Google Security Advisories · June 2023 — Google Security Advisories
519 advisories 306 CVEs 20 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2023-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 20 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2023-32434

GoogleExploitedCISA KEV listedCRITICAL2023-06-21

An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app...

CVEs:CVE-2023-32434

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2023-32434

Project ZeroExploitedCISA KEV listed2023-06-21

An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

CVEs:CVE-2023-32434

Upstream advisory

openSUSE-SU-2023:0124-1

Open SourceExploitedCISA KEV listedCRITICAL2023-06-09

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

openSUSE-SU-2023:0123-1

Open SourceExploitedCISA KEV listed2023-06-09

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DSA-5420-1

Open SourceExploitedCISA KEV listed2023-06-07

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2023-3079

Open SourceExploitedCISA KEV listedHIGH2023-06-05

DEBIAN-CVE-2023-3079

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3079

GoogleExploitedCISA KEV listedHIGH2023-06-05

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3079

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
couchbase_server affected couchbase
debian_linux affected debian
fedora affected fedoraproject
linux_kernel affected linux
macos affected apple
Upstream advisory

CVE-2023-3079

GoogleExploitedCISA KEV listed2023-06-05

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3079

Upstream advisory

CVE-2023-3079

Project ZeroExploitedCISA KEV listed2023-06-05

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3079

Upstream advisory

CVE-2023-32439

GoogleExploitedCISA KEV listed2023-06-21

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2023-32439

Upstream advisory

CVE-2023-32439

Project ZeroExploitedCISA KEV listed2023-06-21

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2023-32439

Upstream advisory

CVE-2023-32439

GoogleExploitedCISA KEV listedCRITICAL2023-06-21

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code exe...

CVEs:CVE-2023-32439

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
webkitgtk\+ affected webkitgtk
Upstream advisory

ASB-A-225040268

GoogleExploitedCISA KEV listed2023-06-01

ASB-A-225040268

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21237

Open SourceExploitedCISA KEV listedMEDIUM2023-06-13

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed...

CVEs:CVE-2023-21237

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-2982

GoogleExploitedVulnCheck KEV listedCRITICAL2023-06-29

The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a...

CVEs:CVE-2023-2982

Affected products

ProductStatusVendorPackageEcosystem
wordpress_social_login_and_register_\(discord\,_google\,_twitter\,_linkedin\) affected miniorange
Upstream advisory

DLA-3455-1

Open SourceWeaponized exploit2023-06-16

golang-go.crypto - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-go.crypto affected Debian:10 golang-go.crypto
Upstream advisory

openSUSE-SU-2023:0132-1

Open SourceActive exploitation (sightings)CRITICAL2023-06-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

openSUSE-SU-2023:0131-1

Open SourceActive exploitation (sightings)CRITICAL2023-06-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DSA-5428-1

Open SourceActive exploitation (sightings)2023-06-15

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-3215

Open SourceActive exploitation (sightings)CRITICAL2023-06-13

DEBIAN-CVE-2023-3215

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3215

GoogleActive exploitation (sightings)CRITICAL2023-06-13

Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3215

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-3217

Open SourceActive exploitation (sightings)CRITICAL2023-06-13

DEBIAN-CVE-2023-3217

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3217

GoogleActive exploitation (sightings)CRITICAL2023-06-13

Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3217

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-33145

Open SourceActive exploitation (sightings)HIGH2023-06-13

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVEs:CVE-2023-33145

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2023-3214

Open SourceActive exploitation (sightings)CRITICAL2023-06-13

DEBIAN-CVE-2023-3214

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3214

GoogleActive exploitation (sightings)CRITICAL2023-06-13

Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2023-3214

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-2899

GoogleActive exploitation (sightings)CRITICAL2023-06-19

The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Script...

CVEs:CVE-2023-2899

Affected products

ProductStatusVendorPackageEcosystem
google_map_shortcode affected web-argument
Upstream advisory

CVE-2023-25055

GoogleActive exploitation (sightings)HIGH2023-06-15

Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.

CVEs:CVE-2023-25055

Affected products

ProductStatusVendorPackageEcosystem
google_xml_sitemap_for_videos affected digitalinspiration
Upstream advisory

CVE-2023-3027

Open SourceActive exploitation (sightings)HIGH2023-06-05

The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster s...

CVEs:CVE-2023-3027

Affected products

ProductStatusVendorPackageEcosystem
advanced_cluster_management_for_kubernetes affected redhat
Upstream advisory

