issue in GitH...
CVEs:CVE-2022-41893
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`
CVEs:CVE-2022-41893
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
GoogleCoalition ESS < 30%HIGH2022-11-07
CVEs:CVE-2022-20445
Open SourceCoalition ESS < 30%HIGH2022-11-07
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2022-20445
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
Segfault in `tf.raw_ops.TensorListConcat`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
Segfault in `tf.raw_ops.TensorListConcat`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Overflow in `ImageProjectiveTransformV2`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Overflow in `ImageProjectiveTransformV2`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Overflow in `FusedResizeAndPadConv2D`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Overflow in `FusedResizeAndPadConv2D`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41891 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41886 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. When `tf.raw_ops.FusedResizeAndPadConv2D` is given a large tensor shape, it overflows. We have patched the issue in GitHub commit d66e1d568275e6a2947de97dca7a102a211e01ce. The fix will be incl...
CVEs:CVE-2022-41885
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Overflow in `FusedResizeAndPadConv2D`
CVEs:CVE-2022-41885
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Overflow in `FusedResizeAndPadConv2D`
CVEs:CVE-2022-41885
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Overflow in `ImageProjectiveTransformV2`
CVEs:CVE-2022-41886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. When `tf.raw_ops.ImageProjectiveTransformV2` is given a large output shape, it overflows. We have patched the issue in GitHub commit 8faa6ea692985dbe6ce10e1a3168e0bd60a723ba. The fix will be i...
CVEs:CVE-2022-41886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Overflow in `ImageProjectiveTransformV2`
CVEs:CVE-2022-41886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
Segfault in `tf.raw_ops.TensorListConcat`
CVEs:CVE-2022-41891
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Segfault in `tf.raw_ops.TensorListConcat`
CVEs:CVE-2022-41891
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListConcat` is given `element_shape=[]`, it results segmentation fault which can be used to trigger a denial of service attack. We have patched the issue in GitHub commit ...
CVEs:CVE-2022-41891
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-30
DEBIAN-CVE-2022-4186
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-29
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTML page. (Chromium security sever...
CVEs:CVE-2022-4186
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-29
CVEs:CVE-2022-4186
Open SourceCoalition ESS < 30%CRITICAL2022-11-09
DEBIAN-CVE-2022-3449
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-01
DEBIAN-CVE-2022-3657
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Segfault via invalid attributes in `pywrap_tfe_src.cc`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Segfault via invalid attributes in `pywrap_tfe_src.cc`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41889 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Segfault via invalid attributes in `pywrap_tfe_src.cc`
CVEs:CVE-2022-41889
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Segfault via invalid attributes in `pywrap_tfe_src.cc`
CVEs:CVE-2022-41889
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. If a list of quantized tensors is assigned to an attribute, the pywrap code fails to parse the tensor and returns a `nullptr`, which is not caught. An example can be seen in `tf.compat.v1.extr...
CVEs:CVE-2022-41889
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
Invalid char to bool conversion when printing a tensor
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
Invalid char to bool conversion when printing a tensor
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41911 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Invalid char to bool conversion when printing a tensor
CVEs:CVE-2022-41911
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. When printing a tensor, we get it's data as a `const char*` array (since that's the underlying storage) and then we typecast it to the element type. However, conversions from `char` to `bool` ...
CVEs:CVE-2022-41911
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
Invalid char to bool conversion when printing a tensor
CVEs:CVE-2022-41911
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-21
Heap overflow in `QuantizeAndDequantizeV2`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-21
Heap overflow in `QuantizeAndDequantizeV2`
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-21
TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bound...
CVEs:CVE-2022-41910
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Heap overflow in `QuantizeAndDequantizeV2`
CVEs:CVE-2022-41910
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-21
Heap overflow in `QuantizeAndDequantizeV2`
CVEs:CVE-2022-41910
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-22
Tensorflow vulnerable to Out-of-Bounds Read
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-22
Tensorflow vulnerable to Out-of-Bounds Read
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41880 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. When the `BaseCandidateSamplerOp` function receives a value in `true_classes` larger than `range_max`, a heap oob read occurs. We have patched the issue in GitHub commit b389f5c944cadfdfe599b3...
CVEs:CVE-2022-41880
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Tensorflow vulnerable to Out-of-Bounds Read
CVEs:CVE-2022-41880
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Tensorflow vulnerable to Out-of-Bounds Read
CVEs:CVE-2022-41880
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-30
DEBIAN-CVE-2022-4189
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-29
Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity:...
CVEs:CVE-2022-4189
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-29
CVEs:CVE-2022-4189
Open SourceCoalition ESS < 30%HIGH2022-11-21
Out of bounds segmentation fault due to unequal op inputs in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-21
Out of bounds segmentation fault due to unequal op inputs in Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-18
Out of bounds segmentation fault due to unequal op inputs in Tensorflow
CVEs:CVE-2022-41883
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Out of bounds segmentation fault due to unequal op inputs in Tensorflow
CVEs:CVE-2022-41883
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. When ops that have specified input sizes receive a differing number of inputs, the executor will crash. We have patched the issue in GitHub commit f5381e0e10b5a61344109c1b7c174c68110f7629. The...
