CVE-2023-23376
CVEs:CVE-2023-23376
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 10 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2023-23376
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVEs:CVE-2023-23376
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVEs:CVE-2023-23376
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_21h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2023-23529
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execu...
CVEs:CVE-2023-23529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| safari | affected | apple | — | — |
CVEs:CVE-2023-23529
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2023-23529
CVEs:CVE-2023-21823
Windows Graphics Component Remote Code Execution Vulnerability
CVEs:CVE-2023-21823
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_21h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
Windows Graphics Component Remote Code Execution Vulnerability
CVEs:CVE-2023-21823
In several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2023-20937
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20937
ASB-A-257443051
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Apache Airflow Google Provider Improper Input Validation vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-google | affected | PyPI | apache-airflow-providers-google | — |
| apache-airflow-providers-google | affected | PyPI | apache-airflow-providers-google | — |
Apache Airflow Google Provider Improper Input Validation vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-google | affected | PyPI | apache-airflow-providers-google | — |
Apache Airflow Google Provider Improper Input Validation vulnerability
CVEs:CVE-2023-25692
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-google | affected | PyPI | apache-airflow-providers-google | — |
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
CVEs:CVE-2023-25692
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-google | affected | apache | — | — |
Apache Airflow Google Provider Improper Input Validation vulnerability
CVEs:CVE-2023-25692
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-google | affected | PyPI | apache-airflow-providers-google | — |
Apache Airflow Google Provider Improper Input Validation vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-google | affected | PyPI | apache-airflow-providers-google | — |
| apache-airflow-providers-google | affected | PyPI | apache-airflow-providers-google | — |
Apache Airflow Google Provider Improper Input Validation vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-google | affected | PyPI | apache-airflow-providers-google | — |
Apache Airflow Google Provider Improper Input Validation vulnerability
CVEs:CVE-2023-25691
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-google | affected | PyPI | apache-airflow-providers-google | — |
Apache Airflow Google Provider Improper Input Validation vulnerability
CVEs:CVE-2023-25691
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-google | affected | PyPI | apache-airflow-providers-google | — |
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
CVEs:CVE-2023-25691
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-google | affected | apache | — | — |
A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for...
CVEs:CVE-2023-25747
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firefox | affected | mozilla | — | — |
| Firefox for Android | affected | Mozilla | — | — |
| firefox_mobile | affected | mozilla | — | — |
CVEs:CVE-2023-25747
CVEs:CVE-2023-20938
In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257685302References: Upstream kernel
CVEs:CVE-2023-20938
In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2023-20938
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-257685302
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Red Hat Security Advisory: Red Hat Ceph Storage 5.3 Bug fix and security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ceph | affected | Red Hat:ceph_storage:5.3::el8 | ceph | — |
| ceph | affected | Red Hat:ceph_storage:5.3::el9 | ceph | — |
| cephadm | affected | Red Hat:ceph_storage:5.3::el9 | cephadm | — |
| cephadm | affected | Red Hat:ceph_storage:5.3::el8 | cephadm | — |
| ceph-base | affected | Red Hat:ceph_storage:5.3::el9 | ceph-base | — |
| ceph-base | affected | Red Hat:ceph_storage:5.3::el8 | ceph-base | — |
| ceph-base-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | ceph-base-debuginfo | — |
| ceph-base-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | ceph-base-debuginfo | — |
| ceph-common | affected | Red Hat:ceph_storage:5.3::el8 | ceph-common | — |
| ceph-common | affected | Red Hat:ceph_storage:5.3::el9 | ceph-common | — |
| ceph-common-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | ceph-common-debuginfo | — |
| ceph-common-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | ceph-common-debuginfo | — |
| ceph-debugsource | affected | Red Hat:ceph_storage:5.3::el8 | ceph-debugsource | — |
| ceph-debugsource | affected | Red Hat:ceph_storage:5.3::el9 | ceph-debugsource | — |
| cephfs-mirror | affected | Red Hat:ceph_storage:5.3::el8 | cephfs-mirror | — |
| cephfs-mirror-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | cephfs-mirror-debuginfo | — |
| cephfs-mirror-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | cephfs-mirror-debuginfo | — |
| cephfs-top | affected | Red Hat:ceph_storage:5.3::el9 | cephfs-top | — |
| cephfs-top | affected | Red Hat:ceph_storage:5.3::el8 | cephfs-top | — |
| ceph-fuse | affected | Red Hat:ceph_storage:5.3::el8 | ceph-fuse | — |
| ceph-fuse | affected | Red Hat:ceph_storage:5.3::el9 | ceph-fuse | — |
| ceph-fuse-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | ceph-fuse-debuginfo | — |
| ceph-fuse-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | ceph-fuse-debuginfo | — |
| ceph-grafana-dashboards | affected | Red Hat:ceph_storage:5.3::el8 | ceph-grafana-dashboards | — |
| ceph-immutable-object-cache | affected | Red Hat:ceph_storage:5.3::el8 | ceph-immutable-object-cache | — |
| ceph-immutable-object-cache | affected | Red Hat:ceph_storage:5.3::el9 | ceph-immutable-object-cache | — |
| ceph-immutable-object-cache-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | ceph-immutable-object-cache-debuginfo | — |
| ceph-immutable-object-cache-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | ceph-immutable-object-cache-debuginfo | — |
| ceph-mds | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mds | — |