CVE-2022-48439

Open SourceActive exploitation (sightings)CRITICAL2023-06-05

In cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2022-48439

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30863

Open SourceActive exploitation (sightings)HIGH2023-06-05

In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVEs:CVE-2023-30863

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30866

Open SourceActive exploitation (sightings)HIGH2023-06-05

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30866

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30914

Open SourceActive exploitation (sightings)HIGH2023-06-05

In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30914

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48443

Open SourceActive exploitation (sightings)HIGH2023-06-05

In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVEs:CVE-2022-48443

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48444

Open SourceActive exploitation (sightings)HIGH2023-06-05

In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVEs:CVE-2022-48444

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48445

Open SourceActive exploitation (sightings)HIGH2023-06-05

In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVEs:CVE-2022-48445

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48441

Open SourceActive exploitation (sightings)HIGH2023-06-05

In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVEs:CVE-2022-48441

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48442

Open SourceActive exploitation (sightings)HIGH2023-06-05

In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVEs:CVE-2022-48442

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2023:0159-1

Open SourcePoC exploitCRITICAL2023-06-29

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DSA-5440-1

Open SourcePoC exploit2023-06-28

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-3420

Open SourcePoC exploitHIGH2023-06-26

DEBIAN-CVE-2023-3420

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3420

GooglePoC exploitHIGH2023-06-26

Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3420

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CLSA-2023-1687469630

Open SourcePoC exploit2023-06-22

Fix CVE(s): CVE-2023-24329

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.6 affected TuxCare:Ubuntu:18.04 idle-python3.6
libpython3.6 affected TuxCare:Ubuntu:18.04 libpython3.6
libpython3.6-dev affected TuxCare:Ubuntu:18.04 libpython3.6-dev
libpython3.6-minimal affected TuxCare:Ubuntu:18.04 libpython3.6-minimal
libpython3.6-stdlib affected TuxCare:Ubuntu:18.04 libpython3.6-stdlib
libpython3.6-testsuite affected TuxCare:Ubuntu:18.04 libpython3.6-testsuite
python3.6 affected TuxCare:Ubuntu:18.04 python3.6
python3.6-dev affected TuxCare:Ubuntu:18.04 python3.6-dev
python3.6-doc affected TuxCare:Ubuntu:18.04 python3.6-doc
python3.6-examples affected TuxCare:Ubuntu:18.04 python3.6-examples
python3.6-minimal affected TuxCare:Ubuntu:18.04 python3.6-minimal
python3.6-venv affected TuxCare:Ubuntu:18.04 python3.6-venv
Upstream advisory

CLSA-2023-1687469528

Open SourcePoC exploit2023-06-22

Fix CVE(s): CVE-2023-24329

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:18.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:18.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:18.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:18.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:18.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:18.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:18.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:18.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:18.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:18.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:18.04 python2.7-minimal
Upstream advisory

SUSE-SU-2023:2598-1

Open SourcePoC exploitHIGH2023-06-21

Security update for golang-github-prometheus-prometheus

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-prometheus affected SUSE:Linux Enterprise Module for Package Hub 15 SP5 golang-github-prometheus-prometheus
golang-github-prometheus-prometheus affected SUSE:Manager Proxy Module 4.2 golang-github-prometheus-prometheus
golang-github-prometheus-prometheus affected SUSE:Manager Proxy Module 4.3 golang-github-prometheus-prometheus
golang-github-prometheus-prometheus affected openSUSE:Leap 15.4 golang-github-prometheus-prometheus
golang-github-prometheus-prometheus affected openSUSE:Leap 15.5 golang-github-prometheus-prometheus
Upstream advisory

RHSA-2023:3613

Open SourcePoC exploitHIGH2023-06-26

Red Hat Security Advisory: OpenShift Container Platform 4.12.22 packages and security update