CVEs:CVE-2022-41883
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Seg fault in `ndarray_tensor_bridge` due to zero and large inputs
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-21
Seg fault in `ndarray_tensor_bridge` due to zero and large inputs
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
CVE-2022-41884 affecting package tensorflow for versions less than 2.11.0-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:2 |
tensorflow |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Seg fault in `ndarray_tensor_bridge` due to zero and large inputs
CVEs:CVE-2022-41884
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-18
Seg fault in `ndarray_tensor_bridge` due to zero and large inputs
CVEs:CVE-2022-41884
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-11-18
TensorFlow is an open source platform for machine learning. If a numpy array is created with a shape such that one element is zero and the others sum to a large number, an error will be raised. We have patched the issue in GitHub commit 2b56169c16e375c...
CVEs:CVE-2022-41884
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-29
CVEs:CVE-2022-4955
GoogleCoalition ESS < 30%MEDIUM2022-11-29
Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4955
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-08
CVEs:CVE-2022-38137
GoogleCoalition ESS < 30%HIGH2022-11-08
Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.
CVEs:CVE-2022-38137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| analytify_-_google_analytics_dashboard |
affected |
analytify |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-07
In PAN_WriteBuf of pan_api.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2022-20447
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-07
CVEs:CVE-2022-20447
Open SourceCoalition ESS < 30%MEDIUM2022-11-01
DEBIAN-CVE-2022-3312
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-08
In typec, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. U...
CVEs:CVE-2022-32617
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32617
Open SourceCoalition ESS < 30%HIGH2022-11-08
In typec, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. U...
CVEs:CVE-2022-32618
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32618
GoogleCoalition ESS < 30%MEDIUM2022-11-07
CVEs:CVE-2022-20453
Open SourceCoalition ESS < 30%HIGH2022-11-07
In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is ne...
CVEs:CVE-2022-20453
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-07
In MMU_UnmapPages of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2021-1050
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-07
CVEs:CVE-2021-1050
GoogleCoalition ESS < 30%HIGH2022-11-01
ASB-A-243825200
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-01
ASB-A-244657985
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-01
ASB-A-244666286
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-01
ASB-A-244674480
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-08
In audio, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310571; Issue ID: ALPS07310...
CVEs:CVE-2022-32614
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32614
Open SourceCoalition ESS < 30%HIGH2022-11-08
In ccd, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326559; Issue ID: ALPS...
CVEs:CVE-2022-32615
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32615
Open SourceCoalition ESS < 30%HIGH2022-11-08
In isp, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341258; Issue ID: ALPS...
CVEs:CVE-2022-32616
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32616
Open SourceCoalition ESS < 30%HIGH2022-11-08
In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340373; Issue ID: ...
CVEs:CVE-2022-32611
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32611
Open SourceCoalition ESS < 30%HIGH2022-11-08
In gpu drm, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310704; Iss...
CVEs:CVE-2022-32603
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32603
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32607
Open SourceCoalition ESS < 30%HIGH2022-11-08
In aee, there is a possible use after free due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07202891; Issue ID: ALPS0...
CVEs:CVE-2022-32607
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-07
CVEs:CVE-2022-20454
Open SourceCoalition ESS < 30%HIGH2022-11-07
In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...
CVEs:CVE-2022-20454
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-07
CVEs:CVE-2022-20462
Open SourceCoalition ESS < 30%HIGH2022-11-07
In phNxpNciHal_write_unlocked of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2022-20462
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-08
In isp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07213898; Issue I...
CVEs:CVE-2022-32605
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32605
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-21778
Open SourceCoalition ESS < 30%MEDIUM2022-11-08
In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06382421; Issu...
CVEs:CVE-2022-21778
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-09
CVEs:CVE-2022-39880
Open SourceCoalition ESS < 30%HIGH2022-11-09
Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.
CVEs:CVE-2022-39880
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-07
CVEs:CVE-2022-32602
Open SourceCoalition ESS < 30%MEDIUM2022-11-07
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388790...
CVEs:CVE-2022-32602
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-01
ASB-A-245050053
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-07
In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVEs:CVE-2022-20457
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-07
CVEs:CVE-2022-20457
Open SourceCoalition ESS < 30%HIGH2022-11-17
In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2022-42533
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-17
CVEs:CVE-2022-42533
GoogleCoalition ESS < 30%HIGH2022-11-01
PUB-A-239415718
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-07
In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-20414
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-07
CVEs:CVE-2022-20414
Open SourceCoalition ESS < 30%HIGH2022-11-08
In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203410; Issue ID: ALPS07203410.
CVEs:CVE-2022-32609
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32609
Open SourceCoalition ESS < 30%HIGH2022-11-08
In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203476; Issue ID: ALPS07203476.
