Google Security Advisories · February 2023 — Google Security Advisories
407 advisories 237 CVEs 10 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2023-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 10 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2023-23376

GoogleExploitedCISA KEV listedCRITICAL2023-02-14

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVEs:CVE-2023-23376

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

CVE-2023-23529

Project ZeroExploitedCISA KEV listed2023-02-13

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2023-23529

Upstream advisory

CVE-2023-23529

GoogleExploitedCISA KEV listedCRITICAL2023-02-13

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execu...

CVEs:CVE-2023-23529

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2023-23529

GoogleExploitedCISA KEV listed2023-02-13

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2023-23529

Upstream advisory

CVE-2023-21823

GoogleExploitedCISA KEV listedCRITICAL2023-02-14

Windows Graphics Component Remote Code Execution Vulnerability

CVEs:CVE-2023-21823

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_20h2 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

CVE-2023-20937

Open SourceWeaponized exploitHIGH2023-02-06

In several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2023-20937

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-257443051

GoogleWeaponized exploitHIGH2023-02-01

ASB-A-257443051

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

GHSA-h8p2-8g72-qpgh

GoogleActive exploitation (sightings)HIGH2023-02-24

Apache Airflow Google Provider Improper Input Validation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-google affected PyPI apache-airflow-providers-google
apache-airflow-providers-google affected PyPI apache-airflow-providers-google
Upstream advisory

GHSA-h8p2-8g72-qpgh

GoogleActive exploitation (sightings)HIGH2023-02-24

Apache Airflow Google Provider Improper Input Validation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-google affected PyPI apache-airflow-providers-google
Upstream advisory

CVE-2023-25692

GoogleActive exploitation (sightings)HIGH2023-02-24

Apache Airflow Google Provider Improper Input Validation vulnerability

CVEs:CVE-2023-25692

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-google affected PyPI apache-airflow-providers-google
Upstream advisory

CVE-2023-25692

GoogleActive exploitation (sightings)HIGH2023-02-24

Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.

CVEs:CVE-2023-25692

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-google affected apache
Upstream advisory

CVE-2023-25692

GoogleActive exploitation (sightings)HIGH2023-02-24

Apache Airflow Google Provider Improper Input Validation vulnerability

CVEs:CVE-2023-25692

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-google affected PyPI apache-airflow-providers-google
Upstream advisory

GHSA-8g23-2q5p-8866

GoogleActive exploitation (sightings)CRITICAL2023-02-24

Apache Airflow Google Provider Improper Input Validation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-google affected PyPI apache-airflow-providers-google
apache-airflow-providers-google affected PyPI apache-airflow-providers-google
Upstream advisory

GHSA-8g23-2q5p-8866

GoogleActive exploitation (sightings)CRITICAL2023-02-24

Apache Airflow Google Provider Improper Input Validation vulnerability

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-google affected PyPI apache-airflow-providers-google
Upstream advisory

CVE-2023-25691

GoogleActive exploitation (sightings)CRITICAL2023-02-24

Apache Airflow Google Provider Improper Input Validation vulnerability

CVEs:CVE-2023-25691

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-google affected PyPI apache-airflow-providers-google
Upstream advisory

CVE-2023-25691

GoogleActive exploitation (sightings)CRITICAL2023-02-24

Apache Airflow Google Provider Improper Input Validation vulnerability

CVEs:CVE-2023-25691

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-google affected PyPI apache-airflow-providers-google
Upstream advisory

CVE-2023-25691

GoogleActive exploitation (sightings)CRITICAL2023-02-24

Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.

CVEs:CVE-2023-25691

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-google affected apache
Upstream advisory

CVE-2023-25747

Open SourceActive exploitation (sightings)CRITICAL2023-02-28

A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for...

CVEs:CVE-2023-25747

Affected products

ProductStatusVendorPackageEcosystem
firefox affected mozilla
Firefox for Android affected Mozilla
firefox_mobile affected mozilla
Upstream advisory

CVE-2023-20938

GoogleActive exploitation (sightings)2023-02-06

In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257685302References: Upstream kernel