Affected products

ProductStatusVendorPackageEcosystem
bpftool affected Red Hat:openshift:4.12::el8 bpftool
bpftool-debuginfo affected Red Hat:openshift:4.12::el8 bpftool-debuginfo
buildah affected Red Hat:openshift:4.12::el9 buildah
buildah affected Red Hat:openshift:4.12::el8 buildah
buildah-debuginfo affected Red Hat:openshift:4.12::el9 buildah-debuginfo
buildah-debuginfo affected Red Hat:openshift:4.12::el8 buildah-debuginfo
buildah-debugsource affected Red Hat:openshift:4.12::el9 buildah-debugsource
buildah-debugsource affected Red Hat:openshift:4.12::el8 buildah-debugsource
buildah-tests affected Red Hat:openshift:4.12::el8 buildah-tests
buildah-tests affected Red Hat:openshift:4.12::el9 buildah-tests
buildah-tests-debuginfo affected Red Hat:openshift:4.12::el9 buildah-tests-debuginfo
buildah-tests-debuginfo affected Red Hat:openshift:4.12::el8 buildah-tests-debuginfo
conmon affected Red Hat:openshift:4.12::el9 conmon
conmon affected Red Hat:openshift:4.12::el8 conmon
conmon-debuginfo affected Red Hat:openshift:4.12::el8 conmon-debuginfo
conmon-debuginfo affected Red Hat:openshift:4.12::el9 conmon-debuginfo
conmon-debugsource affected Red Hat:openshift:4.12::el9 conmon-debugsource
conmon-debugsource affected Red Hat:openshift:4.12::el8 conmon-debugsource
containernetworking-plugins affected Red Hat:openshift:4.12::el8 containernetworking-plugins
containernetworking-plugins-debuginfo affected Red Hat:openshift:4.12::el8 containernetworking-plugins-debuginfo
containernetworking-plugins-debugsource affected Red Hat:openshift:4.12::el8 containernetworking-plugins-debugsource
kernel affected Red Hat:openshift:4.12::el8 kernel
kernel-core affected Red Hat:openshift:4.12::el8 kernel-core
kernel-debug affected Red Hat:openshift:4.12::el8 kernel-debug
kernel-debug-core affected Red Hat:openshift:4.12::el8 kernel-debug-core
kernel-debug-debuginfo affected Red Hat:openshift:4.12::el8 kernel-debug-debuginfo
kernel-debug-devel affected Red Hat:openshift:4.12::el8 kernel-debug-devel
kernel-debuginfo affected Red Hat:openshift:4.12::el8 kernel-debuginfo
kernel-debuginfo-common-aarch64 affected Red Hat:openshift:4.12::el8 kernel-debuginfo-common-aarch64
kernel-debuginfo-common-ppc64le affected Red Hat:openshift:4.12::el8 kernel-debuginfo-common-ppc64le
kernel-debuginfo-common-s390x affected Red Hat:openshift:4.12::el8 kernel-debuginfo-common-s390x
kernel-debuginfo-common-x86_64 affected Red Hat:openshift:4.12::el8 kernel-debuginfo-common-x86_64
kernel-debug-modules affected Red Hat:openshift:4.12::el8 kernel-debug-modules
kernel-debug-modules-extra affected Red Hat:openshift:4.12::el8 kernel-debug-modules-extra
kernel-debug-modules-internal affected Red Hat:openshift:4.12::el8 kernel-debug-modules-internal
kernel-devel affected Red Hat:openshift:4.12::el8 kernel-devel
kernel-doc affected Red Hat:openshift:4.12::el8 kernel-doc
kernel-ipaclones-internal affected Red Hat:openshift:4.12::el8 kernel-ipaclones-internal
kernel-modules affected Red Hat:openshift:4.12::el8 kernel-modules
kernel-modules-extra affected Red Hat:openshift:4.12::el8 kernel-modules-extra
kernel-modules-internal affected Red Hat:openshift:4.12::el8 kernel-modules-internal
kernel-rt affected Red Hat:openshift:4.12::el8 kernel-rt
kernel-rt-core affected Red Hat:openshift:4.12::el8 kernel-rt-core
kernel-rt-debug affected Red Hat:openshift:4.12::el8 kernel-rt-debug
kernel-rt-debug-core affected Red Hat:openshift:4.12::el8 kernel-rt-debug-core
kernel-rt-debug-debuginfo affected Red Hat:openshift:4.12::el8 kernel-rt-debug-debuginfo
kernel-rt-debug-devel affected Red Hat:openshift:4.12::el8 kernel-rt-debug-devel
kernel-rt-debuginfo affected Red Hat:openshift:4.12::el8 kernel-rt-debuginfo
kernel-rt-debuginfo-common-x86_64 affected Red Hat:openshift:4.12::el8 kernel-rt-debuginfo-common-x86_64
kernel-rt-debug-kvm affected Red Hat:openshift:4.12::el8 kernel-rt-debug-kvm
kernel-rt-debug-modules affected Red Hat:openshift:4.12::el8 kernel-rt-debug-modules
kernel-rt-debug-modules-extra affected Red Hat:openshift:4.12::el8 kernel-rt-debug-modules-extra
kernel-rt-debug-modules-internal affected Red Hat:openshift:4.12::el8 kernel-rt-debug-modules-internal
kernel-rt-devel affected Red Hat:openshift:4.12::el8 kernel-rt-devel
kernel-rt-kvm affected Red Hat:openshift:4.12::el8 kernel-rt-kvm
kernel-rt-modules affected Red Hat:openshift:4.12::el8 kernel-rt-modules
kernel-rt-modules-extra affected Red Hat:openshift:4.12::el8 kernel-rt-modules-extra
kernel-rt-modules-internal affected Red Hat:openshift:4.12::el8 kernel-rt-modules-internal
kernel-rt-selftests-internal affected Red Hat:openshift:4.12::el8 kernel-rt-selftests-internal
kernel-selftests-internal affected Red Hat:openshift:4.12::el8 kernel-selftests-internal
kernel-tools affected Red Hat:openshift:4.12::el8 kernel-tools
kernel-tools-debuginfo affected Red Hat:openshift:4.12::el8 kernel-tools-debuginfo