| ceph-mds-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | ceph-mds-debuginfo | — |
| ceph-mds-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mds-debuginfo | — |
| ceph-mgr | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mgr | — |
| ceph-mgr-cephadm | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mgr-cephadm | — |
| ceph-mgr-dashboard | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mgr-dashboard | — |
| ceph-mgr-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | ceph-mgr-debuginfo | — |
| ceph-mgr-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mgr-debuginfo | — |
| ceph-mgr-diskprediction-local | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mgr-diskprediction-local | — |
| ceph-mgr-k8sevents | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mgr-k8sevents | — |
| ceph-mgr-modules-core | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mgr-modules-core | — |
| ceph-mgr-rook | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mgr-rook | — |
| ceph-mib | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mib | — |
| ceph-mib | affected | Red Hat:ceph_storage:5.3::el9 | ceph-mib | — |
| ceph-mon | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mon | — |
| ceph-mon-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | ceph-mon-debuginfo | — |
| ceph-mon-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | ceph-mon-debuginfo | — |
| ceph-osd | affected | Red Hat:ceph_storage:5.3::el8 | ceph-osd | — |
| ceph-osd-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | ceph-osd-debuginfo | — |
| ceph-osd-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | ceph-osd-debuginfo | — |
| ceph-prometheus-alerts | affected | Red Hat:ceph_storage:5.3::el8 | ceph-prometheus-alerts | — |
| ceph-radosgw | affected | Red Hat:ceph_storage:5.3::el8 | ceph-radosgw | — |
| ceph-radosgw-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | ceph-radosgw-debuginfo | — |
| ceph-radosgw-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | ceph-radosgw-debuginfo | — |
| ceph-resource-agents | affected | Red Hat:ceph_storage:5.3::el8 | ceph-resource-agents | — |
| ceph-resource-agents | affected | Red Hat:ceph_storage:5.3::el9 | ceph-resource-agents | — |
| ceph-selinux | affected | Red Hat:ceph_storage:5.3::el8 | ceph-selinux | — |
| ceph-selinux | affected | Red Hat:ceph_storage:5.3::el9 | ceph-selinux | — |
| ceph-test | affected | Red Hat:ceph_storage:5.3::el8 | ceph-test | — |
| ceph-test-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | ceph-test-debuginfo | — |
| ceph-test-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | ceph-test-debuginfo | — |
| libcephfs2 | affected | Red Hat:ceph_storage:5.3::el9 | libcephfs2 | — |
| libcephfs2 | affected | Red Hat:ceph_storage:5.3::el8 | libcephfs2 | — |
| libcephfs2-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | libcephfs2-debuginfo | — |
| libcephfs2-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | libcephfs2-debuginfo | — |
| libcephfs-devel | affected | Red Hat:ceph_storage:5.3::el9 | libcephfs-devel | — |
| libcephfs-devel | affected | Red Hat:ceph_storage:5.3::el8 | libcephfs-devel | — |
| libcephsqlite | affected | Red Hat:ceph_storage:5.3::el8 | libcephsqlite | — |
| libcephsqlite-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | libcephsqlite-debuginfo | — |
| libcephsqlite-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | libcephsqlite-debuginfo | — |
| librados2 | affected | Red Hat:ceph_storage:5.3::el8 | librados2 | — |
| librados2 | affected | Red Hat:ceph_storage:5.3::el9 | librados2 | — |
| librados2-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | librados2-debuginfo | — |
| librados2-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | librados2-debuginfo | — |
| librados-devel | affected | Red Hat:ceph_storage:5.3::el8 | librados-devel | — |
| librados-devel | affected | Red Hat:ceph_storage:5.3::el9 | librados-devel | — |
| librados-devel-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | librados-devel-debuginfo | — |
| librados-devel-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | librados-devel-debuginfo | — |
| libradospp-devel | affected | Red Hat:ceph_storage:5.3::el8 | libradospp-devel | — |
| libradospp-devel | affected | Red Hat:ceph_storage:5.3::el9 | libradospp-devel | — |
| libradosstriper1 | affected | Red Hat:ceph_storage:5.3::el9 | libradosstriper1 | — |
| libradosstriper1 | affected | Red Hat:ceph_storage:5.3::el8 | libradosstriper1 | — |
| libradosstriper1-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | libradosstriper1-debuginfo | — |
| libradosstriper1-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | libradosstriper1-debuginfo | — |
| librbd1 | affected | Red Hat:ceph_storage:5.3::el9 | librbd1 | — |
| librbd1 | affected | Red Hat:ceph_storage:5.3::el8 | librbd1 | — |
| librbd1-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | librbd1-debuginfo | — |
| librbd1-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | librbd1-debuginfo | — |
| librbd-devel | affected | Red Hat:ceph_storage:5.3::el9 | librbd-devel | — |
| librbd-devel | affected | Red Hat:ceph_storage:5.3::el8 | librbd-devel | — |
| librgw2 | affected | Red Hat:ceph_storage:5.3::el9 | librgw2 | — |
| librgw2 | affected | Red Hat:ceph_storage:5.3::el8 | librgw2 | — |
| librgw2-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | librgw2-debuginfo | — |
| librgw2-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | librgw2-debuginfo | — |
| librgw-devel | affected | Red Hat:ceph_storage:5.3::el8 | librgw-devel | — |
| librgw-devel | affected | Red Hat:ceph_storage:5.3::el9 | librgw-devel | — |
| python3-ceph-argparse | affected | Red Hat:ceph_storage:5.3::el9 | python3-ceph-argparse | — |
| python3-ceph-argparse | affected | Red Hat:ceph_storage:5.3::el8 | python3-ceph-argparse | — |
| python3-ceph-common | affected | Red Hat:ceph_storage:5.3::el8 | python3-ceph-common | — |
| python3-ceph-common | affected | Red Hat:ceph_storage:5.3::el9 | python3-ceph-common | — |
| python3-cephfs | affected | Red Hat:ceph_storage:5.3::el8 | python3-cephfs | — |
| python3-cephfs | affected | Red Hat:ceph_storage:5.3::el9 | python3-cephfs | — |
| python3-cephfs-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | python3-cephfs-debuginfo | — |
| python3-cephfs-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | python3-cephfs-debuginfo | — |
| python3-rados | affected | Red Hat:ceph_storage:5.3::el9 | python3-rados | — |
| python3-rados | affected | Red Hat:ceph_storage:5.3::el8 | python3-rados | — |
| python3-rados-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | python3-rados-debuginfo | — |
| python3-rados-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | python3-rados-debuginfo | — |
| python3-rbd | affected | Red Hat:ceph_storage:5.3::el8 | python3-rbd | — |
| python3-rbd | affected | Red Hat:ceph_storage:5.3::el9 | python3-rbd | — |
| python3-rbd-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | python3-rbd-debuginfo | — |
| python3-rbd-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | python3-rbd-debuginfo | — |
| python3-rgw | affected | Red Hat:ceph_storage:5.3::el9 | python3-rgw | — |
| python3-rgw | affected | Red Hat:ceph_storage:5.3::el8 | python3-rgw | — |
| python3-rgw-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | python3-rgw-debuginfo | — |
| python3-rgw-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | python3-rgw-debuginfo | — |
| rbd-fuse-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | rbd-fuse-debuginfo | — |
| rbd-fuse-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | rbd-fuse-debuginfo | — |
| rbd-mirror | affected | Red Hat:ceph_storage:5.3::el8 | rbd-mirror | — |
| rbd-mirror-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | rbd-mirror-debuginfo | — |
| rbd-mirror-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | rbd-mirror-debuginfo | — |
| rbd-nbd | affected | Red Hat:ceph_storage:5.3::el8 | rbd-nbd | — |
| rbd-nbd | affected | Red Hat:ceph_storage:5.3::el9 | rbd-nbd | — |
| rbd-nbd-debuginfo | affected | Red Hat:ceph_storage:5.3::el8 | rbd-nbd-debuginfo | — |
| rbd-nbd-debuginfo | affected | Red Hat:ceph_storage:5.3::el9 | rbd-nbd-debuginfo | — |
ASB-A-262503737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:22.03-LTS-SP1 | golang | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:22.03-LTS | golang | — |
CVE-2022-41723 affecting package golang for versions less than 1.19.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-41723 affecting package application-gateway-kubernetes-ingress for versions less than 1.7.2-2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| application-gateway-kubernetes-ingress | affected | Azure Linux:3 | application-gateway-kubernetes-ingress | — |
CVE-2022-41723 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-41723 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
DEBIAN-CVE-2022-41723
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
| golang-golang-x-net | affected | Debian:11 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:12 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:13 | golang-golang-x-net | — |
| golang-golang-x-net | affected | Debian:14 | golang-golang-x-net | — |
golang.org/x/net vulnerable to Uncontrolled Resource Consumption
CVEs:CVE-2022-41723
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net vulnerable to Uncontrolled Resource Consumption
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cadvisor | affected | wolfi | cadvisor | — |
| cadvisor | affected | chainguard | cadvisor | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| falco | affected | wolfi | falco | — |
| falco | affected | chainguard | falco | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| go-1.19 | affected | wolfi | go-1.19 | — |
| go-1.19 | affected | chainguard | go-1.19 | — |
| go-1.20 | affected | chainguard | go-1.20 | — |
| go-1.20 | affected | wolfi | go-1.20 | — |
| go-fips-1.20 | affected | chainguard | go-fips-1.20 | — |
| go-fips-1.20 | affected | wolfi | go-fips-1.20 | — |
| grpcurl | affected | chainguard | grpcurl | — |
| grpcurl | affected | wolfi | grpcurl | — |
| hey | affected | wolfi | hey | — |
| hey | affected | chainguard | hey | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| kyverno-1.8 | affected | chainguard | kyverno-1.8 | — |
| oauth2-proxy | affected | wolfi | oauth2-proxy | — |
| oauth2-proxy | affected | chainguard | oauth2-proxy | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-stackdriver-exporter | affected | wolfi | prometheus-stackdriver-exporter | — |
| restic | affected | wolfi | restic | — |
| restic | affected | chainguard | restic | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| wireguard-go | affected | wolfi | wireguard-go | — |
| wireguard-go | affected | chainguard | wireguard-go | — |
| x/net | affected | golang.org | — | — |
| x/net | affected | golang.org | golang.org/x/net | — |
golang.org/x/net vulnerable to Uncontrolled Resource Consumption
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/net | affected | golang.org | golang.org/x/net | — |
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
CVEs:CVE-2022-41723
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
| hpack | affected | golang | — | — |
| http2 | affected | golang | — | — |
Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cadvisor | affected | wolfi | cadvisor | — |
| cadvisor | affected | chainguard | cadvisor | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| go-1.20 | affected | wolfi | go-1.20 | — |
| go-1.20 | affected | chainguard | go-1.20 | — |
| grpcurl | affected | wolfi | grpcurl | — |
| grpcurl | affected | chainguard | grpcurl | — |
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| oauth2-proxy | affected | wolfi | oauth2-proxy | — |
| oauth2-proxy | affected | chainguard | oauth2-proxy | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| restic | affected | wolfi | restic | — |
| restic | affected | chainguard | restic | — |
| stdlib | affected | Go | stdlib | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| wireguard-go | affected | chainguard | wireguard-go | — |
| wireguard-go | affected | wolfi | wireguard-go | — |
| x/net | affected | golang.org | golang.org/x/net | — |
CVE-2022-43552 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-23916 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2022-41722 affecting package msft-golang for versions less than 1.19.8-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| msft-golang | affected | Azure Linux:2 | msft-golang | — |
CVE-2022-41722 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-41722 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-41722 affecting package golang for versions less than 1.22.7-2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVEs:CVE-2022-41722
DEBIAN-CVE-2022-41722
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an abso...
CVEs:CVE-2022-41722
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
Path traversal on Windows in path/filepath
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| stdlib | affected | Go | stdlib | — |
CVE-2022-41725 affecting package golang for versions less than 1.19.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-41725 affecting package msft-golang for versions less than 1.19.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| msft-golang | affected | Azure Linux:2 | msft-golang | — |
CVE-2022-41725 affecting package golang for versions less than 1.19.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVE-2022-41725 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-41725 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-41725 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVEs:CVE-2022-41725
DEBIAN-CVE-2022-41725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsin...
CVEs:CVE-2022-41725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
Excessive resource consumption in mime/multipart
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| stdlib | affected | Go | stdlib | — |
CVEs:CVE-2023-21720
Microsoft Edge (Chromium-based) Tampering Vulnerability
CVEs:CVE-2023-21720
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVE-2022-41724 affecting package golang for versions less than 1.19.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-41724 affecting package msft-golang for versions less than 1.19.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| msft-golang | affected | Azure Linux:2 | msft-golang | — |
CVE-2022-41724 affecting package golang for versions less than 1.19.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVE-2022-41724 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-41724 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2022-41724 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVEs:CVE-2022-41724
DEBIAN-CVE-2022-41724
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS ...
CVEs:CVE-2022-41724
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
Panic on large handshake records in crypto/tls
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| stdlib | affected | Go | stdlib | — |
CVE-2023-23915 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-23914 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| client-go | affected | k8s.io | k8s.io/client-go | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| client-go | affected | k8s.io | k8s.io/client-go | — |
| gostatsd | affected | wolfi | gostatsd | — |
| gostatsd | affected | chainguard | gostatsd | — |
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| newrelic-nri-statsd | affected | wolfi | newrelic-nri-statsd | — |
| newrelic-nri-statsd | affected | chainguard | newrelic-nri-statsd | — |
| nodetaint | affected | chainguard | nodetaint | — |
| nodetaint | affected | wolfi | nodetaint | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator | affected | wolfi | spark-operator | — |
ASB-A-248354871
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Kubernetes Sensitive Information leak via Log File
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
| kubernetes/kubernetes | affected | github.com | github.com/kubernetes/kubernetes | — |
| nodetaint | affected | wolfi | nodetaint | — |
| nodetaint | affected | chainguard | nodetaint | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator | affected | wolfi | spark-operator | — |
Kubernetes Sensitive Information leak via Log File
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes/kubernetes | affected | github.com | github.com/kubernetes/kubernetes | — |
ASB-A-245869446
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2023-20944
In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-20944
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not ne...
CVEs:CVE-2023-20943
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20943
In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2023-20933
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20933
golang-github-opencontainers-selinux - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-opencontainers-selinux | affected | Debian:10 | golang-github-opencontainers-selinux | — |
Red Hat Bug Fix Advisory: OpenShift Container Platform 4.12.2 packages update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| atomic-openshift-service-idler | affected | Red Hat:openshift:4.12::el8 | atomic-openshift-service-idler | — |
| bpftool | affected | Red Hat:openshift:4.12::el8 | bpftool | — |
| bpftool-debuginfo | affected | Red Hat:openshift:4.12::el8 | bpftool-debuginfo | — |
| buildah | affected | Red Hat:openshift:4.12::el8 | buildah | — |
| buildah-debuginfo | affected | Red Hat:openshift:4.12::el8 | buildah-debuginfo | — |
| buildah-debugsource | affected | Red Hat:openshift:4.12::el8 | buildah-debugsource | — |
| buildah-tests | affected | Red Hat:openshift:4.12::el8 | buildah-tests | — |
| buildah-tests-debuginfo | affected | Red Hat:openshift:4.12::el8 | buildah-tests-debuginfo | — |
| containers-common | affected | Red Hat:openshift:4.12::el8 | containers-common | — |
| kernel | affected | Red Hat:openshift:4.12::el8 | kernel | — |
| kernel-core | affected | Red Hat:openshift:4.12::el8 | kernel-core | — |
| kernel-cross-headers | affected | Red Hat:openshift:4.12::el8 | kernel-cross-headers | — |
| kernel-debug | affected | Red Hat:openshift:4.12::el8 | kernel-debug | — |
| kernel-debug-core | affected | Red Hat:openshift:4.12::el8 | kernel-debug-core | — |
| kernel-debug-debuginfo | affected | Red Hat:openshift:4.12::el8 | kernel-debug-debuginfo | — |
| kernel-debug-devel | affected | Red Hat:openshift:4.12::el8 | kernel-debug-devel | — |
| kernel-debuginfo | affected | Red Hat:openshift:4.12::el8 | kernel-debuginfo | — |
| kernel-debuginfo-common-aarch64 | affected | Red Hat:openshift:4.12::el8 | kernel-debuginfo-common-aarch64 | — |
| kernel-debuginfo-common-ppc64le | affected | Red Hat:openshift:4.12::el8 | kernel-debuginfo-common-ppc64le | — |
| kernel-debuginfo-common-s390x | affected | Red Hat:openshift:4.12::el8 | kernel-debuginfo-common-s390x | — |
| kernel-debuginfo-common-x86_64 | affected | Red Hat:openshift:4.12::el8 | kernel-debuginfo-common-x86_64 | — |
| kernel-debug-modules | affected | Red Hat:openshift:4.12::el8 | kernel-debug-modules | — |
| kernel-debug-modules-extra | affected | Red Hat:openshift:4.12::el8 | kernel-debug-modules-extra | — |
| kernel-debug-modules-internal | affected | Red Hat:openshift:4.12::el8 | kernel-debug-modules-internal | — |
| kernel-devel | affected | Red Hat:openshift:4.12::el8 | kernel-devel | — |
| kernel-doc | affected | Red Hat:openshift:4.12::el8 | kernel-doc | — |
| kernel-headers | affected | Red Hat:openshift:4.12::el8 | kernel-headers | — |
| kernel-ipaclones-internal | affected | Red Hat:openshift:4.12::el8 | kernel-ipaclones-internal | — |
| kernel-modules | affected | Red Hat:openshift:4.12::el8 | kernel-modules | — |
| kernel-modules-extra | affected | Red Hat:openshift:4.12::el8 | kernel-modules-extra | — |
| kernel-modules-internal | affected | Red Hat:openshift:4.12::el8 | kernel-modules-internal | — |
| kernel-rt | affected | Red Hat:openshift:4.12::el8 | kernel-rt | — |
| kernel-rt-core | affected | Red Hat:openshift:4.12::el8 | kernel-rt-core | — |
| kernel-rt-debug | affected | Red Hat:openshift:4.12::el8 | kernel-rt-debug | — |
| kernel-rt-debug-core | affected | Red Hat:openshift:4.12::el8 | kernel-rt-debug-core | — |
| kernel-rt-debug-debuginfo | affected | Red Hat:openshift:4.12::el8 | kernel-rt-debug-debuginfo | — |
| kernel-rt-debug-devel | affected | Red Hat:openshift:4.12::el8 | kernel-rt-debug-devel | — |
| kernel-rt-debuginfo | affected | Red Hat:openshift:4.12::el8 | kernel-rt-debuginfo | — |
| kernel-rt-debuginfo-common-x86_64 | affected | Red Hat:openshift:4.12::el8 | kernel-rt-debuginfo-common-x86_64 | — |
| kernel-rt-debug-kvm | affected | Red Hat:openshift:4.12::el8 | kernel-rt-debug-kvm | — |
| kernel-rt-debug-modules | affected | Red Hat:openshift:4.12::el8 | kernel-rt-debug-modules | — |
| kernel-rt-debug-modules-extra | affected | Red Hat:openshift:4.12::el8 | kernel-rt-debug-modules-extra | — |
| kernel-rt-debug-modules-internal | affected | Red Hat:openshift:4.12::el8 | kernel-rt-debug-modules-internal | — |
| kernel-rt-devel | affected | Red Hat:openshift:4.12::el8 | kernel-rt-devel | — |
| kernel-rt-kvm | affected | Red Hat:openshift:4.12::el8 | kernel-rt-kvm | — |
| kernel-rt-modules | affected | Red Hat:openshift:4.12::el8 | kernel-rt-modules | — |
| kernel-rt-modules-extra | affected | Red Hat:openshift:4.12::el8 | kernel-rt-modules-extra | — |
| kernel-rt-modules-internal | affected | Red Hat:openshift:4.12::el8 | kernel-rt-modules-internal | — |
| kernel-rt-selftests-internal | affected | Red Hat:openshift:4.12::el8 | kernel-rt-selftests-internal | — |
| kernel-selftests-internal | affected | Red Hat:openshift:4.12::el8 | kernel-selftests-internal | — |
| kernel-tools | affected | Red Hat:openshift:4.12::el8 | kernel-tools | — |
| kernel-tools-debuginfo | affected | Red Hat:openshift:4.12::el8 | kernel-tools-debuginfo | — |
| kernel-tools-libs | affected | Red Hat:openshift:4.12::el8 | kernel-tools-libs | — |
| kernel-tools-libs-devel | affected | Red Hat:openshift:4.12::el8 | kernel-tools-libs-devel | — |
| kernel-zfcpdump | affected | Red Hat:openshift:4.12::el8 | kernel-zfcpdump | — |
| kernel-zfcpdump-core | affected | Red Hat:openshift:4.12::el8 | kernel-zfcpdump-core | — |
| kernel-zfcpdump-debuginfo | affected | Red Hat:openshift:4.12::el8 | kernel-zfcpdump-debuginfo | — |
| kernel-zfcpdump-devel | affected | Red Hat:openshift:4.12::el8 | kernel-zfcpdump-devel | — |
| kernel-zfcpdump-modules | affected | Red Hat:openshift:4.12::el8 | kernel-zfcpdump-modules | — |
| kernel-zfcpdump-modules-extra | affected | Red Hat:openshift:4.12::el8 | kernel-zfcpdump-modules-extra | — |
| kernel-zfcpdump-modules-internal | affected | Red Hat:openshift:4.12::el8 | kernel-zfcpdump-modules-internal | — |
| openshift-clients | affected | Red Hat:openshift:4.12::el9 | openshift-clients | — |
| openshift-clients | affected | Red Hat:openshift:4.12::el8 | openshift-clients | — |
| openshift-clients-redistributable | affected | Red Hat:openshift:4.12::el9 | openshift-clients-redistributable | — |
| openshift-clients-redistributable | affected | Red Hat:openshift:4.12::el8 | openshift-clients-redistributable | — |
| openshift-kuryr | affected | Red Hat:openshift:4.12::el8 | openshift-kuryr | — |
| openshift-kuryr-cni | affected | Red Hat:openshift:4.12::el8 | openshift-kuryr-cni | — |
| openshift-kuryr-common | affected | Red Hat:openshift:4.12::el8 | openshift-kuryr-common | — |
| openshift-kuryr-controller | affected | Red Hat:openshift:4.12::el8 | openshift-kuryr-controller | — |
| ovn22.12 | affected | Red Hat:openshift:4.12::el8 | ovn22.12 | — |
| ovn22.12-central | affected | Red Hat:openshift:4.12::el8 | ovn22.12-central | — |
| ovn22.12-central-debuginfo | affected | Red Hat:openshift:4.12::el8 | ovn22.12-central-debuginfo | — |
| ovn22.12-debuginfo | affected | Red Hat:openshift:4.12::el8 | ovn22.12-debuginfo | — |
| ovn22.12-debugsource | affected | Red Hat:openshift:4.12::el8 | ovn22.12-debugsource | — |
| ovn22.12-host | affected | Red Hat:openshift:4.12::el8 | ovn22.12-host | — |
| ovn22.12-host-debuginfo | affected | Red Hat:openshift:4.12::el8 | ovn22.12-host-debuginfo | — |
| ovn22.12-vtep | affected | Red Hat:openshift:4.12::el8 | ovn22.12-vtep | — |
| ovn22.12-vtep-debuginfo | affected | Red Hat:openshift:4.12::el8 | ovn22.12-vtep-debuginfo | — |
| perf | affected | Red Hat:openshift:4.12::el8 | perf | — |
| perf-debuginfo | affected | Red Hat:openshift:4.12::el8 | perf-debuginfo | — |
| python3-kuryr-kubernetes | affected | Red Hat:openshift:4.12::el8 | python3-kuryr-kubernetes | — |
| python3-perf | affected | Red Hat:openshift:4.12::el8 | python3-perf | — |
| python3-perf-debuginfo | affected | Red Hat:openshift:4.12::el8 | python3-perf-debuginfo | — |
| runc | affected | Red Hat:openshift:4.12::el8 | runc | — |
| runc-debuginfo | affected | Red Hat:openshift:4.12::el8 | runc-debuginfo | — |
| runc-debugsource | affected | Red Hat:openshift:4.12::el8 | runc-debugsource | — |
| skopeo | affected | Red Hat:openshift:4.12::el8 | skopeo | — |
| skopeo | affected | Red Hat:openshift:4.12::el9 | skopeo | — |
| skopeo-debuginfo | affected | Red Hat:openshift:4.12::el8 | skopeo-debuginfo | — |
| skopeo-debuginfo | affected | Red Hat:openshift:4.12::el9 | skopeo-debuginfo | — |
| skopeo-debugsource | affected | Red Hat:openshift:4.12::el8 | skopeo-debugsource | — |
| skopeo-debugsource | affected | Red Hat:openshift:4.12::el9 | skopeo-debugsource | — |
| skopeo-tests | affected | Red Hat:openshift:4.12::el9 | skopeo-tests | — |
| skopeo-tests | affected | Red Hat:openshift:4.12::el8 | skopeo-tests | — |
Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache/age/drivers/golang | affected | github.com | github.com/apache/age/drivers/golang | — |
| apache/age/drivers/golang | affected | github.com | github.com/apache/age/drivers/golang | — |
| apache-age-python | affected | PyPI | apache-age-python | — |
| apache-age-python | affected | PyPI | apache-age-python | — |
| github.com/apache/age/drivers/golang | affected | Go | github.com/apache/age/drivers/golang | — |
Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache/age/drivers/golang | affected | github.com | github.com/apache/age/drivers/golang | — |
| apache-age-python | affected | PyPI | apache-age-python | — |
Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
CVEs:CVE-2022-45786
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache/age/drivers/golang | affected | github.com | github.com/apache/age/drivers/golang | — |
| apache-age-python | affected | PyPI | apache-age-python | — |
Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
CVEs:CVE-2022-45786
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache/age/drivers/golang | affected | github.com | github.com/apache/age/drivers/golang | — |
| apache-age-python | affected | PyPI | apache-age-python | — |
There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for PostgreSQL 12, all versions up-to-and-including 1.1.0, when using those drivers. The fix is to update to the ...
CVEs:CVE-2022-45786
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| age | affected | apache | — | — |
The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
CVEs:CVE-2023-0259
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| wp_google_review_slider | affected | ljapps | — | — |
CVEs:CVE-2023-0259
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
CVEs:CVE-2023-0704
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-0704
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0704
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-0699
Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)
CVEs:CVE-2023-0699
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0699
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-0701
Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interaction . (Chromium security severity: Medium)
CVEs:CVE-2023-0701
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0701
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-0705
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-0705
DEBIAN-CVE-2023-0705
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2023-21794
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2023-21794
CVEs:CVE-2023-0702
Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Me...
CVEs:CVE-2023-0702
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0702
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)
CVEs:CVE-2023-0703
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-0703
DEBIAN-CVE-2023-0703
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-0700
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-0700
DEBIAN-CVE-2023-0700
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
CVEs:CVE-2023-0930
Heap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-0930
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0930
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-0698
Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-0698
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0698
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
CVEs:CVE-2023-0931
Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-0931
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0931
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-1065
This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues. It does not expose the user of the integration to any direct security r...
CVEs:CVE-2023-1065
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes_monitor | affected | snyk | — | — |
CVEs:CVE-2023-0933
Integer overflow in PDF in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
CVEs:CVE-2023-0933
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0933
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-0928
Use after free in SwiftShader in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-0928
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-0941
Use after free in Prompts in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVEs:CVE-2023-0941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0928
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
DEBIAN-CVE-2023-0941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
ASB-A-245928838
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2023-0929
Use after free in Vulkan in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-0929
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0929
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-0696
Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-0696
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0696
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Web Payments API in Google Chrome on Android prior to 110.0.5481.177 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-0927
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-0927
CVEs:CVE-2023-0932
Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever...
CVEs:CVE-2023-0932
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0927
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2023-0932
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-0697
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-0697
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-0697
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
textAngular Cross-site Scripting vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| textangular | affected | npm | textangular | — |
textAngular Cross-site Scripting vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| textangular | affected | npm | textangular | — |
textAngular Cross-site Scripting vulnerability
CVEs:CVE-2021-32854
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| textangular | affected | npm | textangular | — |
textAngular Cross-site Scripting vulnerability
CVEs:CVE-2021-32854
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| textangular | affected | npm | textangular | — |
textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There a...
CVEs:CVE-2021-32854
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| textangular | affected | textangular | — | — |
In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interac...
CVEs:CVE-2023-20946
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20946
DEBIAN-CVE-2023-0475
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-hashicorp-go-getter | affected | Debian:11 | golang-github-hashicorp-go-getter | — |
| golang-github-hashicorp-go-getter | affected | Debian:12 | golang-github-hashicorp-go-getter | — |
CVEs:CVE-2023-20948
In dropFramesUntilIframe of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2023-20948
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-245406696
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
DEBIAN-CVE-2022-41727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-golang-x-image | affected | Debian:11 | golang-golang-x-image | — |
| golang-golang-x-image | affected | Debian:12 | golang-golang-x-image | — |
| golang-golang-x-image | affected | Debian:13 | golang-golang-x-image | — |
| golang-golang-x-image | affected | Debian:14 | golang-golang-x-image | — |
Uncontrolled Resource Consumption in golang.org/x/image
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/image | affected | golang.org | golang.org/x/image | — |
Uncontrolled Resource Consumption in golang.org/x/image
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/image | affected | golang.org | golang.org/x/image | — |
Uncontrolled Resource Consumption in golang.org/x/image
CVEs:CVE-2022-41727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/image | affected | golang.org | golang.org/x/image | — |
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
CVEs:CVE-2022-41727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| fedora | affected | fedoraproject | — | — |
| image | affected | golang | — | — |
| tiff | affected | golang | — | — |
Denial of service via crafted TIFF image in golang.org/x/image/tiff
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/image | affected | golang.org | golang.org/x/image | — |
In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
CVEs:CVE-2022-47339
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47339
ASB-A-262503731
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-21427
Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition.
CVEs:CVE-2023-21427
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.
CVEs:CVE-2023-21419
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21419
Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.
CVEs:CVE-2023-21438
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21438
Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.
CVEs:CVE-2023-21420
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21420
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.
CVEs:CVE-2023-21445
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21445
CVEs:CVE-2023-21439
Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2023-21439
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21435
Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.
CVEs:CVE-2023-21435
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.
CVEs:CVE-2023-21430
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21430
CVEs:CVE-2023-21102
Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.
CVEs:CVE-2023-21440
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21440
In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-260821414References: Upstream kernel
CVEs:CVE-2023-21102
In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...
CVEs:CVE-2023-21102
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20945
In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2023-20945
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21446
Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles.
CVEs:CVE-2023-21446
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21428
Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.
CVEs:CVE-2023-21428
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21451
A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.
CVEs:CVE-2023-21451
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2022-47451
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47451
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21426
Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.
CVEs:CVE-2023-21426
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21421
Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.
CVEs:CVE-2023-21421
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
In ccd, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS07341261.
CVEs:CVE-2022-32643
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-32643
Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
CVEs:CVE-2023-21429
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21429
CVEs:CVE-2023-21437
Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.
CVEs:CVE-2023-21437
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21442
Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information.
CVEs:CVE-2023-21442
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.
CVEs:CVE-2023-21424
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21424
CVEs:CVE-2023-21425
Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.
CVEs:CVE-2023-21425
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21436
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
CVEs:CVE-2023-21436
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21423
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.
CVEs:CVE-2023-21423
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21422
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
CVEs:CVE-2023-21422
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446236; Issu...
CVEs:CVE-2022-32595
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-32595
In ccd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326547; Issue ID: ALPS0732...
CVEs:CVE-2022-32642
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-32642
CVEs:CVE-2022-20481
In multiple files, there is a possible way to preserve WiFi settings due to residual data after a reset. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product...
CVEs:CVE-2022-20481
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-240985973
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2022-20455
In addAutomaticZenRule of ZenModeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2022-20455
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20932
In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User in...
CVEs:CVE-2023-20932
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-245402502
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
CVEs:CVE-2022-47341
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47341
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.
CVEs:CVE-2023-21441
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21441
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629572; Issue ID: ...
CVEs:CVE-2023-20615
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20615
In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07560...
CVEs:CVE-2023-20616
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20616
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629571; Issue ID: ...
CVEs:CVE-2023-20612
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20612
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628614; Issue ID: ...
CVEs:CVE-2023-20613
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20613
CVEs:CVE-2023-20614
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628615; Issue ID: ...
CVEs:CVE-2023-20614
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20609
In ccu, there is a possible out of bounds read due to a logic error. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07570864; Issue ID: ALPS07570864.
CVEs:CVE-2023-20609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494107; Issue ID: ALP...
CVEs:CVE-2023-20602
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20602
CVEs:CVE-2023-20604
In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494067; Issue ID: ...
CVEs:CVE-2023-20604
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-261367136
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07550104; Issue...
CVEs:CVE-2023-20605
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20605
In apusys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07571104; Issue ID:...
CVEs:CVE-2023-20606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20606
In firewall service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
CVEs:CVE-2022-47361
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47361
CVEs:CVE-2022-20551
In createTrack of AudioFlinger.cpp, there is a possible way to record audio without a privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ...
CVEs:CVE-2022-20551
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wlan driver, there is a possible missing permission check. This could lead to local In wlan driver, information disclosure.
CVEs:CVE-2022-44421
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-44421
CVEs:CVE-2022-38681
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-38681
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47452
In gnss driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47452
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVEs:CVE-2022-47347
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47347
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVEs:CVE-2022-47348
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47348
CVEs:CVE-2022-47342
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVEs:CVE-2022-47342
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47343
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVEs:CVE-2022-47343
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47344
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVEs:CVE-2022-47344
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVEs:CVE-2022-47345
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47345
CVEs:CVE-2022-47346
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVEs:CVE-2022-47346
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-38674
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-38674
In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVEs:CVE-2022-38675
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-38675
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-38680
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-38680
In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the microphone privacy indicator due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User ...
CVEs:CVE-2023-20934
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20934
In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363599; Issue ID: ALP...
CVEs:CVE-2023-20608
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20608
CVEs:CVE-2023-20610
In display drm, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363469; Issue ID: ...
CVEs:CVE-2023-20610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20611
In gpu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588678; Issue ID: ALPS07588678.
CVEs:CVE-2023-20611
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47363
In wlan driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47363
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47364
In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47364
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47368
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47368
CVEs:CVE-2022-47369
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47369
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2023-20949
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20949
PUB-A-259323133
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In ccu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07512839; Issue ID: ALPS0751...
CVEs:CVE-2023-20607
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20607
CVEs:CVE-2022-47450
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVEs:CVE-2022-47450
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47365
In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47365
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47366
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47366
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47370
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47370
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVEs:CVE-2022-47327
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47327
CVEs:CVE-2022-47330
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVEs:CVE-2022-47330
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47332
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVEs:CVE-2022-47332
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47333
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVEs:CVE-2022-47333
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42783
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-42783
In wlan driver, there is a possible null pointer dereference issue due to a missing bounds check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-44447
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-44447
CVEs:CVE-2022-44448
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-44448
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47322
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47322
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-38686
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-38686
In hasInputInfo of Layer.cpp, there is a possible bypass of user interaction requirements due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2022-20443
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20443
In bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2022-47367
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47367
In bt driver, there is a thread competition leads to early release of resources to be accessed. This could lead to local denial of service in kernel.
CVEs:CVE-2022-47371
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47371
In log service, there is a missing permission check. This could lead to local denial of service in log service.
CVEs:CVE-2022-47357
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47357
CVEs:CVE-2022-47358
In log service, there is a missing permission check. This could lead to local denial of service in log service.
CVEs:CVE-2022-47358
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In log service, there is a missing permission check. This could lead to local denial of service in log service.
CVEs:CVE-2022-47359
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47359
In log service, there is a missing permission check. This could lead to local denial of service in log service.
CVEs:CVE-2022-47360
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47360
In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2023-20927
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20927
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVEs:CVE-2022-47324
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47324
CVEs:CVE-2022-47325
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVEs:CVE-2022-47325
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47326
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVEs:CVE-2022-47326
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVEs:CVE-2022-47328
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47328
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVEs:CVE-2022-47329
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47329
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47323
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47323
In log service, there is a missing permission check. This could lead to local denial of service in log service.
CVEs:CVE-2022-47354
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47354
In log service, there is a missing permission check. This could lead to local denial of service in log service.
CVEs:CVE-2022-47355
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47355
CVEs:CVE-2022-47356
In log service, there is a missing permission check. This could lead to local denial of service in log service.
CVEs:CVE-2022-47356
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20618
In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519184; Issue ID: ALPS0751...
CVEs:CVE-2023-20618
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20619
In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519159; Issue ID: ALPS0751...
CVEs:CVE-2023-20619
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20939
In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2023-20939
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20942
In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privilege...
CVEs:CVE-2023-20942
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47331
In wlan driver, there is a race condition. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47331
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20940
In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2023-20940
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
golang.org/x/crypto/ssh Man-in-the-Middle attack
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
golang.org/x/crypto/ssh Man-in-the-Middle attack
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
CVEs:CVE-2023-23374
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2023-23374
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
dd-plist XML External Entitly vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.googlecode.plist:dd-plist | affected | Maven | com.googlecode.plist:dd-plist | — |
dd-plist XML External Entitly vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.googlecode.plist:dd-plist | affected | Maven | com.googlecode.plist:dd-plist | — |
A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. An attack has to be approached locally. Upgrading to versio...
CVEs:CVE-2016-15026
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dd-plist | affected | dd-plist_project | — | — |
dd-plist XML External Entitly vulnerability
CVEs:CVE-2016-15026
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.googlecode.plist:dd-plist | affected | Maven | com.googlecode.plist:dd-plist | — |
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apimachinery | affected | k8s.io | k8s.io/apimachinery | — |
| apimachinery | affected | k8s.io | k8s.io/apimachinery | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apimachinery | affected | k8s.io | k8s.io/apimachinery | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.