CVE-2023-23397
CVEs:CVE-2023-23397
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 19 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
CVEs:CVE-2023-23397
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| 365_apps | affected | microsoft | — | — |
| office | affected | microsoft | — | — |
| office_long_term_servicing_channel | affected | microsoft | — | — |
| outlook | affected | microsoft | — | — |
Microsoft Outlook Elevation of Privilege Vulnerability
CVEs:CVE-2023-23397
CVEs:CVE-2023-32435
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple i...
CVEs:CVE-2023-32435
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| safari | affected | apple | — | — |
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
CVEs:CVE-2023-32435
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
CVEs:CVE-2023-32435
CVEs:CVE-2023-20963
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android...
CVEs:CVE-2023-20963
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519
CVEs:CVE-2023-20963
CVE-2023-25668 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25668 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
CVEs:CVE-2023-25668
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
CVEs:CVE-2023-25668
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in Tensor...
CVEs:CVE-2023-25668
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CVEs:CVE-2023-0037
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
CVEs:CVE-2023-0037
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| map_builder_for_google_maps | affected | 10web | — | — |
CVEs:CVE-2023-24892
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
CVEs:CVE-2023-24892
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
PUB-A-265822830
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-274463883
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-274464337
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-274465028
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
angular vulnerable to regular expression denial of service via the $resource service
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
| solr | affected | chainguard | solr | — |
| solr | affected | wolfi | solr | — |
angular vulnerable to regular expression denial of service via the $resource service
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
angular vulnerable to regular expression denial of service via the angular.copy() utility
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
angular vulnerable to regular expression denial of service via the angular.copy() utility
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
| solr | affected | wolfi | solr | — |
| solr | affected | chainguard | solr | — |
DEBIAN-CVE-2023-26116
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular.js | affected | Debian:14 | angular.js | — |
| angular.js | affected | Debian:11 | angular.js | — |
| angular.js | affected | Debian:12 | angular.js | — |
| angular.js | affected | Debian:13 | angular.js | — |
DEBIAN-CVE-2023-26117
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular.js | affected | Debian:11 | angular.js | — |
| angular.js | affected | Debian:12 | angular.js | — |
| angular.js | affected | Debian:13 | angular.js | — |
| angular.js | affected | Debian:14 | angular.js | — |
angular vulnerable to regular expression denial of service via the angular.copy() utility
CVEs:CVE-2023-26116
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
angular vulnerable to regular expression denial of service via the $resource service
CVEs:CVE-2023-26117
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
angular vulnerable to regular expression denial of service via the $resource service
CVEs:CVE-2023-26117
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-craft...
CVEs:CVE-2023-26117
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angularjs | affected | angularjs | — | — |
| fedora | affected | fedoraproject | — | — |
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large ...
CVEs:CVE-2023-26116
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angularjs | affected | angularjs | — | — |
| fedora | affected | fedoraproject | — | — |
angular vulnerable to regular expression denial of service via the angular.copy() utility
CVEs:CVE-2023-26116
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
CVEs:CVE-2023-1534
DEBIAN-CVE-2023-1534
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1534
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2023-1532
DEBIAN-CVE-2023-1532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2023-1528
DEBIAN-CVE-2023-1528
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1528
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-server-side-configuration | affected | npm | angular-server-side-configuration | — |
angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-server-side-configuration | affected | npm | angular-server-side-configuration | — |
angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend
CVEs:CVE-2023-28444
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-server-side-configuration | affected | npm | angular-server-side-configuration | — |
angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables. angular-server-side-configuration detects used environment variables in TypeScript (.ts) files during ...
CVEs:CVE-2023-28444
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-server-side-configuration | affected | angular-server-side-configuration_project | — | — |
angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend
CVEs:CVE-2023-28444
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-server-side-configuration | affected | npm | angular-server-side-configuration | — |
CVEs:CVE-2023-28261
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2023-28261
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVE-2023-25671 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25671 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
TensorFlow has segmentation fault in tfg-translate
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
TensorFlow has segmentation fault in tfg-translate
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | tensorflow | — | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
TensorFlow has segmentation fault in tfg-translate
CVEs:CVE-2023-25671
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
TensorFlow is an open source platform for machine learning. There is out-of-bounds access due to mismatched integer type sizes. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
CVEs:CVE-2023-25671
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has segmentation fault in tfg-translate
CVEs:CVE-2023-25671
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
CVE-2023-25664 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25664 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
TensorFlow has Heap-buffer-overflow in AvgPoolGrad
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
TensorFlow has Heap-buffer-overflow in AvgPoolGrad
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
TensorFlow has Heap-buffer-overflow in AvgPoolGrad
CVEs:CVE-2023-25664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
TensorFlow has Heap-buffer-overflow in AvgPoolGrad
CVEs:CVE-2023-25664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.