kernel-tools-libs affected Red Hat:openshift:4.12::el8 kernel-tools-libs
kernel-tools-libs-devel affected Red Hat:openshift:4.12::el8 kernel-tools-libs-devel
kernel-zfcpdump affected Red Hat:openshift:4.12::el8 kernel-zfcpdump
kernel-zfcpdump-core affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-core
kernel-zfcpdump-debuginfo affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-debuginfo
kernel-zfcpdump-devel affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-devel
kernel-zfcpdump-modules affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-modules
kernel-zfcpdump-modules-extra affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-modules-extra
kernel-zfcpdump-modules-internal affected Red Hat:openshift:4.12::el8 kernel-zfcpdump-modules-internal
openshift affected Red Hat:openshift:4.12::el9 openshift
openshift affected Red Hat:openshift:4.12::el8 openshift
openshift4-aws-iso affected Red Hat:openshift:4.12::el8 openshift4-aws-iso
openshift-ansible affected Red Hat:openshift:4.12::el8 openshift-ansible
openshift-ansible-test affected Red Hat:openshift:4.12::el8 openshift-ansible-test
openshift-clients affected Red Hat:openshift:4.12::el8 openshift-clients
openshift-clients affected Red Hat:openshift:4.12::el9 openshift-clients
openshift-clients-redistributable affected Red Hat:openshift:4.12::el8 openshift-clients-redistributable
openshift-clients-redistributable affected Red Hat:openshift:4.12::el9 openshift-clients-redistributable
openshift-hyperkube affected Red Hat:openshift:4.12::el9 openshift-hyperkube
openshift-hyperkube affected Red Hat:openshift:4.12::el8 openshift-hyperkube
openshift-kuryr affected Red Hat:openshift:4.12::el8 openshift-kuryr
openshift-kuryr-cni affected Red Hat:openshift:4.12::el8 openshift-kuryr-cni
openshift-kuryr-common affected Red Hat:openshift:4.12::el8 openshift-kuryr-common
openshift-kuryr-controller affected Red Hat:openshift:4.12::el8 openshift-kuryr-controller
perf affected Red Hat:openshift:4.12::el8 perf
perf-debuginfo affected Red Hat:openshift:4.12::el8 perf-debuginfo
podman affected Red Hat:openshift:4.12::el8 podman
podman affected Red Hat:openshift:4.12::el9 podman
podman-catatonit affected Red Hat:openshift:4.12::el9 podman-catatonit
podman-catatonit affected Red Hat:openshift:4.12::el8 podman-catatonit
podman-catatonit-debuginfo affected Red Hat:openshift:4.12::el9 podman-catatonit-debuginfo
podman-catatonit-debuginfo affected Red Hat:openshift:4.12::el8 podman-catatonit-debuginfo
podman-debuginfo affected Red Hat:openshift:4.12::el9 podman-debuginfo
podman-debuginfo affected Red Hat:openshift:4.12::el8 podman-debuginfo
podman-debugsource affected Red Hat:openshift:4.12::el8 podman-debugsource
podman-debugsource affected Red Hat:openshift:4.12::el9 podman-debugsource
podman-docker affected Red Hat:openshift:4.12::el8 podman-docker
podman-docker affected Red Hat:openshift:4.12::el9 podman-docker
podman-gvproxy affected Red Hat:openshift:4.12::el8 podman-gvproxy
podman-gvproxy affected Red Hat:openshift:4.12::el9 podman-gvproxy
podman-gvproxy-debuginfo affected Red Hat:openshift:4.12::el8 podman-gvproxy-debuginfo
podman-gvproxy-debuginfo affected Red Hat:openshift:4.12::el9 podman-gvproxy-debuginfo
podman-plugins affected Red Hat:openshift:4.12::el9 podman-plugins
podman-plugins affected Red Hat:openshift:4.12::el8 podman-plugins
podman-plugins-debuginfo affected Red Hat:openshift:4.12::el8 podman-plugins-debuginfo
podman-plugins-debuginfo affected Red Hat:openshift:4.12::el9 podman-plugins-debuginfo
podman-remote affected Red Hat:openshift:4.12::el9 podman-remote
podman-remote affected Red Hat:openshift:4.12::el8 podman-remote
podman-remote-debuginfo affected Red Hat:openshift:4.12::el9 podman-remote-debuginfo
podman-remote-debuginfo affected Red Hat:openshift:4.12::el8 podman-remote-debuginfo
podman-tests affected Red Hat:openshift:4.12::el9 podman-tests
podman-tests affected Red Hat:openshift:4.12::el8 podman-tests
python3-kuryr-kubernetes affected Red Hat:openshift:4.12::el8 python3-kuryr-kubernetes
python3-perf affected Red Hat:openshift:4.12::el8 python3-perf
python3-perf-debuginfo affected Red Hat:openshift:4.12::el8 python3-perf-debuginfo
runc affected Red Hat:openshift:4.12::el8 runc
runc-debuginfo affected Red Hat:openshift:4.12::el8 runc-debuginfo
runc-debugsource affected Red Hat:openshift:4.12::el8 runc-debugsource
skopeo affected Red Hat:openshift:4.12::el8 skopeo
skopeo affected Red Hat:openshift:4.12::el9 skopeo
skopeo-debuginfo affected Red Hat:openshift:4.12::el9 skopeo-debuginfo
skopeo-debuginfo affected Red Hat:openshift:4.12::el8 skopeo-debuginfo
skopeo-debugsource affected Red Hat:openshift:4.12::el9 skopeo-debugsource
skopeo-debugsource affected Red Hat:openshift:4.12::el8 skopeo-debugsource
skopeo-tests affected Red Hat:openshift:4.12::el9 skopeo-tests
skopeo-tests affected Red Hat:openshift:4.12::el8 skopeo-tests
Upstream advisory

GHSA-6mjq-h674-j845

GooglePoC exploitMEDIUM2023-06-20

netty-handler SniHandler 16MB allocation

Affected products

ProductStatusVendorPackageEcosystem
io.netty:netty-handler affected Maven io.netty:netty-handler
Upstream advisory

GHSA-6mjq-h674-j845

Open SourcePoC exploitMEDIUM2023-06-20

netty-handler SniHandler 16MB allocation

Affected products

ProductStatusVendorPackageEcosystem
cloudwatch-exporter affected wolfi cloudwatch-exporter
cloudwatch-exporter affected chainguard cloudwatch-exporter
docker-selenium-jre-bcfips affected chainguard docker-selenium-jre-bcfips
grpc-java-fips-1.56.0 affected chainguard grpc-java-fips-1.56.0
io.netty:netty-handler affected Maven io.netty:netty-handler
stargate affected chainguard stargate
wavefront-proxy affected chainguard wavefront-proxy
wavefront-proxy affected wolfi wavefront-proxy
Upstream advisory

SUSE-SU-2023:2544-1

Open SourcePoC exploitCRITICAL2023-06-19

Security update for kubernetes1.24

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.24 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.24
kubernetes1.24 affected openSUSE:Leap 15.5 kubernetes1.24
Upstream advisory

SUSE-SU-2023:2543-1

Open SourcePoC exploitCRITICAL2023-06-19

Security update for kubernetes1.23

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.23 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.23
kubernetes1.23 affected openSUSE:Leap 15.5 kubernetes1.23
Upstream advisory

SUSE-SU-2023:2542-1

Open SourcePoC exploitCRITICAL2023-06-19

Security update for kubernetes1.23

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.23 affected SUSE:Linux Enterprise Module for Containers 15 SP4 kubernetes1.23
kubernetes1.23 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS kubernetes1.23
kubernetes1.23 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kubernetes1.23
kubernetes1.23 affected SUSE:Linux Enterprise Server 15 SP3-LTSS kubernetes1.23
kubernetes1.23 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kubernetes1.23
kubernetes1.23 affected SUSE:Enterprise Storage 7.1 kubernetes1.23
Upstream advisory

SUSE-SU-2023:2541-1

Open SourcePoC exploitCRITICAL2023-06-19

Security update for kubernetes1.18

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.18 affected SUSE:Linux Enterprise Module for Containers 15 SP4 kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server 15 SP2-LTSS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server 15 SP3-LTSS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kubernetes1.18
kubernetes1.18 affected SUSE:Enterprise Storage 7 kubernetes1.18
kubernetes1.18 affected SUSE:Enterprise Storage 7.1 kubernetes1.18
kubernetes1.18 affected openSUSE:Leap 15.4 kubernetes1.18
kubernetes1.18 affected openSUSE:Leap 15.5 kubernetes1.18
Upstream advisory

CVE-2023-2728

GooglePoC exploit2023-06-14

Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.

CVEs:CVE-2023-2728

Upstream advisory

CVE-2023-2728

Open SourcePoC exploitMEDIUM2023-06-14

Kubernetes mountable secrets policy bypass

CVEs:CVE-2023-2728

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2023-2728

Open SourcePoC exploitCRITICAL2023-06-14

Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified...

CVEs:CVE-2023-2728

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

RHSA-2023:3923

Open SourcePoC exploitHIGH2023-06-29

Red Hat Security Advisory: go-toolset and golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:9::appstream golang
golang-bin affected Red Hat:enterprise_linux:9::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:9::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:9::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:9::appstream golang-race
golang-src affected Red Hat:enterprise_linux:9::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:9::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:9::appstream go-toolset
Upstream advisory

RHSA-2023:3922

Open SourcePoC exploitHIGH2023-06-29

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

RHSA-2023:3920

Open SourcePoC exploitHIGH2023-06-29

Red Hat Security Advisory: go-toolset-1.19 and go-toolset-1.19-golang security update

Affected products

ProductStatusVendorPackageEcosystem
go-toolset-1.19 affected Red Hat:devtools:2023::el7 go-toolset-1.19
go-toolset-1.19-build affected Red Hat:devtools:2023::el7 go-toolset-1.19-build
go-toolset-1.19-golang affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang
go-toolset-1.19-golang-bin affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-bin
go-toolset-1.19-golang-docs affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-docs
go-toolset-1.19-golang-misc affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-misc
go-toolset-1.19-golang-race affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-race
go-toolset-1.19-golang-src affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-src
go-toolset-1.19-golang-tests affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-tests
go-toolset-1.19-runtime affected Red Hat:devtools:2023::el7 go-toolset-1.19-runtime
go-toolset-1.19-scldevel affected Red Hat:devtools:2023::el7 go-toolset-1.19-scldevel
Upstream advisory

ALSA-2023:3922

Open SourcePoC exploitCRITICAL2023-06-29

Critical: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected AlmaLinux:8 delve
golang affected AlmaLinux:8 golang
golang-bin affected AlmaLinux:8 golang-bin
golang-docs affected AlmaLinux:8 golang-docs
golang-misc affected AlmaLinux:8 golang-misc
golang-race affected AlmaLinux:8 golang-race
golang-src affected AlmaLinux:8 golang-src
golang-tests affected AlmaLinux:8 golang-tests
go-toolset affected AlmaLinux:8 go-toolset
Upstream advisory

ALSA-2023:3923

Open SourcePoC exploitCRITICAL2023-06-29

Critical: go-toolset and golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected AlmaLinux:9 golang
golang-bin affected AlmaLinux:9 golang-bin
golang-docs affected AlmaLinux:9 golang-docs
golang-misc affected AlmaLinux:9 golang-misc
golang-race affected AlmaLinux:9 golang-race
golang-src affected AlmaLinux:9 golang-src
golang-tests affected AlmaLinux:9 golang-tests
go-toolset affected AlmaLinux:9 go-toolset
Upstream advisory

AZL-27140

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29404 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-27150

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29404 affecting package msft-golang for versions less than 1.19.10-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37337

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29404 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37510

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29404 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-47146

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29404 affecting package golang for versions less than 1.22.7-2

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-29404

Open SourcePoC exploitCRITICAL2023-06-08

DEBIAN-CVE-2023-29404

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2023-29404

GooglePoC exploitCRITICAL2023-06-06

The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a...

CVEs:CVE-2023-29404

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
Upstream advisory

CVE-2023-29404

GooglePoC exploit2023-06-06

The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. The arguments for a number of flags which are non-optional are incorrectly considered optional, allowing disallowed flags to be smuggled through the LDFLAGS sanitization. This affects usage of both the gc and gccgo compilers.

CVEs:CVE-2023-29404

Upstream advisory

AZL-27110

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29405 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-27123

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29405 affecting package msft-golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37347

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29405 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37499

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29405 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-52827

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29405 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-79012

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29405 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-29405

Open SourcePoC exploitCRITICAL2023-06-08

DEBIAN-CVE-2023-29405

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2023-29405

GooglePoC exploitCRITICAL2023-06-06

The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a...

CVEs:CVE-2023-29405

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
Upstream advisory

CVE-2023-29405

GooglePoC exploit2023-06-06

The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. Flags containing embedded spaces are mishandled, allowing disallowed flags to be smuggled through the LDFLAGS sanitization by including them in the argument of another flag. This only affects usage of the gccgo compiler.

CVEs:CVE-2023-29405

Upstream advisory

AZL-27111

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29402 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-27122

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29402 affecting package msft-golang for versions less than 1.19.10-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37329

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29402 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37353

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29402 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-47225

Open SourcePoC exploitCRITICAL2023-06-08

CVE-2023-29402 affecting package golang for versions less than 1.22.7-2

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-29402

Open SourcePoC exploitCRITICAL2023-06-08

DEBIAN-CVE-2023-29402

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2023-29402

GooglePoC exploit2023-06-06

The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules which are retrieved using the go command, i.e. via "go get", are not affected (modules retrieved using GOPATH-mode, i.e. GO111MODULE=off, may be affected).

CVEs:CVE-2023-29402

Upstream advisory

CVE-2023-29402

GooglePoC exploitCRITICAL2023-06-06

The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline character...

CVEs:CVE-2023-29402

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
Upstream advisory

CVE-2023-2727

GooglePoC exploit2023-06-14

Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.

CVEs:CVE-2023-2727

Upstream advisory

CVE-2023-2727

Open SourcePoC exploitMEDIUM2023-06-14

kube-apiserver vulnerable to policy bypass

CVEs:CVE-2023-2727

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2023-2727

Open SourcePoC exploitMEDIUM2023-06-14

Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.

CVEs:CVE-2023-2727

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

GHSA-mrcj-5qxr-vhp2

Open SourcePoC exploitCRITICAL2023-06-30

angular-ui-notification Cross-site Scripting vulnerability

Affected products

ProductStatusVendorPackageEcosystem
angular-ui-notification affected npm angular-ui-notification
Upstream advisory

GHSA-mrcj-5qxr-vhp2

Open SourcePoC exploitCRITICAL2023-06-30

angular-ui-notification Cross-site Scripting vulnerability

Affected products

ProductStatusVendorPackageEcosystem
angular-ui-notification affected npm angular-ui-notification
Upstream advisory

CVE-2023-34840

Open SourcePoC exploitMEDIUM2023-06-30

angular-ui-notification Cross-site Scripting vulnerability

CVEs:CVE-2023-34840

Affected products

ProductStatusVendorPackageEcosystem
angular-ui-notification affected npm angular-ui-notification
Upstream advisory

CVE-2023-34840

Open SourcePoC exploitMEDIUM2023-06-30

angular-ui-notification Cross-site Scripting vulnerability

CVEs:CVE-2023-34840

Affected products

ProductStatusVendorPackageEcosystem
angular-ui-notification affected npm angular-ui-notification
Upstream advisory

CVE-2023-34840

Open SourcePoC exploitCRITICAL2023-06-30

angular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVEs:CVE-2023-34840

Affected products

ProductStatusVendorPackageEcosystem
angular-ui-notification affected angular-ui-notification_project
Upstream advisory

DEBIAN-CVE-2023-32732

Open SourcePoC exploitMEDIUM2023-06-09

DEBIAN-CVE-2023-32732

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Debian:11 grpc
grpc affected Debian:12 grpc
grpc affected Debian:13 grpc
grpc affected Debian:14 grpc
Upstream advisory

CVE-2023-32732

Open SourcePoC exploitMEDIUM2023-06-09

gRPC connection termination issue

CVEs:CVE-2023-32732

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
Upstream advisory

CVE-2023-32732

Open SourcePoC exploitMEDIUM2023-06-09

gRPC connection termination issue

CVEs:CVE-2023-32732

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
Upstream advisory

CVE-2023-32732

Open SourcePoC exploitMEDIUM2023-06-09

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowe...

CVEs:CVE-2023-32732

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
grpc affected grpc
Upstream advisory

CVE-2023-32731

Open SourcePoC exploitCRITICAL2023-06-09

When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of HPACK tables between sender and receiver. If levera...

CVEs:CVE-2023-32731

Affected products

ProductStatusVendorPackageEcosystem
grpc affected grpc
Upstream advisory

CVE-2023-32731

Open SourcePoC exploitHIGH2023-06-09

Connection confusion in gRPC

CVEs:CVE-2023-32731

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
Upstream advisory

CVE-2023-32731

Open SourcePoC exploitCRITICAL2023-06-09

Connection confusion in gRPC

CVEs:CVE-2023-32731

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
Upstream advisory

DEBIAN-CVE-2023-29401

Open SourcePoC exploitCRITICAL2023-06-08

DEBIAN-CVE-2023-29401

Affected products

ProductStatusVendorPackageEcosystem
golang-github-gin-gonic-gin affected Debian:11 golang-github-gin-gonic-gin
golang-github-gin-gonic-gin affected Debian:12 golang-github-gin-gonic-gin
golang-github-gin-gonic-gin affected Debian:13 golang-github-gin-gonic-gin
golang-github-gin-gonic-gin affected Debian:14 golang-github-gin-gonic-gin
Upstream advisory

AZL-27112

Open SourcePoC exploitHIGH2023-06-08

CVE-2023-29403 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-27121

Open SourcePoC exploitHIGH2023-06-08

CVE-2023-29403 affecting package msft-golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37301

Open SourcePoC exploitHIGH2023-06-08

CVE-2023-29403 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37368

Open SourcePoC exploitHIGH2023-06-08

CVE-2023-29403 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-52789

Open SourcePoC exploitHIGH2023-06-08

CVE-2023-29403 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-79002

Open SourcePoC exploitHIGH2023-06-08

CVE-2023-29403 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-29403

Open SourcePoC exploitHIGH2023-06-08

DEBIAN-CVE-2023-29403

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GO-2023-1840

Open SourcePoC exploit2023-06-08

Unsafe behavior in setuid/setgid binaries in runtime

Affected products

ProductStatusVendorPackageEcosystem
kind affected chainguard kind
kind affected wolfi kind
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
policy-controller affected chainguard policy-controller
policy-controller affected wolfi policy-controller
stdlib affected Go stdlib
Upstream advisory

CVE-2023-29403

GooglePoC exploit2023-06-06

On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers.

CVEs:CVE-2023-29403

Upstream advisory

CVE-2023-29403

GooglePoC exploitHIGH2023-06-06

On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a set...

CVEs:CVE-2023-29403

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
Upstream advisory

CVE-2023-1428

Open SourcePoC exploitHIGH2023-06-09

gRPC Reachable Assertion issue

CVEs:CVE-2023-1428

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
Upstream advisory

CVE-2023-1428

Open SourcePoC exploitHIGH2023-06-09

There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementation to abort() when called via http2: te: x (x != trailers) :scheme: x (x != http, https) grpclb_client_stats: x (x == anythin...

CVEs:CVE-2023-1428

Affected products

ProductStatusVendorPackageEcosystem
grpc affected grpc
Upstream advisory

CVE-2023-1428

Open SourcePoC exploitHIGH2023-06-09

gRPC Reachable Assertion issue

CVEs:CVE-2023-1428

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
Upstream advisory

SUSE-SU-2023:2691-1

Open SourcePoC exploitCRITICAL2023-06-28

Security update for kubernetes1.23

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.23 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.23
kubernetes1.23 affected openSUSE:Leap 15.5 kubernetes1.23
Upstream advisory

GHSA-xc8m-28vv-4pjc

Open SourcePoC exploitCRITICAL2023-06-16

Kubelet vulnerable to bypass of seccomp profile enforcement

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-xc8m-28vv-4pjc

Open SourcePoC exploitCRITICAL2023-06-16

Kubelet vulnerable to bypass of seccomp profile enforcement

Affected products

ProductStatusVendorPackageEcosystem
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
Upstream advisory

DEBIAN-CVE-2023-2431

Open SourcePoC exploitCRITICAL2023-06-16

DEBIAN-CVE-2023-2431

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2023-2431

Open SourcePoC exploitMEDIUM2023-06-15

Kubelet vulnerable to bypass of seccomp profile enforcement

CVEs:CVE-2023-2431

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2023-2431

Open SourcePoC exploitCRITICAL2023-06-15

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability...

CVEs:CVE-2023-2431

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
kubernetes affected kubernetes
Upstream advisory

CVE-2023-2431

GooglePoC exploit2023-06-15

A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.

CVEs:CVE-2023-2431

Upstream advisory

GHSA-7g45-4rm6-3mm3

GooglePoC exploitMEDIUM2023-06-14

Guava vulnerable to insecure use of temporary directory

Affected products

ProductStatusVendorPackageEcosystem
com.google.guava:guava affected Maven com.google.guava:guava
Upstream advisory

GHSA-7g45-4rm6-3mm3

Open SourcePoC exploitMEDIUM2023-06-14

Guava vulnerable to insecure use of temporary directory

Affected products

ProductStatusVendorPackageEcosystem
cassandra-4.0 affected chainguard cassandra-4.0
cassandra-4.1 affected chainguard cassandra-4.1
cassandra-4.1 affected wolfi cassandra-4.1
cassandra-fips-4.0 affected chainguard cassandra-fips-4.0
cassandra-fips-4.1 affected chainguard cassandra-fips-4.1
cassandra-reaper affected wolfi cassandra-reaper
cassandra-reaper affected chainguard cassandra-reaper
cassandra-reaper-jre-bcfips affected chainguard cassandra-reaper-jre-bcfips
celeborn-0.5 affected wolfi celeborn-0.5
celeborn-0.5 affected chainguard celeborn-0.5
celeborn-0.6 affected wolfi celeborn-0.6
celeborn-0.6 affected chainguard celeborn-0.6
com.google.guava:guava affected Maven com.google.guava:guava
debezium-connector-spanner-3.0 affected wolfi debezium-connector-spanner-3.0
debezium-connector-spanner-3.0 affected chainguard debezium-connector-spanner-3.0
druid affected chainguard druid
druid affected wolfi druid
elasticsearch-7 affected chainguard elasticsearch-7
elasticsearch-7.17 affected chainguard elasticsearch-7.17
gradle-8 affected chainguard gradle-8
gradle-8 affected wolfi gradle-8
grpc-java-fips-1.56.0 affected chainguard grpc-java-fips-1.56.0
hadoop-client-modules affected chainguard hadoop-client-modules
hadoop-fips-3.3.6 affected chainguard hadoop-fips-3.3.6
keycloak affected wolfi keycloak
keycloak affected chainguard keycloak
keycloak-fips affected chainguard keycloak-fips
maven affected wolfi maven
maven affected chainguard maven
maven-stage0 affected chainguard maven-stage0
maven-stage0 affected wolfi maven-stage0
spark-fips-3.5 affected chainguard spark-fips-3.5
spdx-tools-java affected wolfi spdx-tools-java
spdx-tools-java affected chainguard spdx-tools-java
trino affected wolfi trino
trino affected chainguard trino
Upstream advisory

CVE-2023-2976

GooglePoC exploitMEDIUM2023-06-14

Guava vulnerable to insecure use of temporary directory

CVEs:CVE-2023-2976

Affected products

ProductStatusVendorPackageEcosystem
com.google.guava:guava affected Maven com.google.guava:guava
Upstream advisory

CVE-2023-2976

GooglePoC exploitHIGH2023-06-14

Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java tempo...

CVEs:CVE-2023-2976

Affected products

ProductStatusVendorPackageEcosystem
guava affected google
Upstream advisory

CVE-2023-2976

GooglePoC exploit2023-06-14

Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class. Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.

CVEs:CVE-2023-2976

Upstream advisory

CVE-2023-21173

Open SourcePoC exploitMEDIUM2023-06-13

In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User in...

CVEs:CVE-2023-21173

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DSA-5418-1

Open SourceCoalition ESS < 30%2023-06-03

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
Upstream advisory

GHSA-2jx2-qcm4-rf9h

Open SourceCoalition ESS < 30%HIGH2023-06-09

Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec

Affected products

ProductStatusVendorPackageEcosystem
grpc/grpc-swift affected github.com
grpc/grpc-swift affected github.com github.com/grpc/grpc-swift
Upstream advisory

GHSA-2jx2-qcm4-rf9h

Open SourceCoalition ESS < 30%HIGH2023-06-09

Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec

Affected products

ProductStatusVendorPackageEcosystem
grpc/grpc-swift affected github.com github.com/grpc/grpc-swift
Upstream advisory

GHSA-rxmj-hg9v-vp3p

Open SourceCoalition ESS < 30%CRITICAL2023-06-09

Uncontrolled Resource Consumption in LengthPrefixedMessageReader

Affected products

ProductStatusVendorPackageEcosystem
grpc/grpc-swift affected github.com github.com/grpc/grpc-swift
Upstream advisory

GHSA-rxmj-hg9v-vp3p

Open SourceCoalition ESS < 30%CRITICAL2023-06-09

Uncontrolled Resource Consumption in LengthPrefixedMessageReader

Affected products

ProductStatusVendorPackageEcosystem
grpc/grpc-swift affected github.com github.com/grpc/grpc-swift
Upstream advisory

CVE-2023-33143

Open SourceCoalition ESS < 30%CRITICAL2023-06-03

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2023-33143

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

ASB-A-278616909

GoogleCoalition ESS < 30%2023-06-01

ASB-A-278616909

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-r6ww-5963-7r95

Open SourceCoalition ESS < 30%CRITICAL2023-06-09

Denial of Service via reachable assertion

Affected products

ProductStatusVendorPackageEcosystem
grpc/grpc-swift affected github.com github.com/grpc/grpc-swift
Upstream advisory

GHSA-r6ww-5963-7r95

Open SourceCoalition ESS < 30%CRITICAL2023-06-09

Denial of Service via reachable assertion

Affected products

ProductStatusVendorPackageEcosystem
grpc/grpc-swift affected github.com github.com/grpc/grpc-swift
Upstream advisory

DEBIAN-CVE-2023-3421

Open SourceCoalition ESS < 30%CRITICAL2023-06-26

DEBIAN-CