Advisories
GoogleExploitedCISA KEV listedCRITICAL2023-06-21
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app...
CVEs:CVE-2023-32434
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2023-06-21
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
CVEs:CVE-2023-32434
GoogleExploitedCISA KEV listedHIGH2023-06-21
CVEs:CVE-2023-32434
Open SourceExploitedCISA KEV listedCRITICAL2023-06-09
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
Open SourceExploitedCISA KEV listed2023-06-09
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourceExploitedCISA KEV listed2023-06-07
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceExploitedCISA KEV listedHIGH2023-06-05
DEBIAN-CVE-2023-3079
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleExploitedCISA KEV listedHIGH2023-06-05
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3079
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| couchbase_server |
affected |
couchbase |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| macos |
affected |
apple |
— |
— |
GoogleExploitedCISA KEV listedHIGH2023-06-05
CVEs:CVE-2023-3079
GoogleExploitedCISA KEV listed2023-06-05
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3079
Project ZeroExploitedCISA KEV listed2023-06-05
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3079
GoogleExploitedCISA KEV listedHIGH2023-06-21
CVEs:CVE-2023-32439
GoogleExploitedCISA KEV listed2023-06-21
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2023-32439
Project ZeroExploitedCISA KEV listed2023-06-21
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2023-32439
GoogleExploitedCISA KEV listedCRITICAL2023-06-21
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code exe...
CVEs:CVE-2023-32439
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| webkitgtk\+ |
affected |
webkitgtk |
— |
— |
GoogleExploitedCISA KEV listed2023-06-01
ASB-A-225040268
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceExploitedCISA KEV listedMEDIUM2023-06-13
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed...
CVEs:CVE-2023-21237
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleExploitedCISA KEV listedMEDIUM2023-06-13
CVEs:CVE-2023-21237
GoogleExploitedVulnCheck KEV listedCRITICAL2023-06-29
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a...
CVEs:CVE-2023-2982
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| wordpress_social_login_and_register_\(discord\,_google\,_twitter\,_linkedin\) |
affected |
miniorange |
— |
— |
GoogleExploitedVulnCheck KEV listedCRITICAL2023-06-29
CVEs:CVE-2023-2982
Open SourceWeaponized exploit2023-06-16
golang-go.crypto - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-go.crypto |
affected |
Debian:10 |
golang-go.crypto |
— |
Open SourceActive exploitation (sightings)CRITICAL2023-06-16
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2023-06-16
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourceActive exploitation (sightings)2023-06-15
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2023-06-13
CVEs:CVE-2023-3215
Open SourceActive exploitation (sightings)CRITICAL2023-06-13
DEBIAN-CVE-2023-3215
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2023-06-13
Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3215
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-06-13
CVEs:CVE-2023-3217
Open SourceActive exploitation (sightings)CRITICAL2023-06-13
DEBIAN-CVE-2023-3217
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2023-06-13
Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3217
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-06-13
CVEs:CVE-2023-33145
Open SourceActive exploitation (sightings)HIGH2023-06-13
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVEs:CVE-2023-33145
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-06-13
CVEs:CVE-2023-3214
Open SourceActive exploitation (sightings)CRITICAL2023-06-13
DEBIAN-CVE-2023-3214
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2023-06-13
Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVEs:CVE-2023-3214
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-06-19
CVEs:CVE-2023-2899
GoogleActive exploitation (sightings)CRITICAL2023-06-19
The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Script...
CVEs:CVE-2023-2899
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_map_shortcode |
affected |
web-argument |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-06-15
CVEs:CVE-2023-25055
GoogleActive exploitation (sightings)HIGH2023-06-15
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.
CVEs:CVE-2023-25055
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_xml_sitemap_for_videos |
affected |
digitalinspiration |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-06-05
CVEs:CVE-2023-3027
Open SourceActive exploitation (sightings)HIGH2023-06-05
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster s...
CVEs:CVE-2023-3027
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| advanced_cluster_management_for_kubernetes |
affected |
redhat |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-06-05
CVEs:CVE-2022-48439
Open SourceActive exploitation (sightings)CRITICAL2023-06-05
In cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2022-48439
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-06-05
In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
CVEs:CVE-2023-30863
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-06-05
CVEs:CVE-2023-30863
Open SourceActive exploitation (sightings)HIGH2023-06-05
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30866
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-06-05
CVEs:CVE-2023-30866
Open SourceActive exploitation (sightings)HIGH2023-06-05
In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30914
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-06-05
CVEs:CVE-2023-30914
Open SourceActive exploitation (sightings)HIGH2023-06-05
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVEs:CVE-2022-48443
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-06-05
CVEs:CVE-2022-48443
GoogleActive exploitation (sightings)MEDIUM2023-06-05
CVEs:CVE-2022-48444
Open SourceActive exploitation (sightings)HIGH2023-06-05
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVEs:CVE-2022-48444
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-06-05
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVEs:CVE-2022-48445
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-06-05
CVEs:CVE-2022-48445
GoogleActive exploitation (sightings)MEDIUM2023-06-05
CVEs:CVE-2022-48441
Open SourceActive exploitation (sightings)HIGH2023-06-05
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVEs:CVE-2022-48441
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-06-05
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVEs:CVE-2022-48442
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-06-05
CVEs:CVE-2022-48442
Open SourcePoC exploitCRITICAL2023-06-29
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourcePoC exploit2023-06-28
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
GooglePoC exploitHIGH2023-06-26
CVEs:CVE-2023-3420
Open SourcePoC exploitHIGH2023-06-26
DEBIAN-CVE-2023-3420
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitHIGH2023-06-26
Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3420
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
Open SourcePoC exploit2023-06-22
Fix CVE(s): CVE-2023-24329
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python3.6 |
affected |
TuxCare:Ubuntu:18.04 |
idle-python3.6 |
— |
| libpython3.6 |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6 |
— |
| libpython3.6-dev |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-dev |
— |
| libpython3.6-minimal |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-minimal |
— |
| libpython3.6-stdlib |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-stdlib |
— |
| libpython3.6-testsuite |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-testsuite |
— |
| python3.6 |
affected |
TuxCare:Ubuntu:18.04 |
python3.6 |
— |
| python3.6-dev |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-dev |
— |
| python3.6-doc |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-doc |
— |
| python3.6-examples |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-examples |
— |
| python3.6-minimal |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-minimal |
— |
| python3.6-venv |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-venv |
— |
Open SourcePoC exploit2023-06-22
Fix CVE(s): CVE-2023-24329
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python2.7 |
affected |
TuxCare:Ubuntu:18.04 |
idle-python2.7 |
— |
| libpython2.7 |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7 |
— |
| libpython2.7-dev |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-dev |
— |
| libpython2.7-minimal |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-minimal |
— |
| libpython2.7-stdlib |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-stdlib |
— |
| libpython2.7-testsuite |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-testsuite |
— |
| python2.7 |
affected |
TuxCare:Ubuntu:18.04 |
python2.7 |
— |
| python2.7-dev |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-dev |
— |
| python2.7-doc |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-doc |
— |
| python2.7-examples |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-examples |
— |
| python2.7-minimal |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-minimal |
— |
Open SourcePoC exploitHIGH2023-06-21
Security update for golang-github-prometheus-prometheus
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-prometheus-prometheus |
affected |
SUSE:Linux Enterprise Module for Package Hub 15 SP5 |
golang-github-prometheus-prometheus |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Proxy Module 4.2 |
golang-github-prometheus-prometheus |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Proxy Module 4.3 |
golang-github-prometheus-prometheus |
— |
| golang-github-prometheus-prometheus |
affected |
openSUSE:Leap 15.4 |
golang-github-prometheus-prometheus |
— |
| golang-github-prometheus-prometheus |
affected |
openSUSE:Leap 15.5 |
golang-github-prometheus-prometheus |
— |
Open SourcePoC exploitHIGH2023-06-26
Red Hat Security Advisory: OpenShift Container Platform 4.12.22 packages and security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| bpftool |
affected |
Red Hat:openshift:4.12::el8 |
bpftool |
— |
| bpftool-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
bpftool-debuginfo |
— |
| buildah |
affected |
Red Hat:openshift:4.12::el9 |
buildah |
— |
| buildah |
affected |
Red Hat:openshift:4.12::el8 |
buildah |
— |
| buildah-debuginfo |
affected |
Red Hat:openshift:4.12::el9 |
buildah-debuginfo |
— |
| buildah-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
buildah-debuginfo |
— |
| buildah-debugsource |
affected |
Red Hat:openshift:4.12::el9 |
buildah-debugsource |
— |
| buildah-debugsource |
affected |
Red Hat:openshift:4.12::el8 |
buildah-debugsource |
— |
| buildah-tests |
affected |
Red Hat:openshift:4.12::el8 |
buildah-tests |
— |
| buildah-tests |
affected |
Red Hat:openshift:4.12::el9 |
buildah-tests |
— |
| buildah-tests-debuginfo |
affected |
Red Hat:openshift:4.12::el9 |
buildah-tests-debuginfo |
— |
| buildah-tests-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
buildah-tests-debuginfo |
— |
| conmon |
affected |
Red Hat:openshift:4.12::el9 |
conmon |
— |
| conmon |
affected |
Red Hat:openshift:4.12::el8 |
conmon |
— |
| conmon-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
conmon-debuginfo |
— |
| conmon-debuginfo |
affected |
Red Hat:openshift:4.12::el9 |
conmon-debuginfo |
— |
| conmon-debugsource |
affected |
Red Hat:openshift:4.12::el9 |
conmon-debugsource |
— |
| conmon-debugsource |
affected |
Red Hat:openshift:4.12::el8 |
conmon-debugsource |
— |
| containernetworking-plugins |
affected |
Red Hat:openshift:4.12::el8 |
containernetworking-plugins |
— |
| containernetworking-plugins-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
containernetworking-plugins-debuginfo |
— |
| containernetworking-plugins-debugsource |
affected |
Red Hat:openshift:4.12::el8 |
containernetworking-plugins-debugsource |
— |
| kernel |
affected |
Red Hat:openshift:4.12::el8 |
kernel |
— |
| kernel-core |
affected |
Red Hat:openshift:4.12::el8 |
kernel-core |
— |
| kernel-debug |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debug |
— |
| kernel-debug-core |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debug-core |
— |
| kernel-debug-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debug-debuginfo |
— |
| kernel-debug-devel |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debug-devel |
— |
| kernel-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debuginfo |
— |
| kernel-debuginfo-common-aarch64 |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debuginfo-common-aarch64 |
— |
| kernel-debuginfo-common-ppc64le |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debuginfo-common-ppc64le |
— |
| kernel-debuginfo-common-s390x |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debuginfo-common-s390x |
— |
| kernel-debuginfo-common-x86_64 |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debuginfo-common-x86_64 |
— |
| kernel-debug-modules |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debug-modules |
— |
| kernel-debug-modules-extra |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debug-modules-extra |
— |
| kernel-debug-modules-internal |
affected |
Red Hat:openshift:4.12::el8 |
kernel-debug-modules-internal |
— |
| kernel-devel |
affected |
Red Hat:openshift:4.12::el8 |
kernel-devel |
— |
| kernel-doc |
affected |
Red Hat:openshift:4.12::el8 |
kernel-doc |
— |
| kernel-ipaclones-internal |
affected |
Red Hat:openshift:4.12::el8 |
kernel-ipaclones-internal |
— |
| kernel-modules |
affected |
Red Hat:openshift:4.12::el8 |
kernel-modules |
— |
| kernel-modules-extra |
affected |
Red Hat:openshift:4.12::el8 |
kernel-modules-extra |
— |
| kernel-modules-internal |
affected |
Red Hat:openshift:4.12::el8 |
kernel-modules-internal |
— |
| kernel-rt |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt |
— |
| kernel-rt-core |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-core |
— |
| kernel-rt-debug |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-debug |
— |
| kernel-rt-debug-core |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-debug-core |
— |
| kernel-rt-debug-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-debug-debuginfo |
— |
| kernel-rt-debug-devel |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-debug-devel |
— |
| kernel-rt-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-debuginfo |
— |
| kernel-rt-debuginfo-common-x86_64 |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-debuginfo-common-x86_64 |
— |
| kernel-rt-debug-kvm |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-debug-kvm |
— |
| kernel-rt-debug-modules |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-debug-modules |
— |
| kernel-rt-debug-modules-extra |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-debug-modules-extra |
— |
| kernel-rt-debug-modules-internal |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-debug-modules-internal |
— |
| kernel-rt-devel |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-devel |
— |
| kernel-rt-kvm |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-kvm |
— |
| kernel-rt-modules |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-modules |
— |
| kernel-rt-modules-extra |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-modules-extra |
— |
| kernel-rt-modules-internal |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-modules-internal |
— |
| kernel-rt-selftests-internal |
affected |
Red Hat:openshift:4.12::el8 |
kernel-rt-selftests-internal |
— |
| kernel-selftests-internal |
affected |
Red Hat:openshift:4.12::el8 |
kernel-selftests-internal |
— |
| kernel-tools |
affected |
Red Hat:openshift:4.12::el8 |
kernel-tools |
— |
| kernel-tools-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
kernel-tools-debuginfo |
— |
| kernel-tools-libs |
affected |
Red Hat:openshift:4.12::el8 |
kernel-tools-libs |
— |
| kernel-tools-libs-devel |
affected |
Red Hat:openshift:4.12::el8 |
kernel-tools-libs-devel |
— |
| kernel-zfcpdump |
affected |
Red Hat:openshift:4.12::el8 |
kernel-zfcpdump |
— |
| kernel-zfcpdump-core |
affected |
Red Hat:openshift:4.12::el8 |
kernel-zfcpdump-core |
— |
| kernel-zfcpdump-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
kernel-zfcpdump-debuginfo |
— |
| kernel-zfcpdump-devel |
affected |
Red Hat:openshift:4.12::el8 |
kernel-zfcpdump-devel |
— |
| kernel-zfcpdump-modules |
affected |
Red Hat:openshift:4.12::el8 |
kernel-zfcpdump-modules |
— |
| kernel-zfcpdump-modules-extra |
affected |
Red Hat:openshift:4.12::el8 |
kernel-zfcpdump-modules-extra |
— |
| kernel-zfcpdump-modules-internal |
affected |
Red Hat:openshift:4.12::el8 |
kernel-zfcpdump-modules-internal |
— |
| openshift |
affected |
Red Hat:openshift:4.12::el9 |
openshift |
— |
| openshift |
affected |
Red Hat:openshift:4.12::el8 |
openshift |
— |
| openshift4-aws-iso |
affected |
Red Hat:openshift:4.12::el8 |
openshift4-aws-iso |
— |
| openshift-ansible |
affected |
Red Hat:openshift:4.12::el8 |
openshift-ansible |
— |
| openshift-ansible-test |
affected |
Red Hat:openshift:4.12::el8 |
openshift-ansible-test |
— |
| openshift-clients |
affected |
Red Hat:openshift:4.12::el8 |
openshift-clients |
— |
| openshift-clients |
affected |
Red Hat:openshift:4.12::el9 |
openshift-clients |
— |
| openshift-clients-redistributable |
affected |
Red Hat:openshift:4.12::el8 |
openshift-clients-redistributable |
— |
| openshift-clients-redistributable |
affected |
Red Hat:openshift:4.12::el9 |
openshift-clients-redistributable |
— |
| openshift-hyperkube |
affected |
Red Hat:openshift:4.12::el9 |
openshift-hyperkube |
— |
| openshift-hyperkube |
affected |
Red Hat:openshift:4.12::el8 |
openshift-hyperkube |
— |
| openshift-kuryr |
affected |
Red Hat:openshift:4.12::el8 |
openshift-kuryr |
— |
| openshift-kuryr-cni |
affected |
Red Hat:openshift:4.12::el8 |
openshift-kuryr-cni |
— |
| openshift-kuryr-common |
affected |
Red Hat:openshift:4.12::el8 |
openshift-kuryr-common |
— |
| openshift-kuryr-controller |
affected |
Red Hat:openshift:4.12::el8 |
openshift-kuryr-controller |
— |
| perf |
affected |
Red Hat:openshift:4.12::el8 |
perf |
— |
| perf-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
perf-debuginfo |
— |
| podman |
affected |
Red Hat:openshift:4.12::el8 |
podman |
— |
| podman |
affected |
Red Hat:openshift:4.12::el9 |
podman |
— |
| podman-catatonit |
affected |
Red Hat:openshift:4.12::el9 |
podman-catatonit |
— |
| podman-catatonit |
affected |
Red Hat:openshift:4.12::el8 |
podman-catatonit |
— |
| podman-catatonit-debuginfo |
affected |
Red Hat:openshift:4.12::el9 |
podman-catatonit-debuginfo |
— |
| podman-catatonit-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
podman-catatonit-debuginfo |
— |
| podman-debuginfo |
affected |
Red Hat:openshift:4.12::el9 |
podman-debuginfo |
— |
| podman-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
podman-debuginfo |
— |
| podman-debugsource |
affected |
Red Hat:openshift:4.12::el8 |
podman-debugsource |
— |
| podman-debugsource |
affected |
Red Hat:openshift:4.12::el9 |
podman-debugsource |
— |
| podman-docker |
affected |
Red Hat:openshift:4.12::el8 |
podman-docker |
— |
| podman-docker |
affected |
Red Hat:openshift:4.12::el9 |
podman-docker |
— |
| podman-gvproxy |
affected |
Red Hat:openshift:4.12::el8 |
podman-gvproxy |
— |
| podman-gvproxy |
affected |
Red Hat:openshift:4.12::el9 |
podman-gvproxy |
— |
| podman-gvproxy-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
podman-gvproxy-debuginfo |
— |
| podman-gvproxy-debuginfo |
affected |
Red Hat:openshift:4.12::el9 |
podman-gvproxy-debuginfo |
— |
| podman-plugins |
affected |
Red Hat:openshift:4.12::el9 |
podman-plugins |
— |
| podman-plugins |
affected |
Red Hat:openshift:4.12::el8 |
podman-plugins |
— |
| podman-plugins-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
podman-plugins-debuginfo |
— |
| podman-plugins-debuginfo |
affected |
Red Hat:openshift:4.12::el9 |
podman-plugins-debuginfo |
— |
| podman-remote |
affected |
Red Hat:openshift:4.12::el9 |
podman-remote |
— |
| podman-remote |
affected |
Red Hat:openshift:4.12::el8 |
podman-remote |
— |
| podman-remote-debuginfo |
affected |
Red Hat:openshift:4.12::el9 |
podman-remote-debuginfo |
— |
| podman-remote-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
podman-remote-debuginfo |
— |
| podman-tests |
affected |
Red Hat:openshift:4.12::el9 |
podman-tests |
— |
| podman-tests |
affected |
Red Hat:openshift:4.12::el8 |
podman-tests |
— |
| python3-kuryr-kubernetes |
affected |
Red Hat:openshift:4.12::el8 |
python3-kuryr-kubernetes |
— |
| python3-perf |
affected |
Red Hat:openshift:4.12::el8 |
python3-perf |
— |
| python3-perf-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
python3-perf-debuginfo |
— |
| runc |
affected |
Red Hat:openshift:4.12::el8 |
runc |
— |
| runc-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
runc-debuginfo |
— |
| runc-debugsource |
affected |
Red Hat:openshift:4.12::el8 |
runc-debugsource |
— |
| skopeo |
affected |
Red Hat:openshift:4.12::el8 |
skopeo |
— |
| skopeo |
affected |
Red Hat:openshift:4.12::el9 |
skopeo |
— |
| skopeo-debuginfo |
affected |
Red Hat:openshift:4.12::el9 |
skopeo-debuginfo |
— |
| skopeo-debuginfo |
affected |
Red Hat:openshift:4.12::el8 |
skopeo-debuginfo |
— |
| skopeo-debugsource |
affected |
Red Hat:openshift:4.12::el9 |
skopeo-debugsource |
— |
| skopeo-debugsource |
affected |
Red Hat:openshift:4.12::el8 |
skopeo-debugsource |
— |
| skopeo-tests |
affected |
Red Hat:openshift:4.12::el9 |
skopeo-tests |
— |
| skopeo-tests |
affected |
Red Hat:openshift:4.12::el8 |
skopeo-tests |
— |
GooglePoC exploitMEDIUM2023-06-20
netty-handler SniHandler 16MB allocation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| io.netty:netty-handler |
affected |
Maven |
io.netty:netty-handler |
— |
Open SourcePoC exploitMEDIUM2023-06-20
netty-handler SniHandler 16MB allocation
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cloudwatch-exporter |
affected |
wolfi |
cloudwatch-exporter |
— |
| cloudwatch-exporter |
affected |
chainguard |
cloudwatch-exporter |
— |
| docker-selenium-jre-bcfips |
affected |
chainguard |
docker-selenium-jre-bcfips |
— |
| grpc-java-fips-1.56.0 |
affected |
chainguard |
grpc-java-fips-1.56.0 |
— |
| io.netty:netty-handler |
affected |
Maven |
io.netty:netty-handler |
— |
| stargate |
affected |
chainguard |
stargate |
— |
| wavefront-proxy |
affected |
chainguard |
wavefront-proxy |
— |
| wavefront-proxy |
affected |
wolfi |
wavefront-proxy |
— |
Open SourcePoC exploitCRITICAL2023-06-19
Security update for kubernetes1.24
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes1.24 |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP5 |
kubernetes1.24 |
— |
| kubernetes1.24 |
affected |
openSUSE:Leap 15.5 |
kubernetes1.24 |
— |
Open SourcePoC exploitCRITICAL2023-06-19
Security update for kubernetes1.23
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes1.23 |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP5 |
kubernetes1.23 |
— |
| kubernetes1.23 |
affected |
openSUSE:Leap 15.5 |
kubernetes1.23 |
— |
Open SourcePoC exploitCRITICAL2023-06-19
Security update for kubernetes1.23
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes1.23 |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP4 |
kubernetes1.23 |
— |
| kubernetes1.23 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS |
kubernetes1.23 |
— |
| kubernetes1.23 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS |
kubernetes1.23 |
— |
| kubernetes1.23 |
affected |
SUSE:Linux Enterprise Server 15 SP3-LTSS |
kubernetes1.23 |
— |
| kubernetes1.23 |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 |
kubernetes1.23 |
— |
| kubernetes1.23 |
affected |
SUSE:Enterprise Storage 7.1 |
kubernetes1.23 |
— |
Open SourcePoC exploitCRITICAL2023-06-19
Security update for kubernetes1.18
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP4 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise Server 15 SP2-LTSS |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise Server 15 SP3-LTSS |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Enterprise Storage 7 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Enterprise Storage 7.1 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
openSUSE:Leap 15.4 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
openSUSE:Leap 15.5 |
kubernetes1.18 |
— |
GooglePoC exploit2023-06-14
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.
CVEs:CVE-2023-2728
Open SourcePoC exploitMEDIUM2023-06-14
Kubernetes mountable secrets policy bypass
CVEs:CVE-2023-2728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitCRITICAL2023-06-14
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified...
CVEs:CVE-2023-2728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
Open SourcePoC exploitHIGH2023-06-29
Red Hat Security Advisory: go-toolset and golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Red Hat:enterprise_linux:9::appstream |
golang |
— |
| golang-bin |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-bin |
— |
| golang-docs |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-docs |
— |
| golang-misc |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-misc |
— |
| golang-race |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-race |
— |
| golang-src |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-src |
— |
| golang-tests |
affected |
Red Hat:enterprise_linux:9::appstream |
golang-tests |
— |
| go-toolset |
affected |
Red Hat:enterprise_linux:9::appstream |
go-toolset |
— |
Open SourcePoC exploitHIGH2023-06-29
Red Hat Security Advisory: go-toolset:rhel8 security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| delve |
affected |
Red Hat:enterprise_linux:8::appstream |
delve |
— |
| delve-debuginfo |
affected |
Red Hat:enterprise_linux:8::appstream |
delve-debuginfo |
— |
| delve-debugsource |
affected |
Red Hat:enterprise_linux:8::appstream |
delve-debugsource |
— |
| golang |
affected |
Red Hat:enterprise_linux:8::appstream |
golang |
— |
| golang-bin |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-bin |
— |
| golang-docs |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-docs |
— |
| golang-misc |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-misc |
— |
| golang-race |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-race |
— |
| golang-src |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-src |
— |
| golang-tests |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-tests |
— |
| go-toolset |
affected |
Red Hat:enterprise_linux:8::appstream |
go-toolset |
— |
Open SourcePoC exploitHIGH2023-06-29
Red Hat Security Advisory: go-toolset-1.19 and go-toolset-1.19-golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go-toolset-1.19 |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19 |
— |
| go-toolset-1.19-build |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-build |
— |
| go-toolset-1.19-golang |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang |
— |
| go-toolset-1.19-golang-bin |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-bin |
— |
| go-toolset-1.19-golang-docs |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-docs |
— |
| go-toolset-1.19-golang-misc |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-misc |
— |
| go-toolset-1.19-golang-race |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-race |
— |
| go-toolset-1.19-golang-src |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-src |
— |
| go-toolset-1.19-golang-tests |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-tests |
— |
| go-toolset-1.19-runtime |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-runtime |
— |
| go-toolset-1.19-scldevel |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-scldevel |
— |
Open SourcePoC exploitCRITICAL2023-06-29
Critical: go-toolset:rhel8 security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| delve |
affected |
AlmaLinux:8 |
delve |
— |
| golang |
affected |
AlmaLinux:8 |
golang |
— |
| golang-bin |
affected |
AlmaLinux:8 |
golang-bin |
— |
| golang-docs |
affected |
AlmaLinux:8 |
golang-docs |
— |
| golang-misc |
affected |
AlmaLinux:8 |
golang-misc |
— |
| golang-race |
affected |
AlmaLinux:8 |
golang-race |
— |
| golang-src |
affected |
AlmaLinux:8 |
golang-src |
— |
| golang-tests |
affected |
AlmaLinux:8 |
golang-tests |
— |
| go-toolset |
affected |
AlmaLinux:8 |
go-toolset |
— |
Open SourcePoC exploitCRITICAL2023-06-29
Critical: go-toolset and golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
AlmaLinux:9 |
golang |
— |
| golang-bin |
affected |
AlmaLinux:9 |
golang-bin |
— |
| golang-docs |
affected |
AlmaLinux:9 |
golang-docs |
— |
| golang-misc |
affected |
AlmaLinux:9 |
golang-misc |
— |
| golang-race |
affected |
AlmaLinux:9 |
golang-race |
— |
| golang-src |
affected |
AlmaLinux:9 |
golang-src |
— |
| golang-tests |
affected |
AlmaLinux:9 |
golang-tests |
— |
| go-toolset |
affected |
AlmaLinux:9 |
go-toolset |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29404 affecting package golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29404 affecting package msft-golang for versions less than 1.19.10-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| msft-golang |
affected |
Azure Linux:2 |
msft-golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29404 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29404 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29404 affecting package golang for versions less than 1.22.7-2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
DEBIAN-CVE-2023-29404
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
GooglePoC exploitCRITICAL2023-06-06
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a...
CVEs:CVE-2023-29404
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
GooglePoC exploitCRITICAL2023-06-06
CVEs:CVE-2023-29404
GooglePoC exploit2023-06-06
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. The arguments for a number of flags which are non-optional are incorrectly considered optional, allowing disallowed flags to be smuggled through the LDFLAGS sanitization. This affects usage of both the gc and gccgo compilers.
CVEs:CVE-2023-29404
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29405 affecting package golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29405 affecting package msft-golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| msft-golang |
affected |
Azure Linux:2 |
msft-golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29405 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29405 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29405 affecting package golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29405 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
DEBIAN-CVE-2023-29405
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
GooglePoC exploitCRITICAL2023-06-06
CVEs:CVE-2023-29405
GooglePoC exploitCRITICAL2023-06-06
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a...
CVEs:CVE-2023-29405
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
GooglePoC exploit2023-06-06
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. Flags containing embedded spaces are mishandled, allowing disallowed flags to be smuggled through the LDFLAGS sanitization by including them in the argument of another flag. This only affects usage of the gccgo compiler.
CVEs:CVE-2023-29405
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29402 affecting package golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29402 affecting package msft-golang for versions less than 1.19.10-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| msft-golang |
affected |
Azure Linux:2 |
msft-golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29402 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29402 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
CVE-2023-29402 affecting package golang for versions less than 1.22.7-2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-06-08
DEBIAN-CVE-2023-29402
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
GooglePoC exploitCRITICAL2023-06-06
CVEs:CVE-2023-29402
GooglePoC exploit2023-06-06
The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules which are retrieved using the go command, i.e. via "go get", are not affected (modules retrieved using GOPATH-mode, i.e. GO111MODULE=off, may be affected).
CVEs:CVE-2023-29402
GooglePoC exploitCRITICAL2023-06-06
The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline character...
CVEs:CVE-2023-29402
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
GooglePoC exploit2023-06-14
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
CVEs:CVE-2023-2727
Open SourcePoC exploitMEDIUM2023-06-14
kube-apiserver vulnerable to policy bypass
CVEs:CVE-2023-2727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitMEDIUM2023-06-14
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.
CVEs:CVE-2023-2727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
Open SourcePoC exploitCRITICAL2023-06-30
angular-ui-notification Cross-site Scripting vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular-ui-notification |
affected |
npm |
angular-ui-notification |
— |
Open SourcePoC exploitCRITICAL2023-06-30
angular-ui-notification Cross-site Scripting vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular-ui-notification |
affected |
npm |
angular-ui-notification |
— |
Open SourcePoC exploitMEDIUM2023-06-30
angular-ui-notification Cross-site Scripting vulnerability
CVEs:CVE-2023-34840
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular-ui-notification |
affected |
npm |
angular-ui-notification |
— |
Open SourcePoC exploitMEDIUM2023-06-30
angular-ui-notification Cross-site Scripting vulnerability
CVEs:CVE-2023-34840
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular-ui-notification |
affected |
npm |
angular-ui-notification |
— |
Open SourcePoC exploitCRITICAL2023-06-30
angular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVEs:CVE-2023-34840
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular-ui-notification |
affected |
angular-ui-notification_project |
— |
— |
Open SourcePoC exploitMEDIUM2023-06-09
DEBIAN-CVE-2023-32732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Debian:11 |
grpc |
— |
| grpc |
affected |
Debian:12 |
grpc |
— |
| grpc |
affected |
Debian:13 |
grpc |
— |
| grpc |
affected |
Debian:14 |
grpc |
— |
Open SourcePoC exploitMEDIUM2023-06-09
gRPC connection termination issue
CVEs:CVE-2023-32732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
| io.grpc:grpc-protobuf |
affected |
Maven |
io.grpc:grpc-protobuf |
— |
Open SourcePoC exploitMEDIUM2023-06-09
gRPC connection termination issue
CVEs:CVE-2023-32732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
| io.grpc:grpc-protobuf |
affected |
Maven |
io.grpc:grpc-protobuf |
— |
Open SourcePoC exploitMEDIUM2023-06-09
gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowe...
CVEs:CVE-2023-32732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| grpc |
affected |
grpc |
— |
— |
Open SourcePoC exploitCRITICAL2023-06-09
When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of HPACK tables between sender and receiver. If levera...
CVEs:CVE-2023-32731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
grpc |
— |
— |
Open SourcePoC exploitHIGH2023-06-09
Connection confusion in gRPC
CVEs:CVE-2023-32731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
| io.grpc:grpc-protobuf |
affected |
Maven |
io.grpc:grpc-protobuf |
— |
Open SourcePoC exploitCRITICAL2023-06-09
Connection confusion in gRPC
CVEs:CVE-2023-32731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
| io.grpc:grpc-protobuf |
affected |
Maven |
io.grpc:grpc-protobuf |
— |
Open SourcePoC exploitCRITICAL2023-06-08
DEBIAN-CVE-2023-29401
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-gin-gonic-gin |
affected |
Debian:11 |
golang-github-gin-gonic-gin |
— |
| golang-github-gin-gonic-gin |
affected |
Debian:12 |
golang-github-gin-gonic-gin |
— |
| golang-github-gin-gonic-gin |
affected |
Debian:13 |
golang-github-gin-gonic-gin |
— |
| golang-github-gin-gonic-gin |
affected |
Debian:14 |
golang-github-gin-gonic-gin |
— |
Open SourcePoC exploitHIGH2023-06-08
CVE-2023-29403 affecting package golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitHIGH2023-06-08
CVE-2023-29403 affecting package msft-golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| msft-golang |
affected |
Azure Linux:2 |
msft-golang |
— |
Open SourcePoC exploitHIGH2023-06-08
CVE-2023-29403 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitHIGH2023-06-08
CVE-2023-29403 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitHIGH2023-06-08
CVE-2023-29403 affecting package golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitHIGH2023-06-08
CVE-2023-29403 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitHIGH2023-06-08
DEBIAN-CVE-2023-29403
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
Open SourcePoC exploit2023-06-08
Unsafe behavior in setuid/setgid binaries in runtime
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kind |
affected |
chainguard |
kind |
— |
| kind |
affected |
wolfi |
kind |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| policy-controller |
affected |
chainguard |
policy-controller |
— |
| policy-controller |
affected |
wolfi |
policy-controller |
— |
| stdlib |
affected |
Go |
stdlib |
— |
GooglePoC exploitHIGH2023-06-06
CVEs:CVE-2023-29403
GooglePoC exploit2023-06-06
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers.
CVEs:CVE-2023-29403
GooglePoC exploitHIGH2023-06-06
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a set...
CVEs:CVE-2023-29403
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploitHIGH2023-06-09
gRPC Reachable Assertion issue
CVEs:CVE-2023-1428
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
| io.grpc:grpc-protobuf |
affected |
Maven |
io.grpc:grpc-protobuf |
— |
Open SourcePoC exploitHIGH2023-06-09
There exists an vulnerability causing an abort() to be called in gRPC.
The following headers cause gRPC's C++ implementation to abort() when called via http2:
te: x (x != trailers)
:scheme: x (x != http, https)
grpclb_client_stats: x (x == anythin...
CVEs:CVE-2023-1428
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
grpc |
— |
— |
Open SourcePoC exploitHIGH2023-06-09
gRPC Reachable Assertion issue
CVEs:CVE-2023-1428
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
| io.grpc:grpc-protobuf |
affected |
Maven |
io.grpc:grpc-protobuf |
— |
Open SourcePoC exploitCRITICAL2023-06-28
Security update for kubernetes1.23
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes1.23 |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP5 |
kubernetes1.23 |
— |
| kubernetes1.23 |
affected |
openSUSE:Leap 15.5 |
kubernetes1.23 |
— |
Open SourcePoC exploitCRITICAL2023-06-16
Kubelet vulnerable to bypass of seccomp profile enforcement
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitCRITICAL2023-06-16
Kubelet vulnerable to bypass of seccomp profile enforcement
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aws-ebs-csi-driver-1.18 |
affected |
chainguard |
aws-ebs-csi-driver-1.18 |
— |
| aws-efs-csi-driver |
affected |
chainguard |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver |
affected |
wolfi |
aws-efs-csi-driver |
— |
| kubeflow-pipelines |
affected |
chainguard |
kubeflow-pipelines |
— |
| kubeflow-pipelines |
affected |
wolfi |
kubeflow-pipelines |
— |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
| nodetaint |
affected |
chainguard |
nodetaint |
— |
| nodetaint |
affected |
wolfi |
nodetaint |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
Open SourcePoC exploitCRITICAL2023-06-16
DEBIAN-CVE-2023-2431
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
Open SourcePoC exploitMEDIUM2023-06-15
Kubelet vulnerable to bypass of seccomp profile enforcement
CVEs:CVE-2023-2431
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitCRITICAL2023-06-15
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability...
CVEs:CVE-2023-2431
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| kubernetes |
affected |
kubernetes |
— |
— |
GooglePoC exploit2023-06-15
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.
CVEs:CVE-2023-2431
GooglePoC exploitMEDIUM2023-06-14
Guava vulnerable to insecure use of temporary directory
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.google.guava:guava |
affected |
Maven |
com.google.guava:guava |
— |
Open SourcePoC exploitMEDIUM2023-06-14
Guava vulnerable to insecure use of temporary directory
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cassandra-4.0 |
affected |
chainguard |
cassandra-4.0 |
— |
| cassandra-4.1 |
affected |
chainguard |
cassandra-4.1 |
— |
| cassandra-4.1 |
affected |
wolfi |
cassandra-4.1 |
— |
| cassandra-fips-4.0 |
affected |
chainguard |
cassandra-fips-4.0 |
— |
| cassandra-fips-4.1 |
affected |
chainguard |
cassandra-fips-4.1 |
— |
| cassandra-reaper |
affected |
wolfi |
cassandra-reaper |
— |
| cassandra-reaper |
affected |
chainguard |
cassandra-reaper |
— |
| cassandra-reaper-jre-bcfips |
affected |
chainguard |
cassandra-reaper-jre-bcfips |
— |
| celeborn-0.5 |
affected |
wolfi |
celeborn-0.5 |
— |
| celeborn-0.5 |
affected |
chainguard |
celeborn-0.5 |
— |
| celeborn-0.6 |
affected |
wolfi |
celeborn-0.6 |
— |
| celeborn-0.6 |
affected |
chainguard |
celeborn-0.6 |
— |
| com.google.guava:guava |
affected |
Maven |
com.google.guava:guava |
— |
| debezium-connector-spanner-3.0 |
affected |
wolfi |
debezium-connector-spanner-3.0 |
— |
| debezium-connector-spanner-3.0 |
affected |
chainguard |
debezium-connector-spanner-3.0 |
— |
| druid |
affected |
chainguard |
druid |
— |
| druid |
affected |
wolfi |
druid |
— |
| elasticsearch-7 |
affected |
chainguard |
elasticsearch-7 |
— |
| elasticsearch-7.17 |
affected |
chainguard |
elasticsearch-7.17 |
— |
| gradle-8 |
affected |
chainguard |
gradle-8 |
— |
| gradle-8 |
affected |
wolfi |
gradle-8 |
— |
| grpc-java-fips-1.56.0 |
affected |
chainguard |
grpc-java-fips-1.56.0 |
— |
| hadoop-client-modules |
affected |
chainguard |
hadoop-client-modules |
— |
| hadoop-fips-3.3.6 |
affected |
chainguard |
hadoop-fips-3.3.6 |
— |
| keycloak |
affected |
wolfi |
keycloak |
— |
| keycloak |
affected |
chainguard |
keycloak |
— |
| keycloak-fips |
affected |
chainguard |
keycloak-fips |
— |
| maven |
affected |
wolfi |
maven |
— |
| maven |
affected |
chainguard |
maven |
— |
| maven-stage0 |
affected |
chainguard |
maven-stage0 |
— |
| maven-stage0 |
affected |
wolfi |
maven-stage0 |
— |
| spark-fips-3.5 |
affected |
chainguard |
spark-fips-3.5 |
— |
| spdx-tools-java |
affected |
wolfi |
spdx-tools-java |
— |
| spdx-tools-java |
affected |
chainguard |
spdx-tools-java |
— |
| trino |
affected |
wolfi |
trino |
— |
| trino |
affected |
chainguard |
trino |
— |
GooglePoC exploitMEDIUM2023-06-14
Guava vulnerable to insecure use of temporary directory
CVEs:CVE-2023-2976
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.google.guava:guava |
affected |
Maven |
com.google.guava:guava |
— |
GooglePoC exploitHIGH2023-06-14
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java tempo...
CVEs:CVE-2023-2976
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| guava |
affected |
google |
— |
— |
GooglePoC exploit2023-06-14
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.
Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.
CVEs:CVE-2023-2976
Open SourcePoC exploitMEDIUM2023-06-13
In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User in...
CVEs:CVE-2023-21173
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-06-13
CVEs:CVE-2023-21173
Open SourceCoalition ESS < 30%2023-06-03
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-09
Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc/grpc-swift |
affected |
github.com |
— |
— |
| grpc/grpc-swift |
affected |
github.com |
github.com/grpc/grpc-swift |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-09
Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc/grpc-swift |
affected |
github.com |
github.com/grpc/grpc-swift |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-06-09
Uncontrolled Resource Consumption in LengthPrefixedMessageReader
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc/grpc-swift |
affected |
github.com |
github.com/grpc/grpc-swift |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-06-09
Uncontrolled Resource Consumption in LengthPrefixedMessageReader
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc/grpc-swift |
affected |
github.com |
github.com/grpc/grpc-swift |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-06-03
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2023-33143
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-03
CVEs:CVE-2023-33143
GoogleCoalition ESS < 30%2023-06-01
ASB-A-278616909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-06-09
Denial of Service via reachable assertion
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc/grpc-swift |
affected |
github.com |
github.com/grpc/grpc-swift |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-06-09
Denial of Service via reachable assertion
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc/grpc-swift |
affected |
github.com |
github.com/grpc/grpc-swift |
— |
GoogleCoalition ESS < 30%HIGH2023-06-26
CVEs:CVE-2023-3421
Open SourceCoalition ESS < 30%CRITICAL2023-06-26
DEBIAN-CVE-2023-3421
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-06-26
Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3421
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-3216
Open SourceCoalition ESS < 30%HIGH2023-06-13
DEBIAN-CVE-2023-3216
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3216
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21144
Open SourceCoalition ESS < 30%HIGH2023-06-05
In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2023-21144
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-26
CVEs:CVE-2023-3422
Open SourceCoalition ESS < 30%CRITICAL2023-06-26
DEBIAN-CVE-2023-3422
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-06-26
Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3422
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-06-05
CVEs:CVE-2023-20965
Open SourceCoalition ESS < 30%CRITICAL2023-06-05
In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2023-20965
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-06-21
Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.
CVEs:CVE-2023-1943
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| operations |
affected |
kubernetes |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-21
kOps privilege escalation vulnerability
CVEs:CVE-2023-1943
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kops |
affected |
k8s.io |
k8s.io/kops |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-06-05
In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2023-21130
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-06-05
CVEs:CVE-2023-21130
Open SourceCoalition ESS < 30%CRITICAL2023-06-13
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2023-21066
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-06-13
CVEs:CVE-2023-21066
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-250100597
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21186
Open SourceCoalition ESS < 30%HIGH2023-06-13
In LogResponse of Dns.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2023-21186
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-13
In on_create_record_event of btif_sdp_server.cc, there is a possible out of bounds read due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2023-21201
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21201
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-261079188
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| vendor/google/native |
affected |
platform |
platform/vendor/google/native |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-05
In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: ...
CVEs:CVE-2023-21127
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21127
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21180
Open SourceCoalition ESS < 30%HIGH2023-06-13
In xmlParseTryOrFinish of parser.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2023-21180
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21224
Open SourceCoalition ESS < 30%HIGH2023-06-13
In ss_ProcessReturnResultComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2023-21224
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-265276966
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-13
In VideoFrame of VideoFrame.h, there is a possible abort due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...
CVEs:CVE-2023-21193
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21193
Open SourceCoalition ESS < 30%HIGH2023-06-13
In btm_acl_process_sca_cmpl_pkt of btm_acl.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-21197
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21197
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21223
Open SourceCoalition ESS < 30%HIGH2023-06-13
In LPP_ConvertGNSS_DataBitAssistance of LPP_CommonUtil.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not nee...
CVEs:CVE-2023-21223
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21226
Open SourceCoalition ESS < 30%HIGH2023-06-13
In SAEMM_RetrieveTaiList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not nee...
CVEs:CVE-2023-21226
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-240728187
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-256047000
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2023-21513
Open SourceCoalition ESS < 30%MEDIUM2023-06-05
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
CVEs:CVE-2023-21513
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-19
CVEs:CVE-2023-35772
GoogleCoalition ESS < 30%CRITICAL2023-06-19
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alain Gonzalez Google Map Shortcode plugin <= 3.1.2 versions.
CVEs:CVE-2023-35772
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_map_shortcode |
affected |
google_map_shortcode_project |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-13
there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2023-21219
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21219
Open SourceCoalition ESS < 30%HIGH2023-06-13
there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2023-21220
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21220
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-264590585
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-264698379
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-06-05
In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution priv...
CVEs:CVE-2021-0701
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-06-05
CVEs:CVE-2021-0701
GoogleCoalition ESS < 30%CRITICAL2023-06-05
CVEs:CVE-2021-0945
Open SourceCoalition ESS < 30%CRITICAL2023-06-05
In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via PhysmemNewRamBackedPMR. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...
CVEs:CVE-2021-0945
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2023-06-01
ASB-A-277775870
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2023-06-01
ASB-A-278156680
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-263783333
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-05
In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User intera...
CVEs:CVE-2023-21108
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21108
Open SourceCoalition ESS < 30%LOW2023-06-05
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.
CVEs:CVE-2023-21512
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleCoalition ESS < 30%LOW2023-06-05
CVEs:CVE-2023-21512
GoogleCoalition ESS < 30%2023-06-01
ASB-A-267242697
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21195
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In btm_ble_periodic_adv_sync_tx_rcvd of btm_ble_gap.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth, if the firmware were compromised with System execution priv...
CVEs:CVE-2023-21195
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21202
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In btm_delete_stored_link_key_complete of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over Bluetooth with System execution privileges needed. User interaction is n...
CVEs:CVE-2023-21202
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-05
In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro...
CVEs:CVE-2023-21137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2023-21137
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21212
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2023-21212
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2023-06-01
ASB-A-250627197
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2023-06-01
ASB-A-271880369
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2023-06-01
ASB-A-276750663
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
| vendor/qcom/opensource/graphics-kernel |
affected |
platform |
platform/vendor/qcom/opensource/graphics-kernel |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21209
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2023-21209
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2023-21136
Open SourceCoalition ESS < 30%MEDIUM2023-06-05
In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-21136
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In initiateVenueUrlAnqpQueryInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2023-21206
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21206
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21115
Open SourceCoalition ESS < 30%HIGH2023-06-05
In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2023-21115
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-05
In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges...
CVEs:CVE-2023-21122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21122
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21123
Open SourceCoalition ESS < 30%HIGH2023-06-05
In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileg...
CVEs:CVE-2023-21123
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21124
Open SourceCoalition ESS < 30%HIGH2023-06-05
In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2023-21124
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2023-06-01
PUB-A-261492548
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2023-21205
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21205
Open SourceCoalition ESS < 30%MEDIUM2023-06-05
In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2023-21105
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2023-21105
Open SourceCoalition ESS < 30%HIGH2023-06-13
In getCurrentPrivilegedPackagesForAllUsers of CarrierPrivilegesTracker.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User i...
CVEs:CVE-2023-21184
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21184
Open SourceCoalition ESS < 30%HIGH2023-06-13
In fixNotification of NotificationManagerService.java, there is a possible bypass of notification hide preference due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User in...
CVEs:CVE-2023-21191
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21191
Open SourceCoalition ESS < 30%HIGH2023-06-13
In lwis_i2c_device_disable of lwis_device_i2c.c, there is a possible UAF due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2023-21147
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21147
Open SourceCoalition ESS < 30%HIGH2023-06-13
In ForegroundUtils of ForegroundUtils.java, there is a possible way to read NFC tag data while the app is still in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges...
CVEs:CVE-2023-21183
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21183
GoogleCoalition ESS < 30%NONE2023-06-01
PUB-A-269661912
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-13
In encode of wlandata.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVEs:CVE-2023-21157
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21157
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21129
Open SourceCoalition ESS < 30%HIGH2023-06-05
In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while the app is in the background due to a BAL bypass. This could lead to local escalation of privilege with no additional execution pri...
CVEs:CVE-2023-21129
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-263783137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In addGroupWithConfigInternal of p2p_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2023-21214
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21214
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20739
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559819; Issue ID: ALPS07559819.
CVEs:CVE-2023-20739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20740
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559819; Issue ID: ALPS07559840.
CVEs:CVE-2023-20740
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21159
Open SourceCoalition ESS < 30%HIGH2023-06-13
In Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2023-21159
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-13
In Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2023-21161
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21161
Open SourceCoalition ESS < 30%HIGH2023-06-13
In btm_ble_update_inq_result of btm_ble_gap.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2023-21181
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21181
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is n...
CVEs:CVE-2023-21182
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21182
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21188
Open SourceCoalition ESS < 30%HIGH2023-06-13
In btm_ble_update_inq_result of btm_ble_gap.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2023-21188
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21222
Open SourceCoalition ESS < 30%HIGH2023-06-13
In load_dt_data of storage.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVEs:CVE-2023-21222
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-13
In aoc_service_set_read_blocked of aoc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2023-21236
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21236
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-252764175
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| hardware/google/gchips |
affected |
platform |
platform/hardware/google/gchips |
— |
| hardware/google/graphics/common |
affected |
platform |
platform/hardware/google/graphics/common |
— |
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-263783565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-263783702
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-266977723
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-270148537
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21151
Open SourceCoalition ESS < 30%HIGH2023-06-13
In the Google BMS kernel module, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2023-21151
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-13
In multiple functions of WifiCallingSettings.java, there is a possible way to change calling preferences for the admin user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. Us...
CVEs:CVE-2023-21172
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21172
Open SourceCoalition ESS < 30%HIGH2023-06-13
In isPageSearchEnabled of BillingCycleSettings.java, there is a possible way for the guest user to change data limits due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User int...
CVEs:CVE-2023-21174
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21174
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In btu_ble_proc_ltk_req of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21199
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21199
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2023-21204
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21204
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21213
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In initiateTdlsTeardownInternal of sta_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not ...
CVEs:CVE-2023-21213
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20744
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07519200.
CVEs:CVE-2023-20744
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-265149414
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21146
Open SourceCoalition ESS < 30%HIGH2023-06-13
there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid...
CVEs:CVE-2023-21146
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In Do_AIMS_SET_CALL_WAITING of imsservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2023-21153
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21153
Open SourceCoalition ESS < 30%HIGH2023-06-13
In encode of miscdata.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2023-21158
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21158
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In verifyInputEvent of InputDispatcher.cpp, there is a possible way to conduct click fraud due to side channel information disclosure. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee...
CVEs:CVE-2023-21171
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21171
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21192
Open SourceCoalition ESS < 30%HIGH2023-06-13
In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no additional execution ...
CVEs:CVE-2023-21192
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21203
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In startWpsPbcInternal of sta_iface.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2023-21203
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In initiateTdlsSetupInternal of sta_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2023-21207
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21207
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-239867994
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-263783635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%NONE2023-06-01
PUB-A-264259730
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ...
CVEs:CVE-2023-20738
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20738
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20732
Open SourceCoalition ESS < 30%MEDIUM2023-06-06
In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573480; Issue ID: A...
CVEs:CVE-2023-20732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20734
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ...
CVEs:CVE-2023-20734
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ...
CVEs:CVE-2023-20735
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20735
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21148
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In BuildSetConfig of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2023-21148
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In handle_set_parameters_ctrl of hal_socket.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2023-21150
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21150
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21154
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In StoreAdbSerialNumber of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2023-21154
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21156
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In BuildGetRadioNode of protocolmiscbulider.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure from the modem with System execution privileges needed. User interaction is not ne...
CVEs:CVE-2023-21156
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-13
In BuildSetTcsFci of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2023-21160
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21160
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21169
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In inviteInternal of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2023-21169
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In executeSetClientTarget of ComposerCommandEngine.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2023-21170
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21170
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In gatt_dbg_op_name of gatt_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed ...
CVEs:CVE-2023-21194
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21194
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21196
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In btm_ble_batchscan_filter_track_adv_vse_cback of btm_ble_batchscan.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges need...
CVEs:CVE-2023-21196
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21208
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In setCountryCodeInternal of sta_iface.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2023-21208
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In initiateHs20IconQueryInternal of sta_iface.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2023-21210
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21210
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21211
Open SourceCoalition ESS < 30%HIGH2023-06-13
In multiple files, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...
CVEs:CVE-2023-21211
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-263783657
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-263783910
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2023-06-01
PUB-A-263784118
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-264540759
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-267312009
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21176
Open SourceCoalition ESS < 30%HIGH2023-06-13
In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2023-21176
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21187
Open SourceCoalition ESS < 30%HIGH2023-06-13
In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2023-21187
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20751
Open SourceCoalition ESS < 30%HIGH2023-06-06
In keymange, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07825502; Issue...
CVEs:CVE-2023-20751
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-06
In keymange, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07826586; Issue...
CVEs:CVE-2023-20752
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20752
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20742
Open SourceCoalition ESS < 30%MEDIUM2023-06-06
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628591; Issue ID: AL...
CVEs:CVE-2023-20742
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-06
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628591; Issue ID: AL...
CVEs:CVE-2023-20741
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20741
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20728
Open SourceCoalition ESS < 30%MEDIUM2023-06-06
In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573603; Issue ID: A...
CVEs:CVE-2023-20728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20729
Open SourceCoalition ESS < 30%MEDIUM2023-06-06
In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573552; Issue ID: A...
CVEs:CVE-2023-20729
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20730
Open SourceCoalition ESS < 30%MEDIUM2023-06-06
In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573552; Issue ID: A...
CVEs:CVE-2023-20730
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20731
Open SourceCoalition ESS < 30%MEDIUM2023-06-06
In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573495; Issue ID: A...
CVEs:CVE-2023-20731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-06
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07796900; Issue ID:...
CVEs:CVE-2023-20715
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20715
Open SourceCoalition ESS < 30%HIGH2023-06-06
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07796883; Issue ID:...
CVEs:CVE-2023-20716
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20716
Open SourceCoalition ESS < 30%HIGH2023-06-06
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07734004 / ALP...
CVEs:CVE-2023-20725
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| rdk-b |
affected |
rdkcentral |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20725
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20712
Open SourceCoalition ESS < 30%HIGH2023-06-06
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07796914; Issue ID:...
CVEs:CVE-2023-20712
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20727
Open SourceCoalition ESS < 30%MEDIUM2023-06-06
In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588531; Issue ID: A...
CVEs:CVE-2023-20727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-05
In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVEs:CVE-2023-21135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21135
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21152
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In FaceStatsAnalyzer::InterpolateWeightList of face_stats_analyzer.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not ...
CVEs:CVE-2023-21152
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In BuildSetRadioNode of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2023-21155
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21155
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In convertCbYCrY of ColorConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2023-21168
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21168
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21198
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In remove_sdp_record of btif_sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2023-21198
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21200
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2023-21200
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-06
In swpm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID:...
CVEs:CVE-2023-20749
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20749
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-264540700
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-01
PUB-A-269174022
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21225
Open SourceCoalition ESS < 30%HIGH2023-06-13
there is a possible way to bypass the protected confirmation screen due to Failure to lock display power. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Produ...
CVEs:CVE-2023-21225
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20747
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue ID: ALPS07519121.
CVEs:CVE-2023-20747
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%NONE2023-06-01
PUB-A-270403821
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In setProfileName of DevicePolicyManagerService.java, there is a possible way to crash the SystemUI menu due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2023-21167
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21167
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20723
Open SourceCoalition ESS < 30%MEDIUM2023-06-06
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07843845; Issue...
CVEs:CVE-2023-20723
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-06
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07843845; Issue...
CVEs:CVE-2023-20724
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20724
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21128
Open SourceCoalition ESS < 30%HIGH2023-06-05
In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...
CVEs:CVE-2023-21128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-05
In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of Parcel Mismatch mitigations due to a logic error in the code. This could lead to local escalation of privilege and the ability to launch arbitrary activi...
CVEs:CVE-2023-21131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21131
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21175
Open SourceCoalition ESS < 30%HIGH2023-06-13
In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVEs:CVE-2023-21175
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-13
In registerGsmaServiceIntentReceiver of ShannonRcsService.java, there is a possible way to activate/deactivate RCS service due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges neede...
CVEs:CVE-2023-21149
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21149
Open SourceCoalition ESS < 30%HIGH2023-06-13
In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2023-21185
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21185
GoogleCoalition ESS < 30%NONE2023-06-01
PUB-A-270050709
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges ...
CVEs:CVE-2023-21177
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21177
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21189
Open SourceCoalition ESS < 30%HIGH2023-06-13
In startLockTaskMode of LockTaskController.java, there is a possible bypass of lock task mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed ...
CVEs:CVE-2023-21189
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-05
In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User int...
CVEs:CVE-2023-21126
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21126
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2022-48438
Open SourceCoalition ESS < 30%CRITICAL2023-06-05
In cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2022-48438
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2023-21143
Open SourceCoalition ESS < 30%MEDIUM2023-06-05
In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2023-21143
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2023-06-01
ASB-A-278801630
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-05
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
CVEs:CVE-2022-48390
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2022-48390
Open SourceCoalition ESS < 30%HIGH2023-06-05
In dialer service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
CVEs:CVE-2022-48392
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2022-48392
GoogleCoalition ESS < 30%2023-06-01
ASB-A-278775987
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2023-06-01
ASB-A-278775990
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2023-06-01
ASB-A-278796976
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-05
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVEs:CVE-2022-48391
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2022-48391
Open SourceCoalition ESS < 30%HIGH2023-06-05
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVEs:CVE-2022-48446
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2022-48446
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2022-48447
Open SourceCoalition ESS < 30%HIGH2023-06-05
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVEs:CVE-2022-48447
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21121
Open SourceCoalition ESS < 30%HIGH2023-06-05
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges ne...
CVEs:CVE-2023-21121
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21138
Open SourceCoalition ESS < 30%HIGH2023-06-05
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User...
CVEs:CVE-2023-21138
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21139
Open SourceCoalition ESS < 30%HIGH2023-06-05
In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2023-21139
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-06-05
In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2023-21141
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2023-21141
Open SourceCoalition ESS < 30%MEDIUM2023-06-05
In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2023-21142
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2023-21142
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2022-48448
Open SourceCoalition ESS < 30%HIGH2023-06-05
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVEs:CVE-2022-48448
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-13
In parseSecurityParamsFromXml of XmlUtil.java, there is a possible bypass of user specified wifi encryption protocol due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User in...
CVEs:CVE-2023-21179
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-13
CVEs:CVE-2023-21179
Open SourceCoalition ESS < 30%HIGH2023-06-13
In btm_acl_encrypt_change of btm_acl.cc, there is a possible way for a remote device to turn off encryption without resulting in a terminated connection due to an unusual root cause. This could lead to local information disclosure with no additional ex...
CVEs:CVE-2023-21190
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21190
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07...
CVEs:CVE-2023-20743
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20743
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07...
CVEs:CVE-2023-20745
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20745
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07...
CVEs:CVE-2023-20746
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20746
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20737
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645167.
CVEs:CVE-2023-20737
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20733
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645149.
CVEs:CVE-2023-20733
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-05
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVEs:CVE-2022-48440
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2022-48440
Open SourceCoalition ESS < 30%HIGH2023-06-05
In multiple functions of cdm_engine.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2023-21120
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21120
GoogleCoalition ESS < 30%HIGH2023-06-01
ASB-A-258188673
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20736
Open SourceCoalition ESS < 30%HIGH2023-06-06
In vcu, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07...
CVEs:CVE-2023-20736
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot-yocto |
affected |
linuxfoundation |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-06-06
In swpm, there is a possible out of bounds write due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID: ALPS07...
CVEs:CVE-2023-20750
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-06
CVEs:CVE-2023-20750
GoogleCoalition ESS < 30%HIGH2023-06-05
CVEs:CVE-2023-21101
Open SourceCoalition ESS < 30%HIGH2023-06-05
In multiple functions of WVDrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2023-21101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-06-01
ASB-A-258189255
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-05
CVEs:CVE-2023-21095
Open SourceCoalition ESS < 30%MEDIUM2023-06-05
In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...
CVEs:CVE-2023-21095
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-06-13
CVEs:CVE-2023-21178
Open SourceCoalition ESS < 30%MEDIUM2023-06-13
In installKey of KeyUtil.cpp, there is a possible failure of file encryption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVEs:CVE-2023-21178
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%MEDIUM2023-06-04
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVEs:CVE-2023-29345
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleEPSS <= 49%MEDIUM2023-06-04
CVEs:CVE-2023-29345
GoogleEPSS <= 49%MEDIUM2023-06-27
The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change t...
CVEs:CVE-2023-2326
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| gravity_forms_google_sheets_connector |
affected |
gsheetconnector |
— |
— |
GoogleEPSS <= 49%MEDIUM2023-06-27
CVEs:CVE-2023-2326
GoogleEPSS <= 49%MEDIUM2023-06-09
CVEs:CVE-2023-2526
GoogleEPSS <= 49%MEDIUM2023-06-09
The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.7. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated ...
CVEs:CVE-2023-2526
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| easy_google_maps |
affected |
supsystic |
— |
— |
GoogleEPSS <= 49%HIGH2023-06-15
CVEs:CVE-2023-23802
GoogleEPSS <= 49%HIGH2023-06-15
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions.
CVEs:CVE-2023-23802
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ht_easy_ga4_\(google_analytics_4\) |
affected |
hasthemes |
— |
— |
GoogleEPSS <= 49%HIGH2023-06-05
CVEs:CVE-2023-30864
Open SourceEPSS <= 49%HIGH2023-06-05
In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
CVEs:CVE-2023-30864
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2023-06-05
In dialer service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30865
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2023-06-05
CVEs:CVE-2023-30865
GoogleEPSS <= 49%MEDIUM2023-06-05
CVEs:CVE-2023-30915
Open SourceEPSS <= 49%HIGH2023-06-05
In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30915
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceAll remaining2023-06-27
Security update for kubernetes1.24
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes1.24 |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP5 |
kubernetes1.24 |
— |
| kubernetes1.24 |
affected |
openSUSE:Leap 15.5 |
kubernetes1.24 |
— |
Open SourceAll remaining2023-06-27
Security update for kubernetes1.24
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes1.24 |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP4 |
kubernetes1.24 |
— |
| kubernetes1.24 |
affected |
openSUSE:Leap 15.4 |
kubernetes1.24 |
— |
Open SourceAll remaining2023-06-23
Security update for golang-github-vpenso-prometheus_slurm_exporter
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-vpenso-prometheus_slurm_exporter |
affected |
SUSE:Linux Enterprise Module for Package Hub 15 SP5 |
golang-github-vpenso-prometheus_slurm_exporter |
— |
| golang-github-vpenso-prometheus_slurm_exporter |
affected |
openSUSE:Leap 15.5 |
golang-github-vpenso-prometheus_slurm_exporter |
— |
Open SourceAll remaining2023-06-23
Security update for google-cloud-sap-agent
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-cloud-sap-agent |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP1 |
google-cloud-sap-agent |
— |
| google-cloud-sap-agent |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP2 |
google-cloud-sap-agent |
— |
| google-cloud-sap-agent |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP3 |
google-cloud-sap-agent |
— |
| google-cloud-sap-agent |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 |
google-cloud-sap-agent |
— |
| google-cloud-sap-agent |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 |
google-cloud-sap-agent |
— |
| google-cloud-sap-agent |
affected |
openSUSE:Leap 15.5 |
google-cloud-sap-agent |
— |
Open SourceAll remaining2023-06-07
Security update for google-cloud-sap-agent
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google-cloud-sap-agent |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP1 |
google-cloud-sap-agent |
— |
| google-cloud-sap-agent |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP2 |
google-cloud-sap-agent |
— |
| google-cloud-sap-agent |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP3 |
google-cloud-sap-agent |
— |
| google-cloud-sap-agent |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 |
google-cloud-sap-agent |
— |
| google-cloud-sap-agent |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 |
google-cloud-sap-agent |
— |
| google-cloud-sap-agent |
affected |
openSUSE:Leap 15.5 |
google-cloud-sap-agent |
— |