Google Security Advisories · March 2023 — Google Security Advisories
801 advisories 468 CVEs 19 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2023-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 19 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2023-23397

GoogleExploitedCISA KEV listedCRITICAL2023-03-14

Microsoft Outlook Elevation of Privilege Vulnerability

CVEs:CVE-2023-23397

Affected products

ProductStatusVendorPackageEcosystem
365_apps affected microsoft
office affected microsoft
office_long_term_servicing_channel affected microsoft
outlook affected microsoft
Upstream advisory

CVE-2023-32435

GoogleExploitedCISA KEV listedCRITICAL2023-03-27

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple i...

CVEs:CVE-2023-32435

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2023-32435

GoogleExploitedCISA KEV listed2023-03-27

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

CVEs:CVE-2023-32435

Upstream advisory

CVE-2023-32435

Project ZeroExploitedCISA KEV listed2023-03-27

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

CVEs:CVE-2023-32435

Upstream advisory

CVE-2023-20963

Open SourceExploitedCISA KEV listedHIGH2023-03-06

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android...

CVEs:CVE-2023-20963

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20963

Project ZeroExploitedCISA KEV listed2023-03-06

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519

CVEs:CVE-2023-20963

Upstream advisory

AZL-31200

Open SourceExploitedCISA KEV listedCRITICAL2023-03-25

CVE-2023-25668 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-35313

Open SourceExploitedCISA KEV listedCRITICAL2023-03-25

CVE-2023-25668 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-gw97-ff7c-9v96

Open SourceExploitedCISA KEV listedCRITICAL2023-03-24

TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gw97-ff7c-9v96

Open SourceExploitedCISA KEV listedCRITICAL2023-03-24

TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25668

Open SourceExploitedCISA KEV listedCRITICAL2023-03-24

TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation

CVEs:CVE-2023-25668

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25668

Open SourceExploitedCISA KEV listedCRITICAL2023-03-24

TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation

CVEs:CVE-2023-25668

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25668

Open SourceExploitedCISA KEV listedCRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in Tensor...

CVEs:CVE-2023-25668

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-0037

GoogleExploitedVulnCheck KEV listedCRITICAL2023-03-13

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVEs:CVE-2023-0037

Affected products

ProductStatusVendorPackageEcosystem
map_builder_for_google_maps affected 10web
Upstream advisory

CVE-2023-24892

Open SourceWeaponized exploitHIGH2023-03-07

Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability

CVEs:CVE-2023-24892

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

PUB-A-265822830

GoogleActive exploitation (sightings)HIGH2023-03-01

PUB-A-265822830

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-274463883

GoogleActive exploitation (sightings)HIGH2023-03-01

PUB-A-274463883

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-274464337

GoogleActive exploitation (sightings)HIGH2023-03-01

PUB-A-274464337

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-274465028

GoogleActive exploitation (sightings)HIGH2023-03-01

PUB-A-274465028

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

openSUSE-SU-2023:0082-1

Open SourceActive exploitation (sightings)CRITICAL2023-03-27

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5377-1

Open SourceActive exploitation (sightings)2023-03-23

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

GHSA-2qqx-w9hr-q5gx

Open SourceActive exploitation (sightings)CRITICAL2023-03-30

angular vulnerable to regular expression denial of service via the $resource service

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
solr affected chainguard solr
solr affected wolfi solr
Upstream advisory

GHSA-2qqx-w9hr-q5gx

Open SourceActive exploitation (sightings)CRITICAL2023-03-30

angular vulnerable to regular expression denial of service via the $resource service

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

GHSA-2vrf-hf26-jrp5

Open SourceActive exploitation (sightings)HIGH2023-03-30

angular vulnerable to regular expression denial of service via the angular.copy() utility

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

GHSA-2vrf-hf26-jrp5

Open SourceActive exploitation (sightings)HIGH2023-03-30

angular vulnerable to regular expression denial of service via the angular.copy() utility

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
solr affected wolfi solr
solr affected chainguard solr
Upstream advisory

DEBIAN-CVE-2023-26116

Open SourceActive exploitation (sightings)HIGH2023-03-30

DEBIAN-CVE-2023-26116

Affected products

ProductStatusVendorPackageEcosystem
angular.js affected Debian:14 angular.js
angular.js affected Debian:11 angular.js
angular.js affected Debian:12 angular.js
angular.js affected Debian:13 angular.js
Upstream advisory

DEBIAN-CVE-2023-26117

Open SourceActive exploitation (sightings)CRITICAL2023-03-30

DEBIAN-CVE-2023-26117

Affected products

ProductStatusVendorPackageEcosystem
angular.js affected Debian:11 angular.js
angular.js affected Debian:12 angular.js
angular.js affected Debian:13 angular.js
angular.js affected Debian:14 angular.js
Upstream advisory

CVE-2023-26116

Open SourceActive exploitation (sightings)MEDIUM2023-03-30

angular vulnerable to regular expression denial of service via the angular.copy() utility

CVEs:CVE-2023-26116

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

CVE-2023-26117

Open SourceActive exploitation (sightings)MEDIUM2023-03-30

angular vulnerable to regular expression denial of service via the $resource service

CVEs:CVE-2023-26117

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

CVE-2023-26117

Open SourceActive exploitation (sightings)MEDIUM2023-03-30

angular vulnerable to regular expression denial of service via the $resource service

CVEs:CVE-2023-26117

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

CVE-2023-26117

Open SourceActive exploitation (sightings)CRITICAL2023-03-30

Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-craft...

CVEs:CVE-2023-26117

Affected products

ProductStatusVendorPackageEcosystem
angularjs affected angularjs
fedora affected fedoraproject
Upstream advisory

CVE-2023-26116

Open SourceActive exploitation (sightings)HIGH2023-03-30

Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large ...

CVEs:CVE-2023-26116

Affected products

ProductStatusVendorPackageEcosystem
angularjs affected angularjs
fedora affected fedoraproject
Upstream advisory

CVE-2023-26116

Open SourceActive exploitation (sightings)MEDIUM2023-03-30

angular vulnerable to regular expression denial of service via the angular.copy() utility

CVEs:CVE-2023-26116

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

DEBIAN-CVE-2023-1534

Open SourceActive exploitation (sightings)HIGH2023-03-21

DEBIAN-CVE-2023-1534

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1534

GoogleActive exploitation (sightings)HIGH2023-03-21

Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1534

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-1532

Open SourceActive exploitation (sightings)HIGH2023-03-21

DEBIAN-CVE-2023-1532

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2023-1532

GoogleActive exploitation (sightings)HIGH2023-03-21

Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1532

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-1528

Open SourceActive exploitation (sightings)CRITICAL2023-03-21

DEBIAN-CVE-2023-1528

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1528

GoogleActive exploitation (sightings)CRITICAL2023-03-21

Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1528

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-gwvm-vrp4-4pp5

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend

Affected products

ProductStatusVendorPackageEcosystem
angular-server-side-configuration affected npm angular-server-side-configuration
Upstream advisory

GHSA-gwvm-vrp4-4pp5

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend

Affected products

ProductStatusVendorPackageEcosystem
angular-server-side-configuration affected npm angular-server-side-configuration
Upstream advisory

CVE-2023-28444

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend

CVEs:CVE-2023-28444

Affected products

ProductStatusVendorPackageEcosystem
angular-server-side-configuration affected npm angular-server-side-configuration
Upstream advisory

CVE-2023-28444

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables. angular-server-side-configuration detects used environment variables in TypeScript (.ts) files during ...

CVEs:CVE-2023-28444

Affected products

ProductStatusVendorPackageEcosystem
angular-server-side-configuration affected angular-server-side-configuration_project
Upstream advisory

CVE-2023-28444

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend

CVEs:CVE-2023-28444

Affected products

ProductStatusVendorPackageEcosystem
angular-server-side-configuration affected npm angular-server-side-configuration
Upstream advisory

CVE-2023-28261

Open SourceActive exploitation (sightings)CRITICAL2023-03-14

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2023-28261

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

AZL-31204

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25671 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-35316

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25671 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-j5w9-hmfh-4cr6

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has segmentation fault in tfg-translate

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

GHSA-j5w9-hmfh-4cr6

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has segmentation fault in tfg-translate

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow affected tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2023-25671

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has segmentation fault in tfg-translate

CVEs:CVE-2023-25671

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2023-25671

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. There is out-of-bounds access due to mismatched integer type sizes. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.

CVEs:CVE-2023-25671

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25671

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has segmentation fault in tfg-translate

CVEs:CVE-2023-25671

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

AZL-31211

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25664 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-35309

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25664 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-6hg6-5c2q-7rcr

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Heap-buffer-overflow in AvgPoolGrad

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

GHSA-6hg6-5c2q-7rcr

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Heap-buffer-overflow in AvgPoolGrad

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2023-25664

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Heap-buffer-overflow in AvgPoolGrad

CVEs:CVE-2023-25664

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2023-25664

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Heap-buffer-overflow in AvgPoolGrad

CVEs:CVE-2023-25664

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2023-25664

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.

CVEs:CVE-2023-25664

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

AZL-31203

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25676 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-31208

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-27579 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-35321

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25676 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-35323

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-27579 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-31201

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25659 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-31202

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25660 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-31207

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25669 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-31209

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25662 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-31212

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25675 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-31213

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25673 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-31214

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25670 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-31215

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25663 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-31217

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25674 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-35305

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25659 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-35306

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25660 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-35307

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25662 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-35308

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25663 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-35314

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25669 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-35315

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25670 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-35318

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25673 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-35319

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25674 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-35320

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25675 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-93vr-9q9m-pj8p

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-93vr-9q9m-pj8p

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qjqc-vqcf-5qvj

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-qjqc-vqcf-5qvj

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7jvm-xxmr-v5cw

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow vulnerable to integer overflow in EditDistance

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7jvm-xxmr-v5cw

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow vulnerable to integer overflow in EditDistance

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-64jg-wjww-7c5w

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in TensorArrayConcatV2

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-64jg-wjww-7c5w

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in TensorArrayConcatV2

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rcf8-g8jv-vg6p

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in AvgPoolGrad with XLA

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-rcf8-g8jv-vg6p

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in AvgPoolGrad with XLA

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-49rq-hwc3-x77w

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-49rq-hwc3-x77w

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-647v-r7qq-24fh

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in TensorListSplit with XLA

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-647v-r7qq-24fh

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in TensorListSplit with XLA

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gf97-q72m-7579

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in RandomShuffle with XLA enable

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-gf97-q72m-7579

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in RandomShuffle with XLA enable

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7x4v-9gxg-9hwj

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Segfault in Bincount with XLA

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-7x4v-9gxg-9hwj

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Segfault in Bincount with XLA

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6wfh-89q8-44jq

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has null dereference on ParallelConcat with XLA

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-6wfh-89q8-44jq

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has null dereference on ParallelConcat with XLA

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5w96-866f-6rm8

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in TFLite in conv kernel

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-5w96-866f-6rm8

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in TFLite in conv kernel

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25659

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch

CVEs:CVE-2023-25659

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25659

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the parameter `indices` for `DynamicStitch` does not match the shape of the parameter `data`, it can trigger an stack OOB read. A fix is included in Ten...

CVEs:CVE-2023-25659

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25659

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch

CVEs:CVE-2023-25659

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25660

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `summarize` of `tf.raw_ops.Print` is zero, the new method `SummarizeArray<bool>` will reference to a nullptr, leading to a seg fault. A ...

CVEs:CVE-2023-25660

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25660

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`

CVEs:CVE-2023-25660

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25660

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`

CVEs:CVE-2023-25660

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25662

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overflow in EditDistance. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.

CVEs:CVE-2023-25662

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25662

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow vulnerable to integer overflow in EditDistance

CVEs:CVE-2023-25662

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25662

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to integer overflow in EditDistance

CVEs:CVE-2023-25662

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25663

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `ctx->step_containter()` is a null ptr, the Lookup function will be executed with a null pointer. A fix is included in TensorFlow 2.12.0 and 2.11.1.

CVEs:CVE-2023-25663

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25663

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in TensorArrayConcatV2

CVEs:CVE-2023-25663

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25663

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in TensorArrayConcatV2

CVEs:CVE-2023-25663

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25669

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in AvgPoolGrad with XLA

CVEs:CVE-2023-25669

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25669

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in AvgPoolGrad with XLA

CVEs:CVE-2023-25669

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25669

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the stride and window size are not positive for `tf.raw_ops.AvgPoolGrad`, it can give a floating point exception. A fix is included in TensorFlow versio...

CVEs:CVE-2023-25669

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25670

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize

CVEs:CVE-2023-25670

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25670

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize

CVEs:CVE-2023-25670

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25670

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.

CVEs:CVE-2023-25670

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25673

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in TensorListSplit with XLA

CVEs:CVE-2023-25673

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25673

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a Floating Point Exception in TensorListSplit with XLA. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.

CVEs:CVE-2023-25673

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25673

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in TensorListSplit with XLA

CVEs:CVE-2023-25673

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25674

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in RandomShuffle with XLA enable

CVEs:CVE-2023-25674

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25674

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in RandomShuffle with XLA enable

CVEs:CVE-2023-25674

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25674

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source machine learning platform. Versions prior to 2.12.0 and 2.11.1 have a null pointer error in RandomShuffle with XLA enabled. A fix is included in TensorFlow 2.12.0 and 2.11.1.

CVEs:CVE-2023-25674

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25675

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Segfault in Bincount with XLA

CVEs:CVE-2023-25675

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25675

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Segfault in Bincount with XLA

CVEs:CVE-2023-25675

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25675

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.Bincount` segfaults when given a parameter `weights` that is neither the same shape as parameter `arr` nor a length-0 tensor....

CVEs:CVE-2023-25675

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25676

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has null dereference on ParallelConcat with XLA

CVEs:CVE-2023-25676

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25676

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.ParallelConcat` segfaults with a nullptr dereference when given a parameter `shape` with rank that is not greater than zero. ...

CVEs:CVE-2023-25676

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25676

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has null dereference on ParallelConcat with XLA

CVEs:CVE-2023-25676

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-27579

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an end-to-end open source platform for machine learning. Constructing a tflite model with a paramater `filter_input_channel` of less than 1 gives a FPE. This issue has been patched in version 2.12. TensorFlow will also cherrypick the fix ...

CVEs:CVE-2023-27579

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-27579

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in TFLite in conv kernel

CVEs:CVE-2023-27579

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-27579

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in TFLite in conv kernel

CVEs:CVE-2023-27579

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-31199

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25658 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-31205

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25666 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-35304

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25658 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-35311

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25666 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-f637-vh3r-vfh2

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in AudioSpectrogram

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f637-vh3r-vfh2

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in AudioSpectrogram

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-68v3-g9cm-rmm6

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-68v3-g9cm-rmm6

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25658

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad

CVEs:CVE-2023-25658

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25658

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad

CVEs:CVE-2023-25658

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25658

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, an out of bounds read is in GRUBlockCellGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.

CVEs:CVE-2023-25658

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25666

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in AudioSpectrogram

CVEs:CVE-2023-25666

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25666

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a floating point exception in AudioSpectrogram. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.

CVEs:CVE-2023-25666

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25666

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Floating Point Exception in AudioSpectrogram

CVEs:CVE-2023-25666

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-31210

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25672 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-35317

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25672 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-94mm-g2mv-8p7r

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in LookupTableImportV2

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-94mm-g2mv-8p7r

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in LookupTableImportV2

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25672

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in LookupTableImportV2

CVEs:CVE-2023-25672

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25672

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. The function `tf.raw_ops.LookupTableImportV2` cannot handle scalars in the `values` parameter and gives an NPE. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.

CVEs:CVE-2023-25672

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25672

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has Null Pointer Error in LookupTableImportV2

CVEs:CVE-2023-25672

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-31198

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25667 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-35312

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25667 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-fqm2-gh8w-gr68

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow vulnerable to segfault when opening multiframe gif

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fqm2-gh8w-gr68

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow vulnerable to segfault when opening multiframe gif

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25667

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow vulnerable to segfault when opening multiframe gif

CVEs:CVE-2023-25667

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25667

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, integer overflow occurs when `2^31 <= num_frames * height * width * channels < 2^32`, for example Full HD screencast of at least 346 frames. A fix is inclu...

CVEs:CVE-2023-25667

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25667

Open SourceActive exploitation (sightings)MEDIUM2023-03-24

TensorFlow vulnerable to segfault when opening multiframe gif

CVEs:CVE-2023-25667

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

AZL-31206

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25801 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-35322

Open SourceActive exploitation (sightings)CRITICAL2023-03-25

CVE-2023-25801 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-f49c-87jh-g47q

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow has double free in Fractional(Max/Avg)Pool

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-f49c-87jh-g47q

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow has double free in Fractional(Max/Avg)Pool

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25801

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow has double free in Fractional(Max/Avg)Pool

CVEs:CVE-2023-25801

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25801

Open SourceActive exploitation (sightings)CRITICAL2023-03-24

TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first and fourth elements of their parameter `pooling_ratio` to be equal to 1.0...

CVEs:CVE-2023-25801

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25801

Open SourceActive exploitation (sightings)HIGH2023-03-24

TensorFlow has double free in Fractional(Max/Avg)Pool

CVEs:CVE-2023-25801

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-20936

Open SourceActive exploitation (sightings)HIGH2023-03-06

In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2023-20936

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2023:0068-1

Open SourceCoalition ESS > 63%CRITICAL2023-03-13

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

MGASA-2023-0090

Open SourceCoalition ESS > 63%CRITICAL2023-03-11

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

DSA-5371-1

Open SourceCoalition ESS > 63%2023-03-09

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2023-1234

GoogleCoalition ESS > 63%MEDIUM2023-03-07

Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-1234

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1234

Open SourceCoalition ESS > 63%MEDIUM2023-03-07

DEBIAN-CVE-2023-1234

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CLSA-2023-1678396353

Open SourcePoC exploitCRITICAL2023-03-09

Fix CVE(s): CVE-2023-24329

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

CLSA-2023-1678136704

Open SourcePoC exploit2023-03-06

Fix CVE(s): CVE-2023-24329

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

SUSE-SU-2023:0603-1

GooglePoC exploit2023-03-02

Security update for google-guest-agent

Affected products

ProductStatusVendorPackageEcosystem
google-guest-agent affected SUSE:Linux Enterprise Module for Public Cloud 12 google-guest-agent
Upstream advisory

SUSE-SU-2023:0602-1

GooglePoC exploit2023-03-02

Security update for google-osconfig-agent

Affected products

ProductStatusVendorPackageEcosystem
google-osconfig-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 google-osconfig-agent
google-osconfig-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 google-osconfig-agent
google-osconfig-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 google-osconfig-agent
google-osconfig-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 google-osconfig-agent
google-osconfig-agent affected openSUSE:Leap 15.4 google-osconfig-agent
Upstream advisory

SUSE-SU-2023:0601-1

GooglePoC exploit2023-03-02

Security update for google-osconfig-agent

Affected products

ProductStatusVendorPackageEcosystem
google-osconfig-agent affected SUSE:Linux Enterprise Module for Public Cloud 12 google-osconfig-agent
Upstream advisory

SUSE-SU-2023:0600-1

GooglePoC exploit2023-03-02

Security update for google-guest-agent

Affected products

ProductStatusVendorPackageEcosystem
google-guest-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 google-guest-agent
google-guest-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 google-guest-agent
google-guest-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 google-guest-agent
google-guest-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 google-guest-agent
google-guest-agent affected openSUSE:Leap 15.4 google-guest-agent
Upstream advisory

OESA-2023-1192

Open SourcePoC exploitHIGH2023-03-31

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP3 golang
golang affected openEuler:22.03-LTS golang
Upstream advisory

MGASA-2023-0109

Open SourcePoC exploitCRITICAL2023-03-24

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

AZL-38611

Open SourcePoC exploitCRITICAL2023-03-30

CVE-2023-27534 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-37878

Open SourcePoC exploitCRITICAL2023-03-30

CVE-2023-27533 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-38114

Open SourcePoC exploitCRITICAL2023-03-30

CVE-2023-27537 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-qwqh-hm9m-p5hr

Open SourcePoC exploitHIGH2023-03-30

angular vulnerable to regular expression denial of service via the <input type="url"> element

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
solr affected chainguard solr
solr affected wolfi solr
Upstream advisory

GHSA-qwqh-hm9m-p5hr

Open SourcePoC exploitHIGH2023-03-30

angular vulnerable to regular expression denial of service via the <input type="url"> element

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

DEBIAN-CVE-2023-26118

Open SourcePoC exploitHIGH2023-03-30

DEBIAN-CVE-2023-26118

Affected products

ProductStatusVendorPackageEcosystem
angular.js affected Debian:11 angular.js
angular.js affected Debian:12 angular.js
angular.js affected Debian:13 angular.js
angular.js affected Debian:14 angular.js
Upstream advisory

CVE-2023-26118

Open SourcePoC exploitMEDIUM2023-03-30

angular vulnerable to regular expression denial of service via the <input type="url"> element

CVEs:CVE-2023-26118

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

CVE-2023-26118

Open SourcePoC exploitMEDIUM2023-03-30

angular vulnerable to regular expression denial of service via the <input type="url"> element

CVEs:CVE-2023-26118

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

CVE-2023-26118

Open SourcePoC exploitHIGH2023-03-30

Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerabili...

CVEs:CVE-2023-26118

Affected products

ProductStatusVendorPackageEcosystem
angularjs affected angularjs
fedora affected fedoraproject
Upstream advisory

GHSA-jh36-q97c-9928

Open SourcePoC exploitHIGH2023-03-01

Kubernetes vulnerable to validation bypass

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-jh36-q97c-9928

Open SourcePoC exploitHIGH2023-03-01

Kubernetes vulnerable to validation bypass

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

DEBIAN-CVE-2022-3294

Open SourcePoC exploitHIGH2023-03-01

DEBIAN-CVE-2022-3294

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:14 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
Upstream advisory

CVE-2022-3294

Open SourcePoC exploitHIGH2023-03-01

Kubernetes vulnerable to validation bypass

CVEs:CVE-2022-3294

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

CVE-2022-3294

Open SourcePoC exploitHIGH2023-03-01

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-...

CVEs:CVE-2022-3294

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

AZL-38512

Open SourcePoC exploitCRITICAL2023-03-30

CVE-2023-27535 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-38476

Open SourcePoC exploitCRITICAL2023-03-30

CVE-2023-27536 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

MGASA-2023-0092

Open SourcePoC exploitHIGH2023-03-18

Updated protobuf packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Mageia:8 protobuf
Upstream advisory

AZL-38257

Open SourcePoC exploitCRITICAL2023-03-30

CVE-2023-27538 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

AZL-34775

Open SourcePoC exploitCRITICAL2023-03-06

CVE-2022-4904 affecting package grpc for versions less than 1.62.0-2

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Azure Linux:3 grpc
Upstream advisory

GHSA-2394-5535-8j88

Open SourcePoC exploitCRITICAL2023-03-01

Kubernetes vulnerable to path traversal

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

GHSA-2394-5535-8j88

Open SourcePoC exploitCRITICAL2023-03-01

Kubernetes vulnerable to path traversal

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kubernetes affected github.com github.com/kubernetes/kubernetes
Upstream advisory

AZL-31287

Open SourcePoC exploitCRITICAL2023-03-01

CVE-2022-3162 affecting package kubernetes for versions less than 1.25.4-0

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:2 kubernetes
Upstream advisory

DEBIAN-CVE-2022-3162

Open SourcePoC exploitCRITICAL2023-03-01

DEBIAN-CVE-2022-3162

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

AZL-37373

Open SourcePoC exploitMEDIUM2023-03-08

CVE-2023-24532 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37385

Open SourcePoC exploitMEDIUM2023-03-08

CVE-2023-24532 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-52875

Open SourcePoC exploitMEDIUM2023-03-08

CVE-2023-24532 affecting package golang for versions less than 1.20.2-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-78976

Open SourcePoC exploitMEDIUM2023-03-08

CVE-2023-24532 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-24532

Open SourcePoC exploitMEDIUM2023-03-08

DEBIAN-CVE-2023-24532

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2023-24532

GooglePoC exploitMEDIUM2023-03-08

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.

CVEs:CVE-2023-24532

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2023-24532

GooglePoC exploit2023-03-08

The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.

CVEs:CVE-2023-24532

Upstream advisory

GO-2023-1621

Open SourcePoC exploit2023-03-08

Incorrect calculation on P256 curves in crypto/internal/nistec

Affected products

ProductStatusVendorPackageEcosystem
go-1.20 affected chainguard go-1.20
go-1.20 affected wolfi go-1.20
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
stdlib affected Go
stdlib affected Go stdlib
Upstream advisory

CVE-2023-21036

Open SourcePoC exploitMEDIUM2023-03-13

In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A

CVEs:CVE-2023-21036

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-264261868

GooglePoC exploit2023-03-01

PUB-A-264261868

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-240019719

GooglePoC exploitHIGH2023-03-01

ASB-A-240019719

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2023-20955

Open SourcePoC exploitHIGH2023-03-06

In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and uninstall applications for all users due to a missing permission check. This could lead to local escalation of privilege with no addition...

CVEs:CVE-2023-20955

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20911

Open SourcePoC exploitHIGH2023-03-06

In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2023-20911

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20983

Open SourcePoC exploitMEDIUM2023-03-13

In btm_ble_rand_enc_complete of btm_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2023-20983

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21035

Open SourcePoC exploitHIGH2023-03-13

In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same package name due to a permissions bypass. This could lead to local escalation of privilege with no additio...

CVEs:CVE-2023-21035

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-1531

Open SourceCoalition ESS < 30%CRITICAL2023-03-21

Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1531

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chromium affected chromium
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-1531

Open SourceCoalition ESS < 30%CRITICAL2023-03-21

DEBIAN-CVE-2023-1531

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1229

GoogleCoalition ESS < 30%MEDIUM2023-03-07

Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-1229

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1229

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

DEBIAN-CVE-2023-1229

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1219

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Heap buffer overflow in Metrics in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1219

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1219

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1219

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2023-1529

GoogleCoalition ESS < 30%CRITICAL2023-03-21

Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)

CVEs:CVE-2023-1529

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-1529

Open SourceCoalition ESS < 30%CRITICAL2023-03-21

DEBIAN-CVE-2023-1529

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1220

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1220

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1220

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1220

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-1533

Open SourceCoalition ESS < 30%CRITICAL2023-03-21

DEBIAN-CVE-2023-1533

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1533

GoogleCoalition ESS < 30%CRITICAL2023-03-21

Use after free in WebProtect in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1533

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2023-1530

GoogleCoalition ESS < 30%CRITICAL2023-03-21

Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1530

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-1530

Open SourceCoalition ESS < 30%CRITICAL2023-03-21

DEBIAN-CVE-2023-1530

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2022-42499

Open SourceCoalition ESS < 30%CRITICAL2023-03-13

In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2022-42499

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-242001391

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-242001391

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42498

Open SourceCoalition ESS < 30%CRITICAL2023-03-13

In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...

CVEs:CVE-2022-42498

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-240662453

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-240662453

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-1214

GoogleCoalition ESS < 30%HIGH2023-03-07

Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1214

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1214

Open SourceCoalition ESS < 30%HIGH2023-03-07

DEBIAN-CVE-2023-1214

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

MGASA-2023-0076

Open SourceCoalition ESS < 30%CRITICAL2023-03-01

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

CVE-2022-44580

GoogleCoalition ESS < 30%CRITICAL2023-03-15

SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.

CVEs:CVE-2022-44580

Affected products

ProductStatusVendorPackageEcosystem
plugin_for_google_reviews affected richplugins
Upstream advisory

CVE-2023-1222

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Heap buffer overflow in Web Audio API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-1222

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1222

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1222

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1215

GoogleCoalition ESS < 30%HIGH2023-03-07

Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1215

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1215

Open SourceCoalition ESS < 30%HIGH2023-03-07

DEBIAN-CVE-2023-1215

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1216

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1216

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-1218

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1218

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1216

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1216

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-1218

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1218

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-21054

Open SourceCoalition ESS < 30%HIGH2023-03-13

In EUTRAN_LCS_ConvertLCS_MOLRReq of LPP_CommonUtil.c, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2023-21054

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-244556535

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-244556535

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-1217

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Stack buffer overflow in Crash reporting in Google Chrome on Windows prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chr...

CVEs:CVE-2023-1217

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1217

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1217

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1213

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-1213

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1213

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1213

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1231

GoogleCoalition ESS < 30%MEDIUM2023-03-07

Inappropriate implementation in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to potentially spoof the contents of the omnibox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-1231

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1231

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

DEBIAN-CVE-2023-1231

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-20532

Open SourceCoalition ESS < 30%CRITICAL2023-03-13

In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2022-20532

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21057

Open SourceCoalition ESS < 30%CRITICAL2023-03-13

In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2023-21057

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21058

Open SourceCoalition ESS < 30%CRITICAL2023-03-13

In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2023-21058

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20951

Open SourceCoalition ESS < 30%CRITICAL2023-03-06

In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2023-20951

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20954

Open SourceCoalition ESS < 30%CRITICAL2023-03-06

In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2023-20954

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-244450646

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-244450646

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-246169606

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-246169606

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21027

Open SourceCoalition ESS < 30%HIGH2023-03-13

In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2023-21027

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-1232

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to obtain potentially sensitive information from API via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-1232

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1232

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1232

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1226

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-1226

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-1236

GoogleCoalition ESS < 30%MEDIUM2023-03-07

Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-1236

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1226

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1226

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-1236

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

DEBIAN-CVE-2023-1236

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1227

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity:...

CVEs:CVE-2023-1227

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1227

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1227

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1224

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-1224

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1224

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1224

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1228

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-1228

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1228

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1228

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-21028

Open SourceCoalition ESS < 30%HIGH2023-03-13

In parse_printerAttributes of ipphelper.c, there is a possible out of bounds read due to a string without a null-terminator. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2023-21028

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21053

Open SourceCoalition ESS < 30%HIGH2023-03-13

In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-21053

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21059

Open SourceCoalition ESS < 30%HIGH2023-03-13

In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interacti...

CVEs:CVE-2023-21059

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21060

Open SourceCoalition ESS < 30%HIGH2023-03-13

In sms_GetTpPiIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2023-21060

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-247564044

GoogleCoalition ESS < 30%MEDIUM2023-03-01

PUB-A-247564044

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-251805610

GoogleCoalition ESS < 30%MEDIUM2023-03-01

PUB-A-251805610

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-253770924

GoogleCoalition ESS < 30%MEDIUM2023-03-01

PUB-A-253770924

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2023-1235

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

DEBIAN-CVE-2023-1235

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1235

GoogleCoalition ESS < 30%MEDIUM2023-03-07

Type confusion in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted UI interaction. (Chromium security severity: Low)

CVEs:CVE-2023-1235

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-1223

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Insufficient policy enforcement in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-1223

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1223

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1223

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-h828-v5pv-33qx

GoogleCoalition ESS < 30%MEDIUM2023-03-03

coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints

Affected products

ProductStatusVendorPackageEcosystem
coredns/coredns affected github.com github.com/coredns/coredns
Upstream advisory

GHSA-h828-v5pv-33qx

Open SourceCoalition ESS < 30%MEDIUM2023-03-03

coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints

Affected products

ProductStatusVendorPackageEcosystem
coredns affected chainguard coredns
coredns affected wolfi coredns
coredns/coredns affected github.com github.com/coredns/coredns
coredns-fips affected chainguard coredns-fips
juicefs-1.2 affected chainguard juicefs-1.2
juicefs-1.3 affected chainguard juicefs-1.3
juicefs-1.3 affected wolfi juicefs-1.3
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

CVE-2022-4452

GoogleCoalition ESS < 30%HIGH2023-03-06

Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4452

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-1225

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 111.0.5563.64 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-1225

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1225

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1225

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1233

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from API via a crafted Chrome Extension. (C...

CVEs:CVE-2023-1233

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1233

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1233

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-1221

GoogleCoalition ESS < 30%CRITICAL2023-03-07

Insufficient policy enforcement in Extensions API in Google Chrome prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security sev...

CVEs:CVE-2023-1221

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1221

Open SourceCoalition ESS < 30%CRITICAL2023-03-07

DEBIAN-CVE-2023-1221

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-36689

Open SourceCoalition ESS < 30%CRITICAL2023-03-04

An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The PIN is 5 to 8 ...

CVEs:CVE-2021-36689

Affected products

ProductStatusVendorPackageEcosystem
samourai-wallet-android affected samourai-wallet-android_project
Upstream advisory

CVE-2023-21061

Open SourceCoalition ESS < 30%HIGH2023-03-13

Product: AndroidVersions: Android kernelAndroid ID: A-229255400References: N/A

CVEs:CVE-2023-21061

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-229255400

GoogleCoalition ESS < 30%2023-03-01

PUB-A-229255400

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21459

Open SourceCoalition ESS < 30%CRITICAL2023-03-16

Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.

CVEs:CVE-2023-21459

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21067

Open SourceCoalition ESS < 30%HIGH2023-03-13

Product: AndroidVersions: Android kernelAndroid ID: A-254114726References: N/A

CVEs:CVE-2023-21067

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-254114726

GoogleCoalition ESS < 30%2023-03-01

PUB-A-254114726

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-1230

GoogleCoalition ESS < 30%MEDIUM2023-03-07

Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious WebApp to spoof the contents of the PWA installer via a crafted HTML page. (Chromium secu...

CVEs:CVE-2023-1230

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-1230

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

DEBIAN-CVE-2023-1230

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-21454

Open SourceCoalition ESS < 30%LOW2023-03-16

Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.

CVEs:CVE-2023-21454

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-20960

Open SourceCoalition ESS < 30%HIGH2023-03-06

In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User inter...

CVEs:CVE-2023-20960

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21456

Open SourceCoalition ESS < 30%CRITICAL2023-03-16

Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.

CVEs:CVE-2023-21456

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

GHSA-ch7v-37xg-75ph

Open SourceCoalition ESS < 30%MEDIUM2023-03-03

coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints

Affected products

ProductStatusVendorPackageEcosystem
coredns affected wolfi coredns
coredns affected chainguard coredns
coredns/coredns affected github.com github.com/coredns/coredns
coredns-fips affected chainguard coredns-fips
juicefs-1.2 affected chainguard juicefs-1.2
juicefs-1.3 affected chainguard juicefs-1.3
juicefs-1.3 affected wolfi juicefs-1.3
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
Upstream advisory

GHSA-ch7v-37xg-75ph

GoogleCoalition ESS < 30%MEDIUM2023-03-03

coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints

Affected products

ProductStatusVendorPackageEcosystem
coredns/coredns affected github.com github.com/coredns/coredns
Upstream advisory

CVE-2023-21453

Open SourceCoalition ESS < 30%MEDIUM2023-03-16

Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.

CVEs:CVE-2023-21453

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21457

Open SourceCoalition ESS < 30%HIGH2023-03-16

Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.

CVEs:CVE-2023-21457

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21449

Open SourceCoalition ESS < 30%MEDIUM2023-03-16

Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.

CVEs:CVE-2023-21449

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-261470730

GoogleCoalition ESS < 30%2023-03-01

ASB-A-261470730

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2023-21460

Open SourceCoalition ESS < 30%MEDIUM2023-03-16

Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.

CVEs:CVE-2023-21460

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21458

Open SourceCoalition ESS < 30%MEDIUM2023-03-16

Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.

CVEs:CVE-2023-21458

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21012

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21012

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21452

Open SourceCoalition ESS < 30%LOW2023-03-16

Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.

CVEs:CVE-2023-21452

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21461

Open SourceCoalition ESS < 30%MEDIUM2023-03-16

Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.

CVEs:CVE-2023-21461

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-20958

Open SourceCoalition ESS < 30%HIGH2023-03-06

In read_paint of ttcolr.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2023-20958

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20926

Open SourceCoalition ESS < 30%MEDIUM2023-03-06

In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory ...

CVEs:CVE-2023-20926

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20987

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_read_link_quality_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over Bluetooth with System execution privileges needed. User interaction is not neede...

CVEs:CVE-2023-20987

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20988

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_read_rssi_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not need...

CVEs:CVE-2023-20988

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20992

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In on_iso_link_quality_read of btm_iso_impl.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is no...

CVEs:CVE-2023-20992

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20542

Open SourceCoalition ESS < 30%HIGH2023-03-13

In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2022-20542

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20910

Open SourceCoalition ESS < 30%HIGH2023-03-06

In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2023-20910

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42528

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2022-42528

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-242203672

GoogleCoalition ESS < 30%MEDIUM2023-03-01

PUB-A-242203672

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20917

Open SourceCoalition ESS < 30%HIGH2023-03-06

In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2023-20917

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-235113793

GoogleCoalition ESS < 30%2023-03-01

PUB-A-235113793

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/opensource/camera-kernel affected platform platform/vendor/opensource/camera-kernel
Upstream advisory

CVE-2023-20953

Open SourceCoalition ESS < 30%HIGH2023-03-06

In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to bypass factory reset protection due to incorrect UI being shown prior to setup completion. This could lead to local escalation of privilege with no additional execution privi...

CVEs:CVE-2023-20953

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20964

Open SourceCoalition ESS < 30%HIGH2023-03-06

In multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local denial of service or escalation of privilege with no additional execution privileges needed. User interaction is...

CVEs:CVE-2023-20964

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-193434313

GoogleCoalition ESS < 30%2023-03-01

ASB-A-193434313

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
qcom/sepolicy_vndr affected device device/qcom/sepolicy_vndr
Upstream advisory

CVE-2023-21049

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In append_camera_metadata of camera_metadata.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2023-21049

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20634

Open SourceCoalition ESS < 30%HIGH2023-03-07

In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07635697; Is...

CVEs:CVE-2023-20634

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-236688120

GoogleCoalition ESS < 30%MEDIUM2023-03-01

PUB-A-236688120

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-0460

Open SourceCoalition ESS < 30%HIGH2023-03-01

The YouTube Embedded 1.2 SDK binds to a service within the YouTube Main App. After binding, a remote context is created with the flags Context.CONTEXT_INCLUDE_CODE | Context.CONTEXT_IGNORE_SECURITY. This allows the client app to remotely load code from...

CVEs:CVE-2023-0460

Affected products

ProductStatusVendorPackageEcosystem
youtube_android_player_api affected google
Upstream advisory

CVE-2023-21002

Open SourceCoalition ESS < 30%HIGH2023-03-13

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2023-21002

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20635

Open SourceCoalition ESS < 30%HIGH2023-03-07

In keyinstall, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issu...

CVEs:CVE-2023-20635

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21034

Open SourceCoalition ESS < 30%HIGH2023-03-13

In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2023-21034

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20971

Open SourceCoalition ESS < 30%HIGH2023-03-13

In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privi...

CVEs:CVE-2023-20971

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42500

Open SourceCoalition ESS < 30%HIGH2023-03-13

In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2022-42500

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-239701389

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-239701389

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20976

Open SourceCoalition ESS < 30%HIGH2023-03-13

In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution ...

CVEs:CVE-2023-20976

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20467

Open SourceCoalition ESS < 30%MEDIUM2023-03-06

In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploit...

CVEs:CVE-2022-20467

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21024

Open SourceCoalition ESS < 30%HIGH2023-03-13

In maybeFinish of FallbackHome.java, there is a possible delay of lockdown screen due to logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21024

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21040

Open SourceCoalition ESS < 30%HIGH2023-03-13

In buildCommand of bluetooth_ccc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2023-21040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-238420277

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-238420277

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21072

Open SourceCoalition ESS < 30%HIGH2023-03-13

In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2023-21072

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21073

Open SourceCoalition ESS < 30%HIGH2023-03-13

In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2023-21073

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21075

Open SourceCoalition ESS < 30%HIGH2023-03-13

In get_svc_hash of nan.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2023-21075

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21077

Open SourceCoalition ESS < 30%HIGH2023-03-13

In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2023-21077

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21078

Open SourceCoalition ESS < 30%HIGH2023-03-13

In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2023-21078

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21079

Open SourceCoalition ESS < 30%HIGH2023-03-13

In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21079

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20630

Open SourceCoalition ESS < 30%HIGH2023-03-07

In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628505; Issue ID: ...

CVEs:CVE-2023-20630

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20632

Open SourceCoalition ESS < 30%HIGH2023-03-07

In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628506; Issue ID: ...

CVEs:CVE-2023-20632

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20966

Open SourceCoalition ESS < 30%HIGH2023-03-06

In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2023-20966

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-254839721

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-254839721

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-254840211

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-254840211

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-257289560

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-257289560

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-257290396

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-257290396

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-257290781

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-257290781

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-261857862

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-261857862

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21041

Open SourceCoalition ESS < 30%HIGH2023-03-13

In append_to_params of param_util.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2023-21041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20906

Open SourceCoalition ESS < 30%HIGH2023-03-06

In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after a Target SDK update due to a permissions bypass. This could lead to local escalation of privilege after updating an app to a higher...

CVEs:CVE-2023-20906

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20947

Open SourceCoalition ESS < 30%HIGH2023-03-06

In getGroupState of GrantPermissionsViewModel.kt, there is a possible way to keep a one-time permission granted due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2023-20947

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-250123688

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-250123688

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21020

Open SourceCoalition ESS < 30%HIGH2023-03-13

In registerSignalHandlers of main.c, there is a possible local arbitrary code execution due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2023-21020

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21042

Open SourceCoalition ESS < 30%HIGH2023-03-13

In (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...

CVEs:CVE-2023-21042

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21043

Open SourceCoalition ESS < 30%HIGH2023-03-13

In (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...

CVEs:CVE-2023-21043

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21046

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2023-21046

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21047

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2023-21047

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20931

Open SourceCoalition ESS < 30%HIGH2023-03-06

In avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2023-20931

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-239872581

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-239872581

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-239873326

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-239873326

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-253424924

GoogleCoalition ESS < 30%MEDIUM2023-03-01

PUB-A-253424924

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-256166866

GoogleCoalition ESS < 30%MEDIUM2023-03-01

PUB-A-256166866

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20968

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple functions of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-20968

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20969

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-20969

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20970

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-20970

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20981

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btu_ble_rc_param_req_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2023-20981

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20982

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_read_tx_power_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not ...

CVEs:CVE-2023-20982

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20986

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_ble_clear_resolving_list_completecomplete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is n...

CVEs:CVE-2023-20986

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20989

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_ble_write_adv_enable_complete of btm_ble_gap.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2023-20989

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20990

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_ble_rand_enc_complete of btm_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2023-20990

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21006

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21006

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21007

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21007

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21008

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21008

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21009

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21009

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21010

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21010

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21011

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21011

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21050

Open SourceCoalition ESS < 30%HIGH2023-03-13

In load_png_image of ExynosHWCHelper.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2023-21050

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21051

Open SourceCoalition ESS < 30%HIGH2023-03-13

In dwc3_exynos_clk_get of dwc3-exynos.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2023-21051

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21076

Open SourceCoalition ESS < 30%HIGH2023-03-13

In createTransmitFollowupRequest of nan.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2023-21076

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47461

Open SourceCoalition ESS < 30%MEDIUM2023-03-06

In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

CVEs:CVE-2022-47461

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47462

Open SourceCoalition ESS < 30%MEDIUM2023-03-06

In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

CVEs:CVE-2022-47462

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-264834026

GoogleCoalition ESS < 30%CRITICAL2023-03-01

ASB-A-264834026

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-264834568

GoogleCoalition ESS < 30%CRITICAL2023-03-01

ASB-A-264834568

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-244423702

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-244423702

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-259323322

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-259323322

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-261857623

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-261857623

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20985

Open SourceCoalition ESS < 30%HIGH2023-03-13

In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2023-20985

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20993

Open SourceCoalition ESS < 30%HIGH2023-03-13

In multiple functions of SnoozeHelper.java, there is a possible failure to persist settings due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2023-20993

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20994

Open SourceCoalition ESS < 30%HIGH2023-03-13

In _ufdt_output_property_to_fdt of ufdt_convert.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2023-20994

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21017

Open SourceCoalition ESS < 30%HIGH2023-03-13

In InstallStart of InstallStart.java, there is a possible way to change the installer package name due to an improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...

CVEs:CVE-2023-21017

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21018

Open SourceCoalition ESS < 30%HIGH2023-03-13

In UnwindingWorker of unwinding.cc, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2023-21018

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21022

Open SourceCoalition ESS < 30%HIGH2023-03-13

In BufferBlock of Suballocation.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2023-21022

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21030

Open SourceCoalition ESS < 30%HIGH2023-03-13

In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2023-21030

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21032

Open SourceCoalition ESS < 30%HIGH2023-03-13

In _ufdt_output_node_to_fdt of ufdt_convert.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2023-21032

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21038

Open SourceCoalition ESS < 30%HIGH2023-03-13

In cs40l2x_cp_trigger_queue_show of cs40l2x.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2023-21038

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21052

Open SourceCoalition ESS < 30%HIGH2023-03-13

In setToExternal of ril_external_client.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2023-21052

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21056

Open SourceCoalition ESS < 30%HIGH2023-03-13

In lwis_slc_buffer_free of lwis_device_slc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2023-21056

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21062

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In DoSetTempEcc of imsservice.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2023-21062

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21063

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In ParseWithAuthType of simdata.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2023-21063

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21064

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In DoSetPinControl of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21064

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21065

Open SourceCoalition ESS < 30%HIGH2023-03-13

In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...

CVEs:CVE-2023-21065

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21069

Open SourceCoalition ESS < 30%HIGH2023-03-13

In wl_update_hidden_ap_ie of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2023-21069

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21070

Open SourceCoalition ESS < 30%HIGH2023-03-13

In add_roam_cache_list of wl_roam.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2023-21070

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21071

Open SourceCoalition ESS < 30%HIGH2023-03-13

In dhd_prot_ioctcmplt_process of dhd_msgbuf.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2023-21071

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20636

Open SourceCoalition ESS < 30%HIGH2023-03-07

In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292593; Is...

CVEs:CVE-2023-20636

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20637

Open SourceCoalition ESS < 30%HIGH2023-03-07

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628588; Issue ID: ...

CVEs:CVE-2023-20637

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20638

Open SourceCoalition ESS < 30%HIGH2023-03-07

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628537; Issue ID: ...

CVEs:CVE-2023-20638

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20639

Open SourceCoalition ESS < 30%HIGH2023-03-07

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628587; Issue ID: ...

CVEs:CVE-2023-20639

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20640

Open SourceCoalition ESS < 30%HIGH2023-03-07

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629573; Issue ID: ...

CVEs:CVE-2023-20640

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20641

Open SourceCoalition ESS < 30%HIGH2023-03-07

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629574; Issue ID: ...

CVEs:CVE-2023-20641

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20642

Open SourceCoalition ESS < 30%HIGH2023-03-07

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628586; Issue ID: ...

CVEs:CVE-2023-20642

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20643

Open SourceCoalition ESS < 30%HIGH2023-03-07

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628584; Issue ID: ...

CVEs:CVE-2023-20643

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20650

Open SourceCoalition ESS < 30%HIGH2023-03-07

In apu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629577; Issue ID: ...

CVEs:CVE-2023-20650

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20624

Open SourceCoalition ESS < 30%HIGH2023-03-07

In vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628530; Issue I...

CVEs:CVE-2023-20624

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20627

Open SourceCoalition ESS < 30%HIGH2023-03-07

In pqframework, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629585; Is...

CVEs:CVE-2023-20627

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-224000736

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-224000736

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-239630493

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-239630493

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-243129862

GoogleCoalition ESS < 30%NONE2023-03-01

PUB-A-243129862

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-243130078

GoogleCoalition ESS < 30%NONE2023-03-01

PUB-A-243130078

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-243376770

GoogleCoalition ESS < 30%NONE2023-03-01

PUB-A-243376770

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-245300559

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-245300559

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-254028518

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-254028518

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-254028776

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-254028776

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-254029309

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-254029309

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-259063189

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-259063189

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20973

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2023-20973

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20974

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not n...

CVEs:CVE-2023-20974

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20977

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_ble_read_remote_features_complete of btm_ble_gap.cc, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure if the firmware were compromised with System execution privileges neede...

CVEs:CVE-2023-20977

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21044

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In init of VendorGraphicBufferMeta, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2023-21044

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21045

Open SourceCoalition ESS < 30%HIGH2023-03-13

When cpif handles probe failures, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2023-21045

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21048

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In handleEvent of nan.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2023-21048

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20956

Open SourceCoalition ESS < 30%HIGH2023-03-06

In Import of C2SurfaceSyncObj.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2023-20956

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-253425086

GoogleCoalition ESS < 30%MEDIUM2023-03-01

PUB-A-253425086

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-259304053

GoogleCoalition ESS < 30%MEDIUM2023-03-01

PUB-A-259304053

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-259323725

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-259323725

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20975

Open SourceCoalition ESS < 30%HIGH2023-03-13

In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges ...

CVEs:CVE-2023-20975

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20984

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In ParseBqrLinkQualityEvt of btif_bqr.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2023-20984

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20991

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_ble_process_periodic_adv_sync_lost_evt of ble_scanner_hci_interface.cc , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interact...

CVEs:CVE-2023-20991

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21013

Open SourceCoalition ESS < 30%HIGH2023-03-13

In forceStaDisconnection of hostapd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2023-21013

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21014

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21014

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21019

Open SourceCoalition ESS < 30%HIGH2023-03-13

In ih264e_init_proc_ctxt of ih264e_process.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2023-21019

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21025

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In ufdt_local_fixup_prop of ufdt_overlay.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2023-21025

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21039

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In dumpstateBoard of Dumpstate.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2023-21039

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20644

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628603; Issue ID: AL...

CVEs:CVE-2023-20644

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20645

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628609; Issue ID: AL...

CVEs:CVE-2023-20645

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20646

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628536; Issue ID: AL...

CVEs:CVE-2023-20646

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20647

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628547; Issue ID: AL...

CVEs:CVE-2023-20647

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20648

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628612; Issue ID: AL...

CVEs:CVE-2023-20648

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20649

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628607; Issue ID: AL...

CVEs:CVE-2023-20649

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20651

Open SourceCoalition ESS < 30%MEDIUM2023-03-07

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629576; Issue ID: AL...

CVEs:CVE-2023-20651

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20633

Open SourceCoalition ESS < 30%HIGH2023-03-07

In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628508; Issue ID: ...

CVEs:CVE-2023-20633

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20621

Open SourceCoalition ESS < 30%HIGH2023-03-06

In tinysys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664755; Issue ...

CVEs:CVE-2023-20621

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-264208866

GoogleCoalition ESS < 30%HIGH2023-03-01

ASB-A-264208866

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-263783650

GoogleCoalition ESS < 30%MEDIUM2023-03-01

PUB-A-263783650

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20972

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btm_vendor_specific_evt of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2023-20972

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20995

Open SourceCoalition ESS < 30%HIGH2023-03-13

In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2023-20995

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20996

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-20996

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20997

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-20997

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20998

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-20998

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20999

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-20999

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20626

Open SourceCoalition ESS < 30%HIGH2023-03-07

In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405223; Issue ...

CVEs:CVE-2023-20626

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20628

Open SourceCoalition ESS < 30%HIGH2023-03-07

In thermal, there is a possible memory corruption due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494460; Issue ID:...

CVEs:CVE-2023-20628

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20979

Open SourceCoalition ESS < 30%HIGH2023-03-13

In GetNextSourceDataPacket of bta_av_co.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2023-20979

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20980

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In btu_ble_ll_conn_param_upd_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is ...

CVEs:CVE-2023-20980

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20929

Open SourceCoalition ESS < 30%MEDIUM2023-03-06

In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed....

CVEs:CVE-2023-20929

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20952

Open SourceCoalition ESS < 30%HIGH2023-03-06

In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2023-20952

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21003

Open SourceCoalition ESS < 30%HIGH2023-03-13

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2023-21003

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21004

Open SourceCoalition ESS < 30%HIGH2023-03-13

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2023-21004

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21005

Open SourceCoalition ESS < 30%HIGH2023-03-13

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2023-21005

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21015

Open SourceCoalition ESS < 30%HIGH2023-03-13

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2023-21015

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21068

Open SourceCoalition ESS < 30%HIGH2023-03-13

In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to local escalation of privilege after preparing the device, hiding the warning, and passing the phone to a new user, wi...

CVEs:CVE-2023-21068

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-243433344

GoogleCoalition ESS < 30%NONE2023-03-01

PUB-A-243433344

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21016

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In AccountTypePreference of AccountTypePreference.java, there is a possible way to mislead the user about accounts installed on the device due to improper input validation. This could lead to local denial of service with no additional execution privile...

CVEs:CVE-2023-21016

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21026

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable region beyond its own SurfaceControl due to a logic error in the code. This could lead to local denial of service with no additional execution privileges nee...

CVEs:CVE-2023-21026

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21033

Open SourceCoalition ESS < 30%HIGH2023-03-13

In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2023-21033

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47478

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-47478

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47479

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-47479

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47471

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-47471

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47472

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-47472

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47473

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-47473

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47474

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-47474

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47475

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-47475

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47476

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-47476

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47477

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2022-47477

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47453

Open SourceCoalition ESS < 30%HIGH2023-03-10

In wcn service, there is a possible missing params check. This could lead to local denial of service in wcn service.

CVEs:CVE-2022-47453

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47454

Open SourceCoalition ESS < 30%HIGH2023-03-10

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47454

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47455

Open SourceCoalition ESS < 30%HIGH2023-03-10

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47455

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47456

Open SourceCoalition ESS < 30%HIGH2023-03-10

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47456

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47457

Open SourceCoalition ESS < 30%HIGH2023-03-10

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47457

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47458

Open SourceCoalition ESS < 30%HIGH2023-03-10

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47458

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47459

Open SourceCoalition ESS < 30%HIGH2023-03-06

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVEs:CVE-2022-47459

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47460

Open SourceCoalition ESS < 30%CRITICAL2023-03-06

In gpu device, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.

CVEs:CVE-2022-47460

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20957

Open SourceCoalition ESS < 30%HIGH2023-03-06

In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2023-20957

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20959

Open SourceCoalition ESS < 30%HIGH2023-03-06

In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2023-20959

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-264598465

GoogleCoalition ESS < 30%HIGH2023-03-01

ASB-A-264598465

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-264831217

GoogleCoalition ESS < 30%CRITICAL2023-03-01

ASB-A-264831217

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21001

Open SourceCoalition ESS < 30%HIGH2023-03-13

In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings of other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution pri...

CVEs:CVE-2023-21001

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21021

Open SourceCoalition ESS < 30%HIGH2023-03-13

In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin user network settings due to a missing permission check. This could lead to local escalation of privilege with no additional executi...

CVEs:CVE-2023-21021

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21055

Open SourceCoalition ESS < 30%HIGH2023-03-13

In dit_hal_ioctl of dit.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A...

CVEs:CVE-2023-21055

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47480

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVEs:CVE-2022-47480

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47481

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVEs:CVE-2022-47481

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47482

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVEs:CVE-2022-47482

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47483

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVEs:CVE-2022-47483

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47484

Open SourceCoalition ESS < 30%HIGH2023-03-10

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVEs:CVE-2022-47484

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-244301523

GoogleCoalition ESS < 30%HIGH2023-03-01

PUB-A-244301523

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21029

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...

CVEs:CVE-2023-21029

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20962

Open SourceCoalition ESS < 30%MEDIUM2023-03-06

In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges...

CVEs:CVE-2023-20962

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20625

Open SourceCoalition ESS < 30%HIGH2023-03-07

In adsp, there is a possible double free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628532; Issue ID: ALPS07628532.

CVEs:CVE-2023-20625

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21031

Open SourceCoalition ESS < 30%MEDIUM2023-03-13

In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2023-21031

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21000

Open SourceCoalition ESS < 30%HIGH2023-03-13

In MediaCodec.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...

CVEs:CVE-2023-21000

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20620

Open SourceCoalition ESS < 30%MEDIUM2023-03-06

In adsp, there is a possible escalation of privilege due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07554558; Issue ID: ALPS...

CVEs:CVE-2023-20620

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-264149248

GoogleCoalition ESS < 30%NONE2023-03-01

ASB-A-264149248

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20623

Open SourceCoalition ESS < 30%MEDIUM2023-03-06

In ion, there is a possible escalation of privilege due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559778; Issue...

CVEs:CVE-2023-20623

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

ASB-A-264209787

GoogleCoalition ESS < 30%NONE2023-03-01

ASB-A-264209787

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-24535

Open SourceEPSS <= 49%HIGH2023-03-14

google.golang.org/protobuf vulnerable to panic leading to denial of service

CVEs:CVE-2023-24535

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected google.golang.org google.golang.org/protobuf
Upstream advisory

GHSA-hw7c-3rfg-p46j

Open SourceEPSS <= 49%HIGH2023-03-14

google.golang.org/protobuf vulnerable to panic leading to denial of service

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected google.golang.org google.golang.org/protobuf
Upstream advisory

GHSA-hw7c-3rfg-p46j

Open SourceEPSS <= 49%HIGH2023-03-14

google.golang.org/protobuf vulnerable to panic leading to denial of service

Affected products

ProductStatusVendorPackageEcosystem
ko affected chainguard ko
ko affected wolfi ko
protobuf affected google.golang.org google.golang.org/protobuf
Upstream advisory

CVE-2023-24535

GoogleEPSS <= 49%2023-03-14

Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic.

CVEs:CVE-2023-24535

Upstream advisory

CVE-2023-24535

Open SourceEPSS <= 49%HIGH2023-03-14

Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic.

CVEs:CVE-2023-24535

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected protobuf
Upstream advisory

GO-2023-1631

Open SourceEPSS <= 49%2023-03-14

Panic when parsing invalid messages in google.golang.org/protobuf

Affected products

ProductStatusVendorPackageEcosystem
ko affected chainguard ko
ko affected wolfi ko
protobuf affected google.golang.org google.golang.org/protobuf
Upstream advisory

CVE-2023-28286

Open SourceEPSS <= 49%MEDIUM2023-03-14

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVEs:CVE-2023-28286

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

AZL-31216

Open SourceEPSS <= 49%CRITICAL2023-03-25

CVE-2023-25665 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

AZL-35310

Open SourceEPSS <= 49%CRITICAL2023-03-25

CVE-2023-25665 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-558h-mq8x-7q9g

Open SourceEPSS <= 49%HIGH2023-03-24

TensorFlow has Null Pointer Error in SparseSparseMaximum

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-558h-mq8x-7q9g

Open SourceEPSS <= 49%HIGH2023-03-24

TensorFlow has Null Pointer Error in SparseSparseMaximum

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25665

Open SourceEPSS <= 49%CRITICAL2023-03-24

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `SparseSparseMaximum` is given invalid sparse tensors as inputs, it can give a null pointer error. A fix is included in TensorFlow version 2.12 and ve...

CVEs:CVE-2023-25665

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25665

Open SourceEPSS <= 49%HIGH2023-03-24

TensorFlow has Null Pointer Error in SparseSparseMaximum

CVEs:CVE-2023-25665

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

CVE-2023-25665

Open SourceEPSS <= 49%HIGH2023-03-24

TensorFlow has Null Pointer Error in SparseSparseMaximum

CVEs:CVE-2023-25665

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-gpu affected PyPI tensorflow-gpu
Upstream advisory

GHSA-fxgc-95xx-grvq

Open SourceEPSS <= 49%HIGH2023-03-27

TensorFlow Denial of Service vulnerability

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

GHSA-fxgc-95xx-grvq

Open SourceEPSS <= 49%HIGH2023-03-27

TensorFlow Denial of Service vulnerability

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

AZL-31197

Open SourceEPSS <= 49%CRITICAL2023-03-27

CVE-2023-25661 affecting package tensorflow for versions less than 2.11.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:2 tensorflow
Upstream advisory

CVE-2023-25661

Open SourceEPSS <= 49%CRITICAL2023-03-27

TensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a tensorflow model (Check Failed) and can be used to trigger a denial of service attack. A proof of concept can be constructed with t...

CVEs:CVE-2023-25661

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2023-25661

Open SourceEPSS <= 49%MEDIUM2023-03-27

TensorFlow Denial of Service vulnerability

CVEs:CVE-2023-25661

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2023-25661

Open SourceEPSS <= 49%HIGH2023-03-27

TensorFlow Denial of Service vulnerability

CVEs:CVE-2023-25661

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected PyPI tensorflow
tensorflow-cpu affected PyPI tensorflow-cpu
Upstream advisory

CVE-2023-23864

GoogleEPSS <= 49%CRITICAL2023-03-23

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Michael Aronoff Very Simple Google Maps plugin <= 2.8.4 versions.

CVEs:CVE-2023-23864

Affected products

ProductStatusVendorPackageEcosystem
very_simple_google_maps affected very_simple_google_maps_project
Upstream advisory

CVE-2023-2314

GoogleEPSS <= 49%2023-03-07

Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-2314

Upstream advisory

CVE-2023-2314

GoogleEPSS <= 49%MEDIUM2023-03-07

Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-2314

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.