CVEs:CVE-2023-25664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
CVE-2023-25676 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-27579 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25676 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-27579 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-25659 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25660 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25669 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25662 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25675 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25673 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25670 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25663 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25674 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25659 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-25660 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-25662 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-25663 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-25669 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-25670 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-25673 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-25674 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-25675 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to integer overflow in EditDistance
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to integer overflow in EditDistance
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in TensorArrayConcatV2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in TensorArrayConcatV2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Floating Point Exception in AvgPoolGrad with XLA
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Floating Point Exception in AvgPoolGrad with XLA
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Floating Point Exception in TensorListSplit with XLA
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Floating Point Exception in TensorListSplit with XLA
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Segfault in Bincount with XLA
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Segfault in Bincount with XLA
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has null dereference on ParallelConcat with XLA
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has null dereference on ParallelConcat with XLA
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Floating Point Exception in TFLite in conv kernel
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Floating Point Exception in TFLite in conv kernel
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
CVEs:CVE-2023-25659
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the parameter `indices` for `DynamicStitch` does not match the shape of the parameter `data`, it can trigger an stack OOB read. A fix is included in Ten...
CVEs:CVE-2023-25659
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
CVEs:CVE-2023-25659
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `summarize` of `tf.raw_ops.Print` is zero, the new method `SummarizeArray<bool>` will reference to a nullptr, leading to a seg fault. A ...
CVEs:CVE-2023-25660
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`
CVEs:CVE-2023-25660
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`
CVEs:CVE-2023-25660
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overflow in EditDistance. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
CVEs:CVE-2023-25662
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to integer overflow in EditDistance
CVEs:CVE-2023-25662
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to integer overflow in EditDistance
CVEs:CVE-2023-25662
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `ctx->step_containter()` is a null ptr, the Lookup function will be executed with a null pointer. A fix is included in TensorFlow 2.12.0 and 2.11.1.
CVEs:CVE-2023-25663
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has Null Pointer Error in TensorArrayConcatV2
CVEs:CVE-2023-25663
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in TensorArrayConcatV2
CVEs:CVE-2023-25663
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Floating Point Exception in AvgPoolGrad with XLA
CVEs:CVE-2023-25669
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Floating Point Exception in AvgPoolGrad with XLA
CVEs:CVE-2023-25669
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the stride and window size are not positive for `tf.raw_ops.AvgPoolGrad`, it can give a floating point exception. A fix is included in TensorFlow versio...
CVEs:CVE-2023-25669
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize
CVEs:CVE-2023-25670
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize
CVEs:CVE-2023-25670
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
CVEs:CVE-2023-25670
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has Floating Point Exception in TensorListSplit with XLA
CVEs:CVE-2023-25673
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a Floating Point Exception in TensorListSplit with XLA. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
CVEs:CVE-2023-25673
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has Floating Point Exception in TensorListSplit with XLA
CVEs:CVE-2023-25673
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
CVEs:CVE-2023-25674
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
CVEs:CVE-2023-25674
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source machine learning platform. Versions prior to 2.12.0 and 2.11.1 have a null pointer error in RandomShuffle with XLA enabled. A fix is included in TensorFlow 2.12.0 and 2.11.1.
CVEs:CVE-2023-25674
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has Segfault in Bincount with XLA
CVEs:CVE-2023-25675
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Segfault in Bincount with XLA
CVEs:CVE-2023-25675
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.Bincount` segfaults when given a parameter `weights` that is neither the same shape as parameter `arr` nor a length-0 tensor....
CVEs:CVE-2023-25675
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has null dereference on ParallelConcat with XLA
CVEs:CVE-2023-25676
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.ParallelConcat` segfaults with a nullptr dereference when given a parameter `shape` with rank that is not greater than zero. ...
CVEs:CVE-2023-25676
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has null dereference on ParallelConcat with XLA
CVEs:CVE-2023-25676
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an end-to-end open source platform for machine learning. Constructing a tflite model with a paramater `filter_input_channel` of less than 1 gives a FPE. This issue has been patched in version 2.12. TensorFlow will also cherrypick the fix ...
CVEs:CVE-2023-27579
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has Floating Point Exception in TFLite in conv kernel
CVEs:CVE-2023-27579
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Floating Point Exception in TFLite in conv kernel
CVEs:CVE-2023-27579
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CVE-2023-25658 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25666 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25658 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-25666 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
TensorFlow has Floating Point Exception in AudioSpectrogram
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Floating Point Exception in AudioSpectrogram
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad
CVEs:CVE-2023-25658
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad
CVEs:CVE-2023-25658
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, an out of bounds read is in GRUBlockCellGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.
CVEs:CVE-2023-25658
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has Floating Point Exception in AudioSpectrogram
CVEs:CVE-2023-25666
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a floating point exception in AudioSpectrogram. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
CVEs:CVE-2023-25666
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has Floating Point Exception in AudioSpectrogram
CVEs:CVE-2023-25666
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CVE-2023-25672 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25672 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
TensorFlow has Null Pointer Error in LookupTableImportV2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in LookupTableImportV2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in LookupTableImportV2
CVEs:CVE-2023-25672
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. The function `tf.raw_ops.LookupTableImportV2` cannot handle scalars in the `values` parameter and gives an NPE. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
CVEs:CVE-2023-25672
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has Null Pointer Error in LookupTableImportV2
CVEs:CVE-2023-25672
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CVE-2023-25667 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25667 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
TensorFlow vulnerable to segfault when opening multiframe gif
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault when opening multiframe gif
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow vulnerable to segfault when opening multiframe gif
CVEs:CVE-2023-25667
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, integer overflow occurs when `2^31 <= num_frames * height * width * channels < 2^32`, for example Full HD screencast of at least 346 frames. A fix is inclu...
CVEs:CVE-2023-25667
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow vulnerable to segfault when opening multiframe gif
CVEs:CVE-2023-25667
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CVE-2023-25801 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25801 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
TensorFlow has double free in Fractional(Max/Avg)Pool
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has double free in Fractional(Max/Avg)Pool
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has double free in Fractional(Max/Avg)Pool
CVEs:CVE-2023-25801
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first and fourth elements of their parameter `pooling_ratio` to be equal to 1.0...
CVEs:CVE-2023-25801
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has double free in Fractional(Max/Avg)Pool
CVEs:CVE-2023-25801
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
CVEs:CVE-2023-20936
In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2023-20936
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
CVEs:CVE-2023-1234
Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-1234
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1234
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Fix CVE(s): CVE-2023-24329
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.5 | affected | TuxCare:Ubuntu:16.04 | idle-python3.5 | — |
| libpython3.5 | affected | TuxCare:Ubuntu:16.04 | libpython3.5 | — |
| libpython3.5-dev | affected | TuxCare:Ubuntu:16.04 | libpython3.5-dev | — |
| libpython3.5-minimal | affected | TuxCare:Ubuntu:16.04 | libpython3.5-minimal | — |
| libpython3.5-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython3.5-stdlib | — |
| libpython3.5-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython3.5-testsuite | — |
| python3.5 | affected | TuxCare:Ubuntu:16.04 | python3.5 | — |
| python3.5-dev | affected | TuxCare:Ubuntu:16.04 | python3.5-dev | — |
| python3.5-doc | affected | TuxCare:Ubuntu:16.04 | python3.5-doc | — |
| python3.5-examples | affected | TuxCare:Ubuntu:16.04 | python3.5-examples | — |
| python3.5-minimal | affected | TuxCare:Ubuntu:16.04 | python3.5-minimal | — |
| python3.5-venv | affected | TuxCare:Ubuntu:16.04 | python3.5-venv | — |
Fix CVE(s): CVE-2023-24329
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:16.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:16.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:16.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:16.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:16.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:16.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:16.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:16.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:16.04 | python2.7-minimal | — |
Security update for google-guest-agent
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-guest-agent | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | google-guest-agent | — |
Security update for google-osconfig-agent
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-osconfig-agent | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | google-osconfig-agent | — |
| google-osconfig-agent | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | google-osconfig-agent | — |
| google-osconfig-agent | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | google-osconfig-agent | — |
| google-osconfig-agent | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | google-osconfig-agent | — |
| google-osconfig-agent | affected | openSUSE:Leap 15.4 | google-osconfig-agent | — |
Security update for google-osconfig-agent
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-osconfig-agent | affected | SUSE:Linux Enterprise Module for Public Cloud 12 | google-osconfig-agent | — |
Security update for google-guest-agent
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-guest-agent | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | google-guest-agent | — |
| google-guest-agent | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | google-guest-agent | — |
| google-guest-agent | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | google-guest-agent | — |
| google-guest-agent | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | google-guest-agent | — |
| google-guest-agent | affected | openSUSE:Leap 15.4 | google-guest-agent | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:22.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
| golang | affected | openEuler:22.03-LTS | golang | — |
Updated golang packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:8 | golang | — |
CVE-2023-27534 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-27533 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-27537 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
angular vulnerable to regular expression denial of service via the <input type="url"> element
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
| solr | affected | chainguard | solr | — |
| solr | affected | wolfi | solr | — |
angular vulnerable to regular expression denial of service via the <input type="url"> element
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
DEBIAN-CVE-2023-26118
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular.js | affected | Debian:11 | angular.js | — |
| angular.js | affected | Debian:12 | angular.js | — |
| angular.js | affected | Debian:13 | angular.js | — |
| angular.js | affected | Debian:14 | angular.js | — |
angular vulnerable to regular expression denial of service via the <input type="url"> element
CVEs:CVE-2023-26118
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
angular vulnerable to regular expression denial of service via the <input type="url"> element
CVEs:CVE-2023-26118
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerabili...
CVEs:CVE-2023-26118
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angularjs | affected | angularjs | — | — |
| fedora | affected | fedoraproject | — | — |
Kubernetes vulnerable to validation bypass
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes/kubernetes | affected | github.com | github.com/kubernetes/kubernetes | — |
Kubernetes vulnerable to validation bypass
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes/kubernetes | affected | github.com | github.com/kubernetes/kubernetes | — |
DEBIAN-CVE-2022-3294
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:14 | kubernetes | — |
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:13 | kubernetes | — |
Kubernetes vulnerable to validation bypass
CVEs:CVE-2022-3294
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes/kubernetes | affected | github.com | github.com/kubernetes/kubernetes | — |
Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-...
CVEs:CVE-2022-3294
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | kubernetes | — | — |
CVE-2023-27535 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2023-27536 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
Updated protobuf packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | Mageia:8 | protobuf | — |
CVE-2023-27538 affecting package tensorflow for versions less than 2.16.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
CVE-2022-4904 affecting package grpc for versions less than 1.62.0-2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc | affected | Azure Linux:3 | grpc | — |
Kubernetes vulnerable to path traversal
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes/kubernetes | affected | github.com | github.com/kubernetes/kubernetes | — |
Kubernetes vulnerable to path traversal
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes/kubernetes | affected | github.com | github.com/kubernetes/kubernetes | — |
CVE-2022-3162 affecting package kubernetes for versions less than 1.25.4-0
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Azure Linux:2 | kubernetes | — |
DEBIAN-CVE-2022-3162
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:13 | kubernetes | — |
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:14 | kubernetes | — |
CVE-2023-24532 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-24532 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-24532 affecting package golang for versions less than 1.20.2-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVE-2023-24532 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVEs:CVE-2023-24532
DEBIAN-CVE-2023-24532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.
CVEs:CVE-2023-24532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.
CVEs:CVE-2023-24532
Incorrect calculation on P256 curves in crypto/internal/nistec
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go-1.20 | affected | chainguard | go-1.20 | — |
| go-1.20 | affected | wolfi | go-1.20 | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| stdlib | affected | Go | — | — |
| stdlib | affected | Go | stdlib | — |
In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A
CVEs:CVE-2023-21036
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21036
PUB-A-264261868
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-240019719
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and uninstall applications for all users due to a missing permission check. This could lead to local escalation of privilege with no addition...
CVEs:CVE-2023-20955
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20955
In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2023-20911
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20911
In btm_ble_rand_enc_complete of btm_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2023-20983
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20983
CVEs:CVE-2023-21035
In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same package name due to a permissions bypass. This could lead to local escalation of privilege with no additio...
CVEs:CVE-2023-21035
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1531
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| chromium | affected | chromium | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2023-1531
DEBIAN-CVE-2023-1531
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-1229
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1229
DEBIAN-CVE-2023-1229
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Heap buffer overflow in Metrics in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1219
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1219
DEBIAN-CVE-2023-1219
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)
CVEs:CVE-2023-1529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2023-1529
DEBIAN-CVE-2023-1529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1220
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1220
DEBIAN-CVE-2023-1220
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-1533
DEBIAN-CVE-2023-1533
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in WebProtect in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1533
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1530
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2023-1530
DEBIAN-CVE-2023-1530
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
CVEs:CVE-2022-42499
In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2022-42499
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-242001391
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2022-42498
In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVEs:CVE-2022-42498
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-240662453
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-1214
Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1214
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1214
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Updated chromium-browser-stable packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:8 | chromium-browser-stable | — |
CVEs:CVE-2022-44580
SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.
CVEs:CVE-2022-44580
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| plugin_for_google_reviews | affected | richplugins | — | — |
Heap buffer overflow in Web Audio API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-1222
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1222
DEBIAN-CVE-2023-1222
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1215
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1215
DEBIAN-CVE-2023-1215
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1216
CVEs:CVE-2023-1218
Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1218
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2023-1218
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-21054
In EUTRAN_LCS_ConvertLCS_MOLRReq of LPP_CommonUtil.c, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2023-21054
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-244556535
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-1217
Stack buffer overflow in Crash reporting in Google Chrome on Windows prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chr...
CVEs:CVE-2023-1217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-1213
Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-1213
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1213
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to potentially spoof the contents of the omnibox via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-1231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1231
DEBIAN-CVE-2023-1231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-20532
In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2022-20532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21057
In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2023-21057
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21058
In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2023-21058
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20951
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2023-20951
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20954
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2023-20954
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-244450646
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-246169606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2023-21027
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21027
CVEs:CVE-2023-1232
Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to obtain potentially sensitive information from API via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-1232
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1232
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-1226
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1226
Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-1236
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1236
DEBIAN-CVE-2023-1226
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2023-1236
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-1227
Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity:...
CVEs:CVE-2023-1227
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1227
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-1224
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1224
DEBIAN-CVE-2023-1224
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-1228
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-1228
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1228
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
In parse_printerAttributes of ipphelper.c, there is a possible out of bounds read due to a string without a null-terminator. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2023-21028
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21028
In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2023-21053
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21053
In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interacti...
CVEs:CVE-2023-21059
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21059
CVEs:CVE-2023-21060
In sms_GetTpPiIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2023-21060
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-247564044
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-251805610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-253770924
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-1235
DEBIAN-CVE-2023-1235
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Type confusion in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted UI interaction. (Chromium security severity: Low)
CVEs:CVE-2023-1235
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1223
Insufficient policy enforcement in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-1223
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1223
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| coredns/coredns | affected | github.com | github.com/coredns/coredns | — |
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| coredns | affected | chainguard | coredns | — |
| coredns | affected | wolfi | coredns | — |
| coredns/coredns | affected | github.com | github.com/coredns/coredns | — |
| coredns-fips | affected | chainguard | coredns-fips | — |
| juicefs-1.2 | affected | chainguard | juicefs-1.2 | — |
| juicefs-1.3 | affected | chainguard | juicefs-1.3 | — |
| juicefs-1.3 | affected | wolfi | juicefs-1.3 | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4452
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4452
Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 111.0.5563.64 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-1225
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1225
DEBIAN-CVE-2023-1225
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-1233
Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from API via a crafted Chrome Extension. (C...
CVEs:CVE-2023-1233
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1233
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-1221
Insufficient policy enforcement in Extensions API in Google Chrome prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security sev...
CVEs:CVE-2023-1221
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-1221
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The PIN is 5 to 8 ...
CVEs:CVE-2021-36689
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| samourai-wallet-android | affected | samourai-wallet-android_project | — | — |
CVEs:CVE-2021-36689
Product: AndroidVersions: Android kernelAndroid ID: A-229255400References: N/A
CVEs:CVE-2023-21061
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21061
PUB-A-229255400
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-21459
Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.
CVEs:CVE-2023-21459
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Product: AndroidVersions: Android kernelAndroid ID: A-254114726References: N/A
CVEs:CVE-2023-21067
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21067
PUB-A-254114726
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious WebApp to spoof the contents of the PWA installer via a crafted HTML page. (Chromium secu...
CVEs:CVE-2023-1230
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-1230
DEBIAN-CVE-2023-1230
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.
CVEs:CVE-2023-21454
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21454
CVEs:CVE-2023-20960
In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User inter...
CVEs:CVE-2023-20960
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
CVEs:CVE-2023-21456
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21456
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| coredns | affected | wolfi | coredns | — |
| coredns | affected | chainguard | coredns | — |
| coredns/coredns | affected | github.com | github.com/coredns/coredns | — |
| coredns-fips | affected | chainguard | coredns-fips | — |
| juicefs-1.2 | affected | chainguard | juicefs-1.2 | — |
| juicefs-1.3 | affected | chainguard | juicefs-1.3 | — |
| juicefs-1.3 | affected | wolfi | juicefs-1.3 | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| coredns/coredns | affected | github.com | github.com/coredns/coredns | — |
CVEs:CVE-2023-21453
Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
CVEs:CVE-2023-21453
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21457
Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.
CVEs:CVE-2023-21457
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.
CVEs:CVE-2023-21449
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21449
ASB-A-261470730
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
CVEs:CVE-2023-21460
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21460
CVEs:CVE-2023-21458
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
CVEs:CVE-2023-21458
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21012
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21012
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
CVEs:CVE-2023-21452
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21452
Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
CVEs:CVE-2023-21461
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21461
In read_paint of ttcolr.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2023-20958
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20958
In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory ...
CVEs:CVE-2023-20926
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20926
CVEs:CVE-2023-20987
In btm_read_link_quality_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over Bluetooth with System execution privileges needed. User interaction is not neede...
CVEs:CVE-2023-20987
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In btm_read_rssi_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not need...
CVEs:CVE-2023-20988
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20988
CVEs:CVE-2023-20992
In on_iso_link_quality_read of btm_iso_impl.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is no...
CVEs:CVE-2023-20992
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20542
In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2022-20542
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20910
In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2023-20910
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-42528
In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2022-42528
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-242203672
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2023-20917
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20917
PUB-A-235113793
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
| vendor/opensource/camera-kernel | affected | platform | platform/vendor/opensource/camera-kernel | — |
CVEs:CVE-2023-20953
In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to bypass factory reset protection due to incorrect UI being shown prior to setup completion. This could lead to local escalation of privilege with no additional execution privi...
CVEs:CVE-2023-20953
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20964
In multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local denial of service or escalation of privilege with no additional execution privileges needed. User interaction is...
CVEs:CVE-2023-20964
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-193434313
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
| qcom/sepolicy_vndr | affected | device | device/qcom/sepolicy_vndr | — |
In append_camera_metadata of camera_metadata.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2023-21049
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21049
In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07635697; Is...
CVEs:CVE-2023-20634
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20634
PUB-A-236688120
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-0460
The YouTube Embedded 1.2 SDK binds to a service within the YouTube Main App. After binding, a remote context is created with the flags Context.CONTEXT_INCLUDE_CODE | Context.CONTEXT_IGNORE_SECURITY. This allows the client app to remotely load code from...
CVEs:CVE-2023-0460
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| youtube_android_player_api | affected | — | — |
CVEs:CVE-2023-21002
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2023-21002
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20635
In keyinstall, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issu...
CVEs:CVE-2023-20635
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2023-21034
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21034
CVEs:CVE-2023-20971
In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privi...
CVEs:CVE-2023-20971
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-42500
In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2022-42500
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-239701389
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution ...
CVEs:CVE-2023-20976
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20976
In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploit...
CVEs:CVE-2022-20467
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-20467
CVEs:CVE-2023-21024
In maybeFinish of FallbackHome.java, there is a possible delay of lockdown screen due to logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21024
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21040
In buildCommand of bluetooth_ccc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2023-21040
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-238420277
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-21072
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2023-21072
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2023-21073
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21073
CVEs:CVE-2023-21075
In get_svc_hash of nan.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2023-21075
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2023-21077
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21077
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2023-21078
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21078
CVEs:CVE-2023-21079
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21079
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628505; Issue ID: ...
CVEs:CVE-2023-20630
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20630
CVEs:CVE-2023-20632
In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628506; Issue ID: ...
CVEs:CVE-2023-20632
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20966
In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2023-20966
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-254839721
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-254840211
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-257289560
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-257290396
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-257290781
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-261857862
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-21041
In append_to_params of param_util.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2023-21041
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after a Target SDK update due to a permissions bypass. This could lead to local escalation of privilege after updating an app to a higher...
CVEs:CVE-2023-20906
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20906
CVEs:CVE-2023-20947
In getGroupState of GrantPermissionsViewModel.kt, there is a possible way to keep a one-time permission granted due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...
CVEs:CVE-2023-20947
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-250123688
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In registerSignalHandlers of main.c, there is a possible local arbitrary code execution due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2023-21020
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21020
CVEs:CVE-2023-21042
In (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...
CVEs:CVE-2023-21042
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...
CVEs:CVE-2023-21043
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21043
In ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2023-21046
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21046
CVEs:CVE-2023-21047
In ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2023-21047
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20931
In avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2023-20931
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-239872581
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-239873326
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-253424924
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-256166866
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-20968
In multiple functions of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-20968
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-20969
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20969
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-20970
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20970
In btu_ble_rc_param_req_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2023-20981
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20981
CVEs:CVE-2023-20982
In btm_read_tx_power_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not ...
CVEs:CVE-2023-20982
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In btm_ble_clear_resolving_list_completecomplete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is n...
CVEs:CVE-2023-20986
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20986
CVEs:CVE-2023-20989
In btm_ble_write_adv_enable_complete of btm_ble_gap.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2023-20989
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20990
In btm_ble_rand_enc_complete of btm_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2023-20990
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21006
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21006
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21007
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21007
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21008
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21008
CVEs:CVE-2023-21009
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21009
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21010
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21010
CVEs:CVE-2023-21011
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21050
In load_png_image of ExynosHWCHelper.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2023-21050
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In dwc3_exynos_clk_get of dwc3-exynos.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2023-21051
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21051
CVEs:CVE-2023-21076
In createTransmitFollowupRequest of nan.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2023-21076
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47461
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
CVEs:CVE-2022-47461
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
CVEs:CVE-2022-47462
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47462
ASB-A-264834026
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-264834568
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-244423702
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-259323322
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-261857623
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-20985
In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2023-20985
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20993
In multiple functions of SnoozeHelper.java, there is a possible failure to persist settings due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2023-20993
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20994
In _ufdt_output_property_to_fdt of ufdt_convert.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2023-20994
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21017
In InstallStart of InstallStart.java, there is a possible way to change the installer package name due to an improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...
CVEs:CVE-2023-21017
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In UnwindingWorker of unwinding.cc, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVEs:CVE-2023-21018
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21018
CVEs:CVE-2023-21022
In BufferBlock of Suballocation.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2023-21022
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not ...
CVEs:CVE-2023-21030
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21030
CVEs:CVE-2023-21032
In _ufdt_output_node_to_fdt of ufdt_convert.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2023-21032
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In cs40l2x_cp_trigger_queue_show of cs40l2x.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2023-21038
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21038
CVEs:CVE-2023-21052
In setToExternal of ril_external_client.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2023-21052
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21056
In lwis_slc_buffer_free of lwis_device_slc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2023-21056
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21062
In DoSetTempEcc of imsservice.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2023-21062
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21063
In ParseWithAuthType of simdata.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2023-21063
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In DoSetPinControl of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21064
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21064
CVEs:CVE-2023-21065
In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...
CVEs:CVE-2023-21065
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21069
In wl_update_hidden_ap_ie of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2023-21069
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In add_roam_cache_list of wl_roam.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2023-21070
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21070
In dhd_prot_ioctcmplt_process of dhd_msgbuf.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2023-21071
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21071
CVEs:CVE-2023-20636
In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292593; Is...
CVEs:CVE-2023-20636
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628588; Issue ID: ...
CVEs:CVE-2023-20637
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20637
CVEs:CVE-2023-20638
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628537; Issue ID: ...
CVEs:CVE-2023-20638
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628587; Issue ID: ...
CVEs:CVE-2023-20639
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20639
CVEs:CVE-2023-20640
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629573; Issue ID: ...
CVEs:CVE-2023-20640
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20641
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629574; Issue ID: ...
CVEs:CVE-2023-20641
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628586; Issue ID: ...
CVEs:CVE-2023-20642
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20642
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628584; Issue ID: ...
CVEs:CVE-2023-20643
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20643
In apu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629577; Issue ID: ...
CVEs:CVE-2023-20650
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20650
CVEs:CVE-2023-20624
In vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628530; Issue I...
CVEs:CVE-2023-20624
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In pqframework, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629585; Is...
CVEs:CVE-2023-20627
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20627
PUB-A-224000736
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-239630493
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-243129862
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-243130078
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-243376770
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-245300559
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-254028518
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-254028776
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-254029309
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-259063189
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-20973
In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2023-20973
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not n...
CVEs:CVE-2023-20974
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20974
In btm_ble_read_remote_features_complete of btm_ble_gap.cc, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure if the firmware were compromised with System execution privileges neede...
CVEs:CVE-2023-20977
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20977
In init of VendorGraphicBufferMeta, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2023-21044
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21044
When cpif handles probe failures, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
CVEs:CVE-2023-21045
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21045
In handleEvent of nan.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2023-21048
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21048
In Import of C2SurfaceSyncObj.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2023-20956
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20956
PUB-A-253425086
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-259304053
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-259323725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-20975
In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges ...
CVEs:CVE-2023-20975
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20984
In ParseBqrLinkQualityEvt of btif_bqr.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2023-20984
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20991
In btm_ble_process_periodic_adv_sync_lost_evt of ble_scanner_hci_interface.cc , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interact...
CVEs:CVE-2023-20991
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21013
In forceStaDisconnection of hostapd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2023-21013
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21014
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21014
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21019
In ih264e_init_proc_ctxt of ih264e_process.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2023-21019
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21025
In ufdt_local_fixup_prop of ufdt_overlay.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2023-21025
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In dumpstateBoard of Dumpstate.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2023-21039
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21039
CVEs:CVE-2023-20644
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628603; Issue ID: AL...
CVEs:CVE-2023-20644
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20645
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628609; Issue ID: AL...
CVEs:CVE-2023-20645
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20646
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628536; Issue ID: AL...
CVEs:CVE-2023-20646
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20647
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628547; Issue ID: AL...
CVEs:CVE-2023-20647
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20648
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628612; Issue ID: AL...
CVEs:CVE-2023-20648
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628607; Issue ID: AL...
CVEs:CVE-2023-20649
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20649
CVEs:CVE-2023-20651
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629576; Issue ID: AL...
CVEs:CVE-2023-20651
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20633
In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628508; Issue ID: ...
CVEs:CVE-2023-20633
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In tinysys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664755; Issue ...
CVEs:CVE-2023-20621
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20621
ASB-A-264208866
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-263783650
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In btm_vendor_specific_evt of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2023-20972
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20972
In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2023-20995
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20995
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-20996
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20996
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-20997
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20997
CVEs:CVE-2023-20998
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-20998
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-20999
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20999
CVEs:CVE-2023-20626
In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405223; Issue ...
CVEs:CVE-2023-20626
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20628
In thermal, there is a possible memory corruption due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494460; Issue ID:...
CVEs:CVE-2023-20628
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20979
In GetNextSourceDataPacket of bta_av_co.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2023-20979
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20980
In btu_ble_ll_conn_param_upd_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is ...
CVEs:CVE-2023-20980
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20929
In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed....
CVEs:CVE-2023-20929
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20952
In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2023-20952
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21003
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2023-21003
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2023-21004
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21004
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2023-21005
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21005
CVEs:CVE-2023-21015
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2023-21015
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21068
In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to local escalation of privilege after preparing the device, hiding the warning, and passing the phone to a new user, wi...
CVEs:CVE-2023-21068
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-243433344
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-21016
In AccountTypePreference of AccountTypePreference.java, there is a possible way to mislead the user about accounts installed on the device due to improper input validation. This could lead to local denial of service with no additional execution privile...
CVEs:CVE-2023-21016
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable region beyond its own SurfaceControl due to a logic error in the code. This could lead to local denial of service with no additional execution privileges nee...
CVEs:CVE-2023-21026
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21026
CVEs:CVE-2023-21033
In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2023-21033
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2022-47478
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47478
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2022-47479
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47479
CVEs:CVE-2022-47471
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2022-47471
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47472
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2022-47472
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47473
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2022-47473
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2022-47474
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47474
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2022-47475
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47475
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2022-47476
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47476
CVEs:CVE-2022-47477
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2022-47477
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47453
In wcn service, there is a possible missing params check. This could lead to local denial of service in wcn service.
CVEs:CVE-2022-47453
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47454
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47454
CVEs:CVE-2022-47455
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47455
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47456
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47456
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47457
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47457
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47458
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47458
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47459
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVEs:CVE-2022-47459
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47460
In gpu device, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.
CVEs:CVE-2022-47460
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20957
In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2023-20957
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20959
In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2023-20959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-264598465
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-264831217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-21001
In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings of other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution pri...
CVEs:CVE-2023-21001
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin user network settings due to a missing permission check. This could lead to local escalation of privilege with no additional executi...
CVEs:CVE-2023-21021
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21021
In dit_hal_ioctl of dit.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...
CVEs:CVE-2023-21055
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21055
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
CVEs:CVE-2022-47480
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47480
CVEs:CVE-2022-47481
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
CVEs:CVE-2022-47481
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47482
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
CVEs:CVE-2022-47482
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
CVEs:CVE-2022-47483
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-47483
CVEs:CVE-2022-47484
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
CVEs:CVE-2022-47484
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-244301523
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-21029
In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...
CVEs:CVE-2023-21029
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges...
CVEs:CVE-2023-20962
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20962
In adsp, there is a possible double free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628532; Issue ID: ALPS07628532.
CVEs:CVE-2023-20625
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20625
CVEs:CVE-2023-21031
In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2023-21031
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In MediaCodec.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...
CVEs:CVE-2023-21000
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21000
In adsp, there is a possible escalation of privilege due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07554558; Issue ID: ALPS...
CVEs:CVE-2023-20620
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20620
ASB-A-264149248
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-20623
In ion, there is a possible escalation of privilege due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559778; Issue...
CVEs:CVE-2023-20623
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | yoctoproject | — | — |
ASB-A-264209787
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
google.golang.org/protobuf vulnerable to panic leading to denial of service
CVEs:CVE-2023-24535
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | google.golang.org | google.golang.org/protobuf | — |
google.golang.org/protobuf vulnerable to panic leading to denial of service
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | google.golang.org | google.golang.org/protobuf | — |
google.golang.org/protobuf vulnerable to panic leading to denial of service
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ko | affected | chainguard | ko | — |
| ko | affected | wolfi | ko | — |
| protobuf | affected | google.golang.org | google.golang.org/protobuf | — |
Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic.
CVEs:CVE-2023-24535
Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic.
CVEs:CVE-2023-24535
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | protobuf | — | — |
Panic when parsing invalid messages in google.golang.org/protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ko | affected | chainguard | ko | — |
| ko | affected | wolfi | ko | — |
| protobuf | affected | google.golang.org | google.golang.org/protobuf | — |
CVEs:CVE-2023-28286
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVEs:CVE-2023-28286
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVE-2023-25665 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
CVE-2023-25665 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:3 | tensorflow | — |
TensorFlow has Null Pointer Error in SparseSparseMaximum
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in SparseSparseMaximum
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `SparseSparseMaximum` is given invalid sparse tensors as inputs, it can give a null pointer error. A fix is included in TensorFlow version 2.12 and ve...
CVEs:CVE-2023-25665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow has Null Pointer Error in SparseSparseMaximum
CVEs:CVE-2023-25665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow has Null Pointer Error in SparseSparseMaximum
CVEs:CVE-2023-25665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
TensorFlow Denial of Service vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
TensorFlow Denial of Service vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
CVE-2023-25661 affecting package tensorflow for versions less than 2.11.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | Azure Linux:2 | tensorflow | — |
TensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a tensorflow model (Check Failed) and can be used to trigger a denial of service attack. A proof of concept can be constructed with t...
CVEs:CVE-2023-25661
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
TensorFlow Denial of Service vulnerability
CVEs:CVE-2023-25661
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
TensorFlow Denial of Service vulnerability
CVEs:CVE-2023-25661
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
CVEs:CVE-2023-23864
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Michael Aronoff Very Simple Google Maps plugin <= 2.8.4 versions.
CVEs:CVE-2023-23864
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| very_simple_google_maps | affected | very_simple_google_maps_project | — | — |
Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-2314
CVEs:CVE-2023-2314
Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-2314
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.