CVEs:CVE-2023-20938

Upstream advisory

CVE-2023-20938

Open SourceActive exploitation (sightings)HIGH2023-02-06

In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-20938

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-257685302

GoogleActive exploitation (sightings)HIGH2023-02-01

ASB-A-257685302

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

RHSA-2023:0980

Open SourceActive exploitation (sightings)HIGH2023-02-28

Red Hat Security Advisory: Red Hat Ceph Storage 5.3 Bug fix and security update

Affected products

ProductStatusVendorPackageEcosystem
ceph affected Red Hat:ceph_storage:5.3::el8 ceph
ceph affected Red Hat:ceph_storage:5.3::el9 ceph
cephadm affected Red Hat:ceph_storage:5.3::el9 cephadm
cephadm affected Red Hat:ceph_storage:5.3::el8 cephadm
ceph-base affected Red Hat:ceph_storage:5.3::el9 ceph-base
ceph-base affected Red Hat:ceph_storage:5.3::el8 ceph-base
ceph-base-debuginfo affected Red Hat:ceph_storage:5.3::el8 ceph-base-debuginfo
ceph-base-debuginfo affected Red Hat:ceph_storage:5.3::el9 ceph-base-debuginfo
ceph-common affected Red Hat:ceph_storage:5.3::el8 ceph-common
ceph-common affected Red Hat:ceph_storage:5.3::el9 ceph-common
ceph-common-debuginfo affected Red Hat:ceph_storage:5.3::el8 ceph-common-debuginfo
ceph-common-debuginfo affected Red Hat:ceph_storage:5.3::el9 ceph-common-debuginfo
ceph-debugsource affected Red Hat:ceph_storage:5.3::el8 ceph-debugsource
ceph-debugsource affected Red Hat:ceph_storage:5.3::el9 ceph-debugsource
cephfs-mirror affected Red Hat:ceph_storage:5.3::el8 cephfs-mirror
cephfs-mirror-debuginfo affected Red Hat:ceph_storage:5.3::el8 cephfs-mirror-debuginfo
cephfs-mirror-debuginfo affected Red Hat:ceph_storage:5.3::el9 cephfs-mirror-debuginfo
cephfs-top affected Red Hat:ceph_storage:5.3::el9 cephfs-top
cephfs-top affected Red Hat:ceph_storage:5.3::el8 cephfs-top
ceph-fuse affected Red Hat:ceph_storage:5.3::el8 ceph-fuse
ceph-fuse affected Red Hat:ceph_storage:5.3::el9 ceph-fuse
ceph-fuse-debuginfo affected Red Hat:ceph_storage:5.3::el8 ceph-fuse-debuginfo
ceph-fuse-debuginfo affected Red Hat:ceph_storage:5.3::el9 ceph-fuse-debuginfo
ceph-grafana-dashboards affected Red Hat:ceph_storage:5.3::el8 ceph-grafana-dashboards
ceph-immutable-object-cache affected Red Hat:ceph_storage:5.3::el8 ceph-immutable-object-cache
ceph-immutable-object-cache affected Red Hat:ceph_storage:5.3::el9 ceph-immutable-object-cache
ceph-immutable-object-cache-debuginfo affected Red Hat:ceph_storage:5.3::el8 ceph-immutable-object-cache-debuginfo
ceph-immutable-object-cache-debuginfo affected Red Hat:ceph_storage:5.3::el9 ceph-immutable-object-cache-debuginfo
ceph-mds affected Red Hat:ceph_storage:5.3::el8 ceph-mds
ceph-mds-debuginfo affected Red Hat:ceph_storage:5.3::el9 ceph-mds-debuginfo
ceph-mds-debuginfo affected Red Hat:ceph_storage:5.3::el8 ceph-mds-debuginfo
ceph-mgr affected Red Hat:ceph_storage:5.3::el8 ceph-mgr
ceph-mgr-cephadm affected Red Hat:ceph_storage:5.3::el8 ceph-mgr-cephadm
ceph-mgr-dashboard affected Red Hat:ceph_storage:5.3::el8 ceph-mgr-dashboard
ceph-mgr-debuginfo affected Red Hat:ceph_storage:5.3::el9 ceph-mgr-debuginfo
ceph-mgr-debuginfo affected Red Hat:ceph_storage:5.3::el8 ceph-mgr-debuginfo
ceph-mgr-diskprediction-local affected Red Hat:ceph_storage:5.3::el8 ceph-mgr-diskprediction-local
ceph-mgr-k8sevents affected Red Hat:ceph_storage:5.3::el8 ceph-mgr-k8sevents
ceph-mgr-modules-core affected Red Hat:ceph_storage:5.3::el8 ceph-mgr-modules-core
ceph-mgr-rook affected Red Hat:ceph_storage:5.3::el8 ceph-mgr-rook
ceph-mib affected Red Hat:ceph_storage:5.3::el8 ceph-mib
ceph-mib affected Red Hat:ceph_storage:5.3::el9 ceph-mib
ceph-mon affected Red Hat:ceph_storage:5.3::el8 ceph-mon
ceph-mon-debuginfo affected Red Hat:ceph_storage:5.3::el9 ceph-mon-debuginfo
ceph-mon-debuginfo affected Red Hat:ceph_storage:5.3::el8 ceph-mon-debuginfo
ceph-osd affected Red Hat:ceph_storage:5.3::el8 ceph-osd
ceph-osd-debuginfo affected Red Hat:ceph_storage:5.3::el8 ceph-osd-debuginfo
ceph-osd-debuginfo affected Red Hat:ceph_storage:5.3::el9 ceph-osd-debuginfo
ceph-prometheus-alerts affected Red Hat:ceph_storage:5.3::el8 ceph-prometheus-alerts
ceph-radosgw affected Red Hat:ceph_storage:5.3::el8 ceph-radosgw
ceph-radosgw-debuginfo affected Red Hat:ceph_storage:5.3::el9 ceph-radosgw-debuginfo
ceph-radosgw-debuginfo affected Red Hat:ceph_storage:5.3::el8 ceph-radosgw-debuginfo
ceph-resource-agents affected Red Hat:ceph_storage:5.3::el8 ceph-resource-agents
ceph-resource-agents affected Red Hat:ceph_storage:5.3::el9 ceph-resource-agents
ceph-selinux affected Red Hat:ceph_storage:5.3::el8 ceph-selinux
ceph-selinux affected Red Hat:ceph_storage:5.3::el9 ceph-selinux
ceph-test affected Red Hat:ceph_storage:5.3::el8 ceph-test
ceph-test-debuginfo affected Red Hat:ceph_storage:5.3::el9 ceph-test-debuginfo
ceph-test-debuginfo affected Red Hat:ceph_storage:5.3::el8 ceph-test-debuginfo
libcephfs2 affected Red Hat:ceph_storage:5.3::el9 libcephfs2
libcephfs2 affected Red Hat:ceph_storage:5.3::el8 libcephfs2
libcephfs2-debuginfo affected Red Hat:ceph_storage:5.3::el8 libcephfs2-debuginfo
libcephfs2-debuginfo affected Red Hat:ceph_storage:5.3::el9 libcephfs2-debuginfo
libcephfs-devel affected Red Hat:ceph_storage:5.3::el9 libcephfs-devel
libcephfs-devel affected Red Hat:ceph_storage:5.3::el8 libcephfs-devel
libcephsqlite affected Red Hat:ceph_storage:5.3::el8 libcephsqlite
libcephsqlite-debuginfo affected Red Hat:ceph_storage:5.3::el9 libcephsqlite-debuginfo
libcephsqlite-debuginfo affected Red Hat:ceph_storage:5.3::el8 libcephsqlite-debuginfo
librados2 affected Red Hat:ceph_storage:5.3::el8 librados2
librados2 affected Red Hat:ceph_storage:5.3::el9 librados2
librados2-debuginfo affected Red Hat:ceph_storage:5.3::el8 librados2-debuginfo
librados2-debuginfo affected Red Hat:ceph_storage:5.3::el9 librados2-debuginfo
librados-devel affected Red Hat:ceph_storage:5.3::el8 librados-devel
librados-devel affected Red Hat:ceph_storage:5.3::el9 librados-devel
librados-devel-debuginfo affected Red Hat:ceph_storage:5.3::el8 librados-devel-debuginfo
librados-devel-debuginfo affected Red Hat:ceph_storage:5.3::el9 librados-devel-debuginfo
libradospp-devel affected Red Hat:ceph_storage:5.3::el8 libradospp-devel
libradospp-devel affected Red Hat:ceph_storage:5.3::el9 libradospp-devel
libradosstriper1 affected Red Hat:ceph_storage:5.3::el9 libradosstriper1
libradosstriper1 affected Red Hat:ceph_storage:5.3::el8 libradosstriper1
libradosstriper1-debuginfo affected Red Hat:ceph_storage:5.3::el9 libradosstriper1-debuginfo
libradosstriper1-debuginfo affected Red Hat:ceph_storage:5.3::el8 libradosstriper1-debuginfo
librbd1 affected Red Hat:ceph_storage:5.3::el9 librbd1
librbd1 affected Red Hat:ceph_storage:5.3::el8 librbd1
librbd1-debuginfo affected Red Hat:ceph_storage:5.3::el8 librbd1-debuginfo
librbd1-debuginfo affected Red Hat:ceph_storage:5.3::el9 librbd1-debuginfo
librbd-devel affected Red Hat:ceph_storage:5.3::el9 librbd-devel
librbd-devel affected Red Hat:ceph_storage:5.3::el8 librbd-devel
librgw2 affected Red Hat:ceph_storage:5.3::el9 librgw2
librgw2 affected Red Hat:ceph_storage:5.3::el8 librgw2
librgw2-debuginfo affected Red Hat:ceph_storage:5.3::el9 librgw2-debuginfo
librgw2-debuginfo affected Red Hat:ceph_storage:5.3::el8 librgw2-debuginfo
librgw-devel affected Red Hat:ceph_storage:5.3::el8 librgw-devel
librgw-devel affected Red Hat:ceph_storage:5.3::el9 librgw-devel
python3-ceph-argparse affected Red Hat:ceph_storage:5.3::el9 python3-ceph-argparse
python3-ceph-argparse affected Red Hat:ceph_storage:5.3::el8 python3-ceph-argparse
python3-ceph-common affected Red Hat:ceph_storage:5.3::el8 python3-ceph-common
python3-ceph-common affected Red Hat:ceph_storage:5.3::el9 python3-ceph-common
python3-cephfs affected Red Hat:ceph_storage:5.3::el8 python3-cephfs
python3-cephfs affected Red Hat:ceph_storage:5.3::el9 python3-cephfs
python3-cephfs-debuginfo affected Red Hat:ceph_storage:5.3::el9 python3-cephfs-debuginfo
python3-cephfs-debuginfo affected Red Hat:ceph_storage:5.3::el8 python3-cephfs-debuginfo
python3-rados affected Red Hat:ceph_storage:5.3::el9 python3-rados
python3-rados affected Red Hat:ceph_storage:5.3::el8 python3-rados
python3-rados-debuginfo affected Red Hat:ceph_storage:5.3::el9 python3-rados-debuginfo
python3-rados-debuginfo affected Red Hat:ceph_storage:5.3::el8 python3-rados-debuginfo
python3-rbd affected Red Hat:ceph_storage:5.3::el8 python3-rbd
python3-rbd affected Red Hat:ceph_storage:5.3::el9 python3-rbd
python3-rbd-debuginfo affected Red Hat:ceph_storage:5.3::el8 python3-rbd-debuginfo
python3-rbd-debuginfo affected Red Hat:ceph_storage:5.3::el9 python3-rbd-debuginfo
python3-rgw affected Red Hat:ceph_storage:5.3::el9 python3-rgw
python3-rgw affected Red Hat:ceph_storage:5.3::el8 python3-rgw
python3-rgw-debuginfo affected Red Hat:ceph_storage:5.3::el9 python3-rgw-debuginfo
python3-rgw-debuginfo affected Red Hat:ceph_storage:5.3::el8 python3-rgw-debuginfo
rbd-fuse-debuginfo affected Red Hat:ceph_storage:5.3::el9 rbd-fuse-debuginfo
rbd-fuse-debuginfo affected Red Hat:ceph_storage:5.3::el8 rbd-fuse-debuginfo
rbd-mirror affected Red Hat:ceph_storage:5.3::el8 rbd-mirror
rbd-mirror-debuginfo affected Red Hat:ceph_storage:5.3::el9 rbd-mirror-debuginfo
rbd-mirror-debuginfo affected Red Hat:ceph_storage:5.3::el8 rbd-mirror-debuginfo
rbd-nbd affected Red Hat:ceph_storage:5.3::el8 rbd-nbd
rbd-nbd affected Red Hat:ceph_storage:5.3::el9 rbd-nbd
rbd-nbd-debuginfo affected Red Hat:ceph_storage:5.3::el8 rbd-nbd-debuginfo
rbd-nbd-debuginfo affected Red Hat:ceph_storage:5.3::el9 rbd-nbd-debuginfo
Upstream advisory

ASB-A-262503737

GoogleActive exploitation (sightings)CRITICAL2023-02-01

ASB-A-262503737

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

OESA-2023-1093

Open SourcePoC exploit2023-02-17

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP3 golang
Upstream advisory

OESA-2023-1080

Open SourcePoC exploit2023-02-10

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS-SP1 golang
Upstream advisory

OESA-2023-1081

Open SourcePoC exploit2023-02-10

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
Upstream advisory

OESA-2023-1082

Open SourcePoC exploit2023-02-10

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS golang
Upstream advisory

AZL-25350

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41723 affecting package golang for versions less than 1.19.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-34543

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41723 affecting package application-gateway-kubernetes-ingress for versions less than 1.7.2-2

Affected products

ProductStatusVendorPackageEcosystem
application-gateway-kubernetes-ingress affected Azure Linux:3 application-gateway-kubernetes-ingress
Upstream advisory

AZL-37377

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41723 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37481

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41723 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

DEBIAN-CVE-2022-41723

Open SourcePoC exploitHIGH2023-02-28

DEBIAN-CVE-2022-41723

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
golang-golang-x-net affected Debian:11 golang-golang-x-net
golang-golang-x-net affected Debian:12 golang-golang-x-net
golang-golang-x-net affected Debian:13 golang-golang-x-net
golang-golang-x-net affected Debian:14 golang-golang-x-net
Upstream advisory

CVE-2022-41723

Open SourcePoC exploitHIGH2023-02-17

golang.org/x/net vulnerable to Uncontrolled Resource Consumption

CVEs:CVE-2022-41723

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-vvpx-j8f3-3w6h

Open SourcePoC exploitCRITICAL2023-02-17

golang.org/x/net vulnerable to Uncontrolled Resource Consumption

Affected products

ProductStatusVendorPackageEcosystem
cadvisor affected wolfi cadvisor
cadvisor affected chainguard cadvisor
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
falco affected wolfi falco
falco affected chainguard falco
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
go-1.19 affected wolfi go-1.19
go-1.19 affected chainguard go-1.19
go-1.20 affected chainguard go-1.20
go-1.20 affected wolfi go-1.20
go-fips-1.20 affected chainguard go-fips-1.20
go-fips-1.20 affected wolfi go-fips-1.20
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
hey affected wolfi hey
hey affected chainguard hey
k3d affected chainguard k3d
k3d affected wolfi k3d
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kyverno-1.8 affected chainguard kyverno-1.8
oauth2-proxy affected wolfi oauth2-proxy
oauth2-proxy affected chainguard oauth2-proxy
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
restic affected wolfi restic
restic affected chainguard restic
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
wireguard-go affected wolfi wireguard-go
wireguard-go affected chainguard wireguard-go
x/net affected golang.org
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-vvpx-j8f3-3w6h

Open SourcePoC exploitCRITICAL2023-02-17

golang.org/x/net vulnerable to Uncontrolled Resource Consumption

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2022-41723

GooglePoC exploitHIGH2023-02-16

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

CVEs:CVE-2022-41723

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
hpack affected golang
http2 affected golang
Upstream advisory

GO-2023-1571

Open SourcePoC exploitHIGH2023-02-16

Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net

Affected products

ProductStatusVendorPackageEcosystem
cadvisor affected wolfi cadvisor
cadvisor affected chainguard cadvisor
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
go-1.20 affected wolfi go-1.20
go-1.20 affected chainguard go-1.20
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
hey affected chainguard hey
hey affected wolfi hey
k3d affected chainguard k3d
k3d affected wolfi k3d
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
oauth2-proxy affected wolfi oauth2-proxy
oauth2-proxy affected chainguard oauth2-proxy
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
restic affected wolfi restic
restic affected chainguard restic
stdlib affected Go stdlib
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
wireguard-go affected chainguard wireguard-go
wireguard-go affected wolfi wireguard-go
x/net affected golang.org golang.org/x/net
Upstream advisory

AZL-37981

Open SourcePoC exploitCRITICAL2023-02-09

CVE-2022-43552 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-37839

Open SourcePoC exploitCRITICAL2023-02-23

CVE-2023-23916 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-13738

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41722 affecting package msft-golang for versions less than 1.19.8-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37435

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41722 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37449

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41722 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-47227

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41722 affecting package golang for versions less than 1.22.7-2

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-41722

Open SourcePoC exploitHIGH2023-02-28

DEBIAN-CVE-2022-41722

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-41722

GooglePoC exploitHIGH2023-02-16

A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an abso...

CVEs:CVE-2022-41722

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2023-1568

Open SourcePoC exploitHIGH2023-02-16

Path traversal on Windows in path/filepath

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

AZL-13732

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41725 affecting package golang for versions less than 1.19.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-13739

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41725 affecting package msft-golang for versions less than 1.19.6-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-34761

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41725 affecting package golang for versions less than 1.19.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-37334

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41725 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37487

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41725 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-78992

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41725 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-41725

Open SourcePoC exploitHIGH2023-02-28

DEBIAN-CVE-2022-41725

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-41725

GooglePoC exploitHIGH2023-02-21

A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsin...

CVEs:CVE-2022-41725

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2023-1569

Open SourcePoC exploitHIGH2023-02-21

Excessive resource consumption in mime/multipart

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

CVE-2023-21720

Open SourcePoC exploitMEDIUM2023-02-02

Microsoft Edge (Chromium-based) Tampering Vulnerability

CVEs:CVE-2023-21720

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

AZL-13731

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41724 affecting package golang for versions less than 1.19.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-13737

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41724 affecting package msft-golang for versions less than 1.19.6-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-34755

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41724 affecting package golang for versions less than 1.19.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-37400

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41724 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37508

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41724 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-78952

Open SourcePoC exploitHIGH2023-02-28

CVE-2022-41724 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-41724

Open SourcePoC exploitHIGH2023-02-28

DEBIAN-CVE-2022-41724

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-41724

GooglePoC exploitHIGH2023-02-16

Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS ...

CVEs:CVE-2022-41724

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2023-1570

Open SourcePoC exploit2023-02-16

Panic on large handshake records in crypto/tls

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

AZL-38093

Open SourcePoC exploitHIGH2023-02-23

CVE-2023-23915 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-38043

Open SourcePoC exploitCRITICAL2023-02-23

CVE-2023-23914 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-8cfg-vx93-jvxw

Open SourcePoC exploitHIGH2023-02-06

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

Affected products

ProductStatusVendorPackageEcosystem
client-go affected k8s.io k8s.io/client-go
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-8cfg-vx93-jvxw

Open SourcePoC exploitHIGH2023-02-06

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

Affected products

ProductStatusVendorPackageEcosystem
client-go affected k8s.io k8s.io/client-go
gostatsd affected wolfi gostatsd
gostatsd affected chainguard gostatsd
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
Upstream advisory

ASB-A-248354871

GooglePoC exploitHIGH2023-02-01

ASB-A-248354871

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

GHSA-8mjg-8c8g-6h85

Open SourcePoC exploitHIGH2023-02-06

Kubernetes Sensitive Information leak via Log File

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
Upstream advisory

GHSA-8mjg-8c8g-6h85

Open SourcePoC exploitHIGH2023-02-06

Kubernetes Sensitive Information leak via Log File

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

ASB-A-245869446

GooglePoC exploitHIGH2023-02-01

ASB-A-245869446

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2023-20944

Open SourcePoC exploitHIGH2023-02-06

In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-20944

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20943

Open SourcePoC exploitHIGH2023-02-06

In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not ne...

CVEs:CVE-2023-20943

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20933

Open SourcePoC exploitHIGH2023-02-06

In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2023-20933

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DLA-3322-1

Open SourceCoalition ESS < 30%2023-02-18

golang-github-opencontainers-selinux - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-github-opencontainers-selinux affected Debian:10 golang-github-opencontainers-selinux
Upstream advisory

RHBA-2023:0568

Open SourceCoalition ESS < 30%HIGH2023-02-08

Red Hat Bug Fix Advisory: OpenShift Container Platform 4.12.2 packages update

Affected products

ProductStatusVendorPackageEcosystem
atomic-openshift-service-idler affected Red Hat:openshift:4.12::el8 atomic-openshift-service-idler
bpftool affected Red Hat:openshift:4.12::el8 bpftool
bpftool-debuginfo affected Red Hat:openshift:4.12::el8 bpftool-debuginfo
buildah affected Red Hat:openshift:4.12::el8 buildah
buildah-debuginfo affected Red Hat:openshift:4.12::el8 buildah-debuginfo
buildah-debugsource affected Red Hat:openshift:4.12::el8 buildah-debugsource
buildah-tests affected Red Hat:openshift:4.12::el8 buildah-tests
buildah-tests-debuginfo affected Red Hat:openshift:4.12::el8 buildah-tests-debuginfo
containers-common affected Red Hat:openshift:4.12::el8 containers-common
kernel affected Red Hat:openshift:4.12::el8 kernel
kernel-core affected Red Hat:openshift:4.12::el8 kernel-core
kernel-cross-headers affected Red Hat:openshift:4.12::el8 kernel-cross-headers
kernel-debug affected Red Hat:openshift:4.12::el8 kernel-debug
kernel-debug-core affected Red Hat:openshift:4.12::el8 kernel-debug-core
kernel-debug-debuginfo affected Red Hat:openshift:4.12::el8 kernel-debug-debuginfo
kernel-debug-devel affected Red Hat:openshift:4.12::el8 kernel-debug-devel
kernel-debuginfo affected Red Hat:openshift:4.12::el8 kernel-debuginfo
kernel-debuginfo-common-aarch64 affected Red Hat:openshift:4.12::el8 kernel-debuginfo-common-aarch64
kernel-debuginfo-common-ppc64le affected Red Hat:openshift:4.12::el8 kernel-debuginfo-common-ppc64le
kernel-debuginfo-common-s390x affected Red Hat:openshift:4.12::el8 kernel-debuginfo-common-s390x
kernel-debuginfo-common-x86_64 affected Red Hat:openshift:4.12::el8 kernel-debuginfo-common-x86_64
kernel-debug-modules affected Red Hat:openshift:4.12::el8 kernel-debug-modules
kernel-debug-modules-extra affected Red Hat:openshift:4.12::el8 kernel-debug-modules-extra
kernel-debug-modules-internal affected Red Hat:openshift:4.12::el8 kernel-debug-modules-internal
kernel-devel affected Red Hat:openshift:4.12::el8 kernel-devel
kernel-doc affected Red Hat:openshift:4.12::el8 kernel-doc
kernel-headers affected Red Hat:openshift:4.12::el8 kernel-headers
kernel-ipaclones-internal affected Red Hat:openshift:4.12::el8 kernel-ipaclones-internal
kernel-modules affected Red Hat:openshift:4.12::el8 kernel-modules
kernel-modules-extra affected Red Hat:openshift:4.12::el8 kernel-modules-extra
kernel-modules-internal affected Red Hat:openshift:4.12::el8 kernel-modules-internal
kernel-rt affected Red Hat:openshift:4.12::el8 kernel-rt
kernel-rt-core affected Red Hat:openshift:4.12::el8 kernel-rt-core
kernel-rt-debug affected Red Hat:openshift:4.12::el8 kernel-rt-debug
kernel-rt-debug-core affected Red Hat:openshift:4.12::el8 kernel-rt-debug-core
kernel-rt-debug-debuginfo affected Red Hat:openshift:4.12::el8 kernel-rt-debug-debuginfo
kernel-rt-debug-devel affected Red Hat:openshift:4.12::el8 kernel-rt-debug-devel
kernel-rt-debuginfo affected Red Hat:openshift:4.12::el8 kernel-rt-debuginfo
kernel-rt-debuginfo-common-x86_64 affected Red Hat:openshift:4.12::el8 kernel-rt-debuginfo-common-x86_64
kernel-rt-debug-kvm affected Red Hat:openshift:4.12::el8 kernel-rt-debug-kvm
kernel-rt-debug-modules affected Red Hat:openshift:4.12::el8 kernel-rt-debug-modules
kernel-rt-debug-modules-extra affected Red Hat:openshift:4.12::el8 kernel-rt-debug-modules-extra
kernel-rt-debug-modules-internal affected Red Hat:openshift:4.12::el8 kernel-rt-debug-modules-internal
kernel-rt-devel affected Red Hat:openshift:4.12::el8 kernel-rt-devel
kernel-rt-kvm affected Red Hat:openshift:4.12::el8 kernel-rt-kvm
kernel-rt-modules affected Red Hat:openshift:4.12::el8 kernel-rt-modules
kernel-rt-modules-extra affected Red Hat:openshift:4.12::el8 kernel-rt-modules-extra
kernel-rt-modules-internal affected Red Hat:openshift:4.12::el8 kernel-rt-modules-internal
kernel-rt-selftests-internal affected Red Hat:openshift:4.12::el8 kernel-rt-selftests-internal
kernel-selftests-internal affected Red Hat:openshift:4.12::el8 kernel-selftests-internal
kernel-tools affected Red Hat:openshift:4.12::el8 kernel-tools
kernel-tools-debuginfo affected Red Hat:openshift:4.12::el8 kernel-tools-debuginfo
kernel-tools-libs affected Red Hat:openshift:4.12::el8 kernel-tools-libs
kernel-tools-libs-devel affected Red Hat:openshift:4.12::el8 kernel-tools-libs-devel
kernel-zfcpdump affected Red Hat:openshift:4.12::el8 kernel-zfcpdump
kernel-zfcpdump-core affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-core
kernel-zfcpdump-debuginfo affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-debuginfo
kernel-zfcpdump-devel affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-devel
kernel-zfcpdump-modules affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-modules
kernel-zfcpdump-modules-extra affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-modules-extra
kernel-zfcpdump-modules-internal affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-modules-internal
openshift-clients affected Red Hat:openshift:4.12::el9 openshift-clients
openshift-clients affected Red Hat:openshift:4.12::el8 openshift-clients
openshift-clients-redistributable affected Red Hat:openshift:4.12::el9 openshift-clients-redistributable
openshift-clients-redistributable affected Red Hat:openshift:4.12::el8 openshift-clients-redistributable
openshift-kuryr affected Red Hat:openshift:4.12::el8 openshift-kuryr
openshift-kuryr-cni affected Red Hat:openshift:4.12::el8 openshift-kuryr-cni
openshift-kuryr-common affected Red Hat:openshift:4.12::el8 openshift-kuryr-common
openshift-kuryr-controller affected Red Hat:openshift:4.12::el8 openshift-kuryr-controller
ovn22.12 affected Red Hat:openshift:4.12::el8 ovn22.12
ovn22.12-central affected Red Hat:openshift:4.12::el8 ovn22.12-central
ovn22.12-central-debuginfo affected Red Hat:openshift:4.12::el8 ovn22.12-central-debuginfo
ovn22.12-debuginfo affected Red Hat:openshift:4.12::el8 ovn22.12-debuginfo
ovn22.12-debugsource affected Red Hat:openshift:4.12::el8 ovn22.12-debugsource
ovn22.12-host affected Red Hat:openshift:4.12::el8 ovn22.12-host
ovn22.12-host-debuginfo affected Red Hat:openshift:4.12::el8 ovn22.12-host-debuginfo
ovn22.12-vtep affected Red Hat:openshift:4.12::el8 ovn22.12-vtep
ovn22.12-vtep-debuginfo affected Red Hat:openshift:4.12::el8 ovn22.12-vtep-debuginfo
perf affected Red Hat:openshift:4.12::el8 perf
perf-debuginfo affected Red Hat:openshift:4.12::el8 perf-debuginfo
python3-kuryr-kubernetes affected Red Hat:openshift:4.12::el8 python3-kuryr-kubernetes
python3-perf affected Red Hat:openshift:4.12::el8 python3-perf
python3-perf-debuginfo affected Red Hat:openshift:4.12::el8 python3-perf-debuginfo
runc affected Red Hat:openshift:4.12::el8 runc
runc-debuginfo affected Red Hat:openshift:4.12::el8 runc-debuginfo
runc-debugsource affected Red Hat:openshift:4.12::el8 runc-debugsource
skopeo affected Red Hat:openshift:4.12::el8 skopeo
skopeo affected Red Hat:openshift:4.12::el9 skopeo
skopeo-debuginfo affected Red Hat:openshift:4.12::el8 skopeo-debuginfo
skopeo-debuginfo affected Red Hat:openshift:4.12::el9 skopeo-debuginfo
skopeo-debugsource affected Red Hat:openshift:4.12::el8 skopeo-debugsource
skopeo-debugsource affected Red Hat:openshift:4.12::el9 skopeo-debugsource
skopeo-tests affected Red Hat:openshift:4.12::el9 skopeo-tests
skopeo-tests affected Red Hat:openshift:4.12::el8 skopeo-tests
Upstream advisory

GHSA-6p5q-h963-pwwf

Open SourceCoalition ESS < 30%CRITICAL2023-02-04

Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection

Affected products

ProductStatusVendorPackageEcosystem
apache/age/drivers/golang affected github.com github.com/apache/age/drivers/golang
apache/age/drivers/golang affected github.com github.com/apache/age/drivers/golang
apache-age-python affected PyPI apache-age-python
apache-age-python affected PyPI apache-age-python
github.com/apache/age/drivers/golang affected Go github.com/apache/age/drivers/golang
Upstream advisory

GHSA-6p5q-h963-pwwf

Open SourceCoalition ESS < 30%CRITICAL2023-02-04

Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection

Affected products

ProductStatusVendorPackageEcosystem
apache/age/drivers/golang affected github.com github.com/apache/age/drivers/golang
apache-age-python affected PyPI apache-age-python
Upstream advisory

CVE-2022-45786

Open SourceCoalition ESS < 30%HIGH2023-02-04

Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection

CVEs:CVE-2022-45786

Affected products

ProductStatusVendorPackageEcosystem
apache/age/drivers/golang affected github.com github.com/apache/age/drivers/golang
apache-age-python affected PyPI apache-age-python
Upstream advisory

CVE-2022-45786

Open SourceCoalition ESS < 30%CRITICAL2023-02-04

Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection

CVEs:CVE-2022-45786

Affected products

ProductStatusVendorPackageEcosystem
apache/age/drivers/golang affected github.com github.com/apache/age/drivers/golang
apache-age-python affected PyPI apache-age-python
Upstream advisory

CVE-2022-45786

GoogleCoalition ESS < 30%CRITICAL2023-02-04

There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for PostgreSQL 12, all versions up-to-and-including 1.1.0, when using those drivers. The fix is to update to the ...

CVEs:CVE-2022-45786

Affected products

ProductStatusVendorPackageEcosystem
age affected apache
Upstream advisory

CVE-2023-0259

GoogleCoalition ESS < 30%CRITICAL2023-02-13

The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVEs:CVE-2023-0259

Affected products

ProductStatusVendorPackageEcosystem
wp_google_review_slider affected ljapps
Upstream advisory

openSUSE-SU-2023:0045-1

Open SourceCoalition ESS < 30%CRITICAL2023-02-13

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5345-1

Open SourceCoalition ESS < 30%2023-02-08

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2023-0704

GoogleCoalition ESS < 30%CRITICAL2023-02-07

Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-0704

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0704

Open SourceCoalition ESS < 30%CRITICAL2023-02-07

DEBIAN-CVE-2023-0704

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-0699

GoogleCoalition ESS < 30%CRITICAL2023-02-07

Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)

CVEs:CVE-2023-0699

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0699

Open SourceCoalition ESS < 30%CRITICAL2023-02-07

DEBIAN-CVE-2023-0699

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-0701

GoogleCoalition ESS < 30%CRITICAL2023-02-07

Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interaction . (Chromium security severity: Medium)

CVEs:CVE-2023-0701

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0701

Open SourceCoalition ESS < 30%CRITICAL2023-02-07

DEBIAN-CVE-2023-0701

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

MGASA-2023-0044

Open SourceCoalition ESS < 30%CRITICAL2023-02-14

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

CVE-2023-0705

GoogleCoalition ESS < 30%CRITICAL2023-02-07

Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-0705

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0705

Open SourceCoalition ESS < 30%CRITICAL2023-02-07

DEBIAN-CVE-2023-0705

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-21794

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2023-21794

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-0702

GoogleCoalition ESS < 30%HIGH2023-02-07

Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Me...

CVEs:CVE-2023-0702

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0702

Open SourceCoalition ESS < 30%HIGH2023-02-07

DEBIAN-CVE-2023-0702

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-0703

GoogleCoalition ESS < 30%HIGH2023-02-07

Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)

CVEs:CVE-2023-0703

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0703

Open SourceCoalition ESS < 30%HIGH2023-02-07

DEBIAN-CVE-2023-0703

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-0700

GoogleCoalition ESS < 30%MEDIUM2023-02-07

Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-0700

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0700

Open SourceCoalition ESS < 30%MEDIUM2023-02-07

DEBIAN-CVE-2023-0700

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2023:0061-1

Open SourceCoalition ESS < 30%CRITICAL2023-02-27

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5359-1

Open SourceCoalition ESS < 30%2023-02-23

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2023-0930

GoogleCoalition ESS < 30%CRITICAL2023-02-22

Heap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-0930

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0930

Open SourceCoalition ESS < 30%CRITICAL2023-02-22

DEBIAN-CVE-2023-0930

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-0698

GoogleCoalition ESS < 30%HIGH2023-02-07

Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-0698

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0698

Open SourceCoalition ESS < 30%HIGH2023-02-07

DEBIAN-CVE-2023-0698

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2023-0931

GoogleCoalition ESS < 30%CRITICAL2023-02-22

Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-0931

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0931

Open SourceCoalition ESS < 30%CRITICAL2023-02-22

DEBIAN-CVE-2023-0931

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1065

Open SourceCoalition ESS < 30%MEDIUM2023-02-28

This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues. It does not expose the user of the integration to any direct security r...

CVEs:CVE-2023-1065

Affected products

ProductStatusVendorPackageEcosystem
kubernetes_monitor affected snyk
Upstream advisory

CVE-2023-0933

GoogleCoalition ESS < 30%CRITICAL2023-02-22

Integer overflow in PDF in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

CVEs:CVE-2023-0933

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0933

Open SourceCoalition ESS < 30%CRITICAL2023-02-22

DEBIAN-CVE-2023-0933

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-0928

GoogleCoalition ESS < 30%CRITICAL2023-02-22

Use after free in SwiftShader in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-0928

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-0941

GoogleCoalition ESS < 30%CRITICAL2023-02-22

Use after free in Prompts in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2023-0941

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0928

Open SourceCoalition ESS < 30%CRITICAL2023-02-22

DEBIAN-CVE-2023-0928

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
Upstream advisory

DEBIAN-CVE-2023-0941

Open SourceCoalition ESS < 30%CRITICAL2023-02-22

DEBIAN-CVE-2023-0941

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

ASB-A-245928838

GoogleCoalition ESS < 30%HIGH2023-02-01

ASB-A-245928838

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2023-0929

GoogleCoalition ESS < 30%CRITICAL2023-02-22

Use after free in Vulkan in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-0929

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0929

Open SourceCoalition ESS < 30%CRITICAL2023-02-22

DEBIAN-CVE-2023-0929

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-0696

GoogleCoalition ESS < 30%HIGH2023-02-07

Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-0696

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0696

Open SourceCoalition ESS < 30%HIGH2023-02-07

DEBIAN-CVE-2023-0696

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-0927

GoogleCoalition ESS < 30%CRITICAL2023-02-22

Use after free in Web Payments API in Google Chrome on Android prior to 110.0.5481.177 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-0927

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-0932

GoogleCoalition ESS < 30%CRITICAL2023-02-22

Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever...

CVEs:CVE-2023-0932

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0927

Open SourceCoalition ESS < 30%CRITICAL2023-02-22

DEBIAN-CVE-2023-0927

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-0932

Open SourceCoalition ESS < 30%CRITICAL2023-02-22

DEBIAN-CVE-2023-0932

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-0697

GoogleCoalition ESS < 30%MEDIUM2023-02-07

Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-0697

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-0697

Open SourceCoalition ESS < 30%MEDIUM2023-02-07

DEBIAN-CVE-2023-0697

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-7h4w-6p98-r3wx

Open SourceCoalition ESS < 30%HIGH2023-02-21

textAngular Cross-site Scripting vulnerability

Affected products

ProductStatusVendorPackageEcosystem
textangular affected npm textangular
Upstream advisory

GHSA-7h4w-6p98-r3wx

Open SourceCoalition ESS < 30%HIGH2023-02-21

textAngular Cross-site Scripting vulnerability

Affected products

ProductStatusVendorPackageEcosystem
textangular affected npm textangular
Upstream advisory

CVE-2021-32854

Open SourceCoalition ESS < 30%MEDIUM2023-02-21

textAngular Cross-site Scripting vulnerability

CVEs:CVE-2021-32854

Affected products

ProductStatusVendorPackageEcosystem
textangular affected npm textangular
Upstream advisory

CVE-2021-32854

Open SourceCoalition ESS < 30%MEDIUM2023-02-21

textAngular Cross-site Scripting vulnerability

CVEs:CVE-2021-32854

Affected products

ProductStatusVendorPackageEcosystem
textangular affected npm textangular
Upstream advisory

CVE-2021-32854

Open SourceCoalition ESS < 30%HIGH2023-02-21

textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There a...

CVEs:CVE-2021-32854

Affected products

ProductStatusVendorPackageEcosystem
textangular affected textangular
Upstream advisory

CVE-2023-20946

Open SourceCoalition ESS < 30%CRITICAL2023-02-06

In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interac...

CVEs:CVE-2023-20946

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2023-0475

Open SourceCoalition ESS < 30%MEDIUM2023-02-16

DEBIAN-CVE-2023-0475

Affected products

ProductStatusVendorPackageEcosystem
golang-github-hashicorp-go-getter affected Debian:11 golang-github-hashicorp-go-getter
golang-github-hashicorp-go-getter affected Debian:12 golang-github-hashicorp-go-getter
Upstream advisory

CVE-2023-20948

Open SourceCoalition ESS < 30%HIGH2023-02-06

In dropFramesUntilIframe of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2023-20948

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-245406696

GoogleCoalition ESS < 30%MEDIUM2023-02-01

ASB-A-245406696

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DEBIAN-CVE-2022-41727

Open SourceCoalition ESS < 30%HIGH2023-02-28

DEBIAN-CVE-2022-41727

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-image affected Debian:11 golang-golang-x-image
golang-golang-x-image affected Debian:12 golang-golang-x-image
golang-golang-x-image affected Debian:13 golang-golang-x-image
golang-golang-x-image affected Debian:14 golang-golang-x-image
Upstream advisory

GHSA-qgc7-mgm3-q253

Open SourceCoalition ESS < 30%CRITICAL2023-02-17

Uncontrolled Resource Consumption in golang.org/x/image

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

GHSA-qgc7-mgm3-q253

Open SourceCoalition ESS < 30%CRITICAL2023-02-17

Uncontrolled Resource Consumption in golang.org/x/image

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

CVE-2022-41727

Open SourceCoalition ESS < 30%MEDIUM2023-02-17

Uncontrolled Resource Consumption in golang.org/x/image

CVEs:CVE-2022-41727

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

CVE-2022-41727

GoogleCoalition ESS < 30%HIGH2023-02-16

An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.

CVEs:CVE-2022-41727

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
image affected golang
tiff affected golang
Upstream advisory

GO-2023-1572

Open SourceCoalition ESS < 30%HIGH2023-02-16

Denial of service via crafted TIFF image in golang.org/x/image/tiff

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

CVE-2022-47339

Open SourceCoalition ESS < 30%CRITICAL2023-02-06

In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

CVEs:CVE-2022-47339

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-262503731

GoogleCoalition ESS < 30%CRITICAL2023-02-01

ASB-A-262503731

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21427

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition.

CVEs:CVE-2023-21427

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21419

Open SourceCoalition ESS < 30%HIGH2023-02-09

An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.

CVEs:CVE-2023-21419

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21438

Open SourceCoalition ESS < 30%LOW2023-02-09

Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.

CVEs:CVE-2023-21438

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21420

Open SourceCoalition ESS < 30%CRITICAL2023-02-09

Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.

CVEs:CVE-2023-21420

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21445

Open SourceCoalition ESS < 30%HIGH2023-02-09

Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.

CVEs:CVE-2023-21445

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21439

Open SourceCoalition ESS < 30%HIGH2023-02-09

Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2023-21439

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21435

Open SourceCoalition ESS < 30%HIGH2023-02-09

Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.

CVEs:CVE-2023-21435

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21430

Open SourceCoalition ESS < 30%HIGH2023-02-09

An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.

CVEs:CVE-2023-21430

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21440

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.

CVEs:CVE-2023-21440

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21102

GoogleCoalition ESS < 30%2023-02-08

In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-260821414References: Upstream kernel

CVEs:CVE-2023-21102

Upstream advisory

CVE-2023-21102

Open SourceCoalition ESS < 30%HIGH2023-02-08

In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...

CVEs:CVE-2023-21102

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20945

Open SourceCoalition ESS < 30%HIGH2023-02-06

In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2023-20945

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21446

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles.

CVEs:CVE-2023-21446

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21428

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.

CVEs:CVE-2023-21428

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21451

Open SourceCoalition ESS < 30%CRITICAL2023-02-09

A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.

CVEs:CVE-2023-21451

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2022-47451

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47451

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21426

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.

CVEs:CVE-2023-21426

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21421

Open SourceCoalition ESS < 30%HIGH2023-02-09

Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.

CVEs:CVE-2023-21421

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2022-32643

Open SourceCoalition ESS < 30%HIGH2023-02-06

In ccd, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS07341261.

CVEs:CVE-2022-32643

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21429

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.

CVEs:CVE-2023-21429

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21437

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.

CVEs:CVE-2023-21437

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21442

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information.

CVEs:CVE-2023-21442

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21424

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.

CVEs:CVE-2023-21424

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21425

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.

CVEs:CVE-2023-21425

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21436

Open SourceCoalition ESS < 30%LOW2023-02-09

Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.

CVEs:CVE-2023-21436

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21423

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.

CVEs:CVE-2023-21423

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21422

Open SourceCoalition ESS < 30%MEDIUM2023-02-09

Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.

CVEs:CVE-2023-21422

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2022-32595

Open SourceCoalition ESS < 30%MEDIUM2023-02-06

In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446236; Issu...

CVEs:CVE-2022-32595

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32642

Open SourceCoalition ESS < 30%HIGH2023-02-06

In ccd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326547; Issue ID: ALPS0732...

CVEs:CVE-2022-32642

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20481

Open SourceCoalition ESS < 30%MEDIUM2023-02-06

In multiple files, there is a possible way to preserve WiFi settings due to residual data after a reset. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product...

CVEs:CVE-2022-20481

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-240985973

GoogleCoalition ESS < 30%2023-02-01

PUB-A-240985973

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-20455

Open SourceCoalition ESS < 30%HIGH2023-02-06

In addAutomaticZenRule of ZenModeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2022-20455

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20932

Open SourceCoalition ESS < 30%MEDIUM2023-02-06

In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User in...

CVEs:CVE-2023-20932

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-245402502

GoogleCoalition ESS < 30%2023-02-01

ASB-A-245402502

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-47341

Open SourceCoalition ESS < 30%MEDIUM2023-02-12

In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

CVEs:CVE-2022-47341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21441

Open SourceCoalition ESS < 30%HIGH2023-02-09

Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.

CVEs:CVE-2023-21441

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-20615

Open SourceCoalition ESS < 30%HIGH2023-02-06

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629572; Issue ID: ...

CVEs:CVE-2023-20615

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20616

Open SourceCoalition ESS < 30%MEDIUM2023-02-06

In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07560...

CVEs:CVE-2023-20616

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20612

Open SourceCoalition ESS < 30%HIGH2023-02-06

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629571; Issue ID: ...

CVEs:CVE-2023-20612

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20613

Open SourceCoalition ESS < 30%HIGH2023-02-06

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628614; Issue ID: ...

CVEs:CVE-2023-20613

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20614

Open SourceCoalition ESS < 30%HIGH2023-02-06

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628615; Issue ID: ...

CVEs:CVE-2023-20614

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20609

Open SourceCoalition ESS < 30%MEDIUM2023-02-06

In ccu, there is a possible out of bounds read due to a logic error. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07570864; Issue ID: ALPS07570864.

CVEs:CVE-2023-20609

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20602

Open SourceCoalition ESS < 30%HIGH2023-02-06

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494107; Issue ID: ALP...

CVEs:CVE-2023-20602

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20604

Open SourceCoalition ESS < 30%HIGH2023-02-06

In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494067; Issue ID: ...

CVEs:CVE-2023-20604

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-261367136

GoogleCoalition ESS < 30%HIGH2023-02-01

ASB-A-261367136

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20605

Open SourceCoalition ESS < 30%MEDIUM2023-02-06

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07550104; Issue...

CVEs:CVE-2023-20605

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20606

Open SourceCoalition ESS < 30%MEDIUM2023-02-06

In apusys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07571104; Issue ID:...

CVEs:CVE-2023-20606

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47361

Open SourceCoalition ESS < 30%HIGH2023-02-12

In firewall service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

CVEs:CVE-2022-47361

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20551

Open SourceCoalition ESS < 30%MEDIUM2023-02-06

In createTrack of AudioFlinger.cpp, there is a possible way to record audio without a privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ...

CVEs:CVE-2022-20551

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-44421

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local In wlan driver, information disclosure.

CVEs:CVE-2022-44421

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38681

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-38681

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47452

Open SourceCoalition ESS < 30%CRITICAL2023-02-12

In gnss driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47452

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47347

Open SourceCoalition ESS < 30%HIGH2023-02-12

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.

CVEs:CVE-2022-47347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47348

Open SourceCoalition ESS < 30%HIGH2023-02-12

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.

CVEs:CVE-2022-47348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47342

Open SourceCoalition ESS < 30%HIGH2023-02-12

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.

CVEs:CVE-2022-47342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47343

Open SourceCoalition ESS < 30%HIGH2023-02-12

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.

CVEs:CVE-2022-47343

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47344

Open SourceCoalition ESS < 30%HIGH2023-02-12

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.

CVEs:CVE-2022-47344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47345

Open SourceCoalition ESS < 30%HIGH2023-02-12

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.

CVEs:CVE-2022-47345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47346

Open SourceCoalition ESS < 30%HIGH2023-02-12

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.

CVEs:CVE-2022-47346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38674

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-38674

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38675

Open SourceCoalition ESS < 30%CRITICAL2023-02-12

In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-38675

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38680

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-38680

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20934

Open SourceCoalition ESS < 30%HIGH2023-02-06

In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the microphone privacy indicator due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User ...

CVEs:CVE-2023-20934

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20608

Open SourceCoalition ESS < 30%HIGH2023-02-06

In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363599; Issue ID: ALP...

CVEs:CVE-2023-20608

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20610

Open SourceCoalition ESS < 30%HIGH2023-02-06

In display drm, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363469; Issue ID: ...

CVEs:CVE-2023-20610

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20611

Open SourceCoalition ESS < 30%HIGH2023-02-06

In gpu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588678; Issue ID: ALPS07588678.

CVEs:CVE-2023-20611

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47363

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47363

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47364

Open SourceCoalition ESS < 30%CRITICAL2023-02-12

In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47364

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47368

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47368

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47369

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47369

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20949

Open SourceCoalition ESS < 30%HIGH2023-02-06

In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2023-20949

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-259323133

GoogleCoalition ESS < 30%HIGH2023-02-01

PUB-A-259323133

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20607

Open SourceCoalition ESS < 30%HIGH2023-02-06

In ccu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07512839; Issue ID: ALPS0751...

CVEs:CVE-2023-20607

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47450

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVEs:CVE-2022-47450

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47365

Open SourceCoalition ESS < 30%CRITICAL2023-02-12

In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47365

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47366

Open SourceCoalition ESS < 30%CRITICAL2023-02-12

In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47366

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47370

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47370

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47327

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVEs:CVE-2022-47327

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47330

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVEs:CVE-2022-47330

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47332

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVEs:CVE-2022-47332

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47333

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVEs:CVE-2022-47333

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42783

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42783

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-44447

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible null pointer dereference issue due to a missing bounds check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-44447

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-44448

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-44448

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47322

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47322

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-38686

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-38686

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20443

Open SourceCoalition ESS < 30%HIGH2023-02-06

In hasInputInfo of Layer.cpp, there is a possible bypass of user interaction requirements due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2022-20443

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47367

Open SourceCoalition ESS < 30%HIGH2023-02-12

In bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-47367

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47371

Open SourceCoalition ESS < 30%CRITICAL2023-02-12

In bt driver, there is a thread competition leads to early release of resources to be accessed. This could lead to local denial of service in kernel.

CVEs:CVE-2022-47371

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47357

Open SourceCoalition ESS < 30%HIGH2023-02-12

In log service, there is a missing permission check. This could lead to local denial of service in log service.

CVEs:CVE-2022-47357

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47358

Open SourceCoalition ESS < 30%HIGH2023-02-12

In log service, there is a missing permission check. This could lead to local denial of service in log service.

CVEs:CVE-2022-47358

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47359

Open SourceCoalition ESS < 30%HIGH2023-02-12

In log service, there is a missing permission check. This could lead to local denial of service in log service.

CVEs:CVE-2022-47359

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47360

Open SourceCoalition ESS < 30%HIGH2023-02-12

In log service, there is a missing permission check. This could lead to local denial of service in log service.

CVEs:CVE-2022-47360

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20927

Open SourceCoalition ESS < 30%HIGH2023-02-15

In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2023-20927

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47324

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVEs:CVE-2022-47324

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47325

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVEs:CVE-2022-47325

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47326

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVEs:CVE-2022-47326

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47328

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVEs:CVE-2022-47328

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47329

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVEs:CVE-2022-47329

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47323

Open SourceCoalition ESS < 30%HIGH2023-02-12

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47323

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47354

Open SourceCoalition ESS < 30%HIGH2023-02-12

In log service, there is a missing permission check. This could lead to local denial of service in log service.

CVEs:CVE-2022-47354

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47355

Open SourceCoalition ESS < 30%HIGH2023-02-12

In log service, there is a missing permission check. This could lead to local denial of service in log service.

CVEs:CVE-2022-47355

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47356

Open SourceCoalition ESS < 30%HIGH2023-02-12

In log service, there is a missing permission check. This could lead to local denial of service in log service.

CVEs:CVE-2022-47356

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20618

Open SourceCoalition ESS < 30%HIGH2023-02-06

In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519184; Issue ID: ALPS0751...

CVEs:CVE-2023-20618

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20619

Open SourceCoalition ESS < 30%HIGH2023-02-06

In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519159; Issue ID: ALPS0751...

CVEs:CVE-2023-20619

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20939

Open SourceCoalition ESS < 30%HIGH2023-02-06

In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2023-20939

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20942

Open SourceCoalition ESS < 30%MEDIUM2023-02-06

In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privilege...

CVEs:CVE-2023-20942

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47331

Open SourceCoalition ESS < 30%HIGH2023-02-06

In wlan driver, there is a race condition. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47331

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20940

Open SourceCoalition ESS < 30%HIGH2023-02-06

In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2023-20940

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-xhjq-w7xm-p8qj

Open SourceEPSS <= 49%HIGH2023-02-07

golang.org/x/crypto/ssh Man-in-the-Middle attack

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-xhjq-w7xm-p8qj

Open SourceEPSS <= 49%HIGH2023-02-07

golang.org/x/crypto/ssh Man-in-the-Middle attack

Affected products

ProductStatusVendorPackageEcosystem
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CVE-2023-23374

Open SourceEPSS <= 49%CRITICAL2023-02-09

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2023-23374

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-4jx2-hvqw-93j9

GoogleEPSS <= 49%HIGH2023-02-20

dd-plist XML External Entitly vulnerability

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.plist:dd-plist affected Maven com.googlecode.plist:dd-plist
Upstream advisory

GHSA-4jx2-hvqw-93j9

GoogleEPSS <= 49%HIGH2023-02-20

dd-plist XML External Entitly vulnerability

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.plist:dd-plist affected Maven com.googlecode.plist:dd-plist
Upstream advisory

CVE-2016-15026

GoogleEPSS <= 49%HIGH2023-02-20

A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. An attack has to be approached locally. Upgrading to versio...

CVEs:CVE-2016-15026

Affected products

ProductStatusVendorPackageEcosystem
dd-plist affected dd-plist_project
Upstream advisory

CVE-2016-15026

GoogleEPSS <= 49%HIGH2023-02-20

dd-plist XML External Entitly vulnerability

CVEs:CVE-2016-15026

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.plist:dd-plist affected Maven com.googlecode.plist:dd-plist
Upstream advisory

GHSA-74fp-r6jw-h4mp

Open SourceAll remainingHIGH2023-02-08

Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing

Affected products

ProductStatusVendorPackageEcosystem
apimachinery affected k8s.io k8s.io/apimachinery
apimachinery affected k8s.io k8s.io/apimachinery
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

GHSA-74fp-r6jw-h4mp

Open SourceAll remainingHIGH2023-02-08

Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing

Affected products

ProductStatusVendorPackageEcosystem
apimachinery affected k8s.io k8s.io/apimachinery
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.