CVEs:CVE-2022-32610
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32610
GoogleCoalition ESS < 30%2022-11-01
ASB-A-238106223
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-01
ASB-A-244673210
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-01
ASB-A-245210875
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-11-07
CVEs:CVE-2022-20441
Open SourceCoalition ESS < 30%HIGH2022-11-07
In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution p...
CVEs:CVE-2022-20441
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-11-01
ASB-A-244109033
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-01
ASB-A-244684957
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-11-01
ASB-A-246482122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-07
In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0731913...
CVEs:CVE-2022-32601
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-07
CVEs:CVE-2022-32601
GoogleCoalition ESS < 30%HIGH2022-11-01
ASB-A-234038598
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-07
CVEs:CVE-2022-20448
Open SourceCoalition ESS < 30%MEDIUM2022-11-07
In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...
CVEs:CVE-2022-20448
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-11-07
CVEs:CVE-2022-20446
Open SourceCoalition ESS < 30%LOW2022-11-07
In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges...
CVEs:CVE-2022-20446
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-07
In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for...
CVEs:CVE-2022-20451
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-07
CVEs:CVE-2022-20451
Open SourceCoalition ESS < 30%HIGH2022-11-09
Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2022-39882
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-09
CVEs:CVE-2022-39882
GoogleCoalition ESS < 30%HIGH2022-11-07
CVEs:CVE-2021-39661
Open SourceCoalition ESS < 30%HIGH2022-11-07
In _PMRLogicalOffsetToPhysicalOffset of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVEs:CVE-2021-39661
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-01
ASB-A-246824784
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-08
In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203500; Issue ID: ALPS07203500.
CVEs:CVE-2022-32612
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32612
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32613
Open SourceCoalition ESS < 30%HIGH2022-11-08
In vcu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07206340; Issue ID: ALPS0720...
CVEs:CVE-2022-32613
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-08
CVEs:CVE-2022-32608
Open SourceCoalition ESS < 30%HIGH2022-11-08
In jpeg, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388753; Issue ID: ALPS07388753.
CVEs:CVE-2022-32608
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-17
CVEs:CVE-2022-20428
Open SourceCoalition ESS < 30%HIGH2022-11-17
In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...
CVEs:CVE-2022-20428
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-17
In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...
CVEs:CVE-2022-20427
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-17
CVEs:CVE-2022-20427
GoogleCoalition ESS < 30%MEDIUM2022-11-07
CVEs:CVE-2022-20459
Open SourceCoalition ESS < 30%HIGH2022-11-07
In (TBD) of (TBD), there is a possible way to redirect code execution due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2022-20459
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-07
In (TBD) mprot_unmap? of (TBD), there is a possible way to corrupt the memory mapping due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2022-20460
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-07
CVEs:CVE-2022-20460
GoogleCoalition ESS < 30%NONE2022-11-01
PUB-A-239555070
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-11-01
PUB-A-239555411
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-11-01
PUB-A-239556260
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%NONE2022-11-01
PUB-A-239557547
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-11-07
In multiple functions of many files, there is a possible obstruction of the user's ability to select a phone account due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction...
CVEs:CVE-2022-20426
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-11-07
CVEs:CVE-2022-20426
Open SourceCoalition ESS < 30%HIGH2022-11-07
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...
CVEs:CVE-2022-20450
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-11-07
CVEs:CVE-2022-20450
GoogleCoalition ESS < 30%CRITICAL2022-11-01
ASB-A-244683429
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-09
Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.
CVEs:CVE-2022-39884
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-11-09
CVEs:CVE-2022-39884
GoogleCoalition ESS < 30%HIGH2022-11-09
CVEs:CVE-2022-39883
Open SourceCoalition ESS < 30%HIGH2022-11-09
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
CVEs:CVE-2022-39883
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-11-09
Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.
CVEs:CVE-2022-39885
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-11-09
CVEs:CVE-2022-39885
Open SourceCoalition ESS < 30%MEDIUM2022-11-09
Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
CVEs:CVE-2022-39886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-11-09
CVEs:CVE-2022-39886
GoogleCoalition ESS < 30%LOW2022-11-09
CVEs:CVE-2022-39887
Open SourceCoalition ESS < 30%MEDIUM2022-11-09
Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.
CVEs:CVE-2022-39887
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-11-09
CVEs:CVE-2022-39879
Open SourceCoalition ESS < 30%MEDIUM2022-11-09
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
CVEs:CVE-2022-39879
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceAll remainingHIGH2022-11-21
`CHECK` failure in `SobolSample` via missing validation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceAll remainingHIGH2022-11-21
`CHECK` failure in `SobolSample` via missing validation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceAll remainingHIGH2022-11-21
`CHECK` fail in `TensorListScatter` and `TensorListScatterV2` in eager mode
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |
Open SourceAll remainingHIGH2022-11-21
`CHECK` fail in `TensorListScatter` and `TensorListScatterV2` in eager mode
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
PyPI |
tensorflow |
— |
| tensorflow-cpu |
affected |
PyPI |
tensorflow-cpu |
— |
| tensorflow-gpu |
affected |
PyPI |
tensorflow-gpu |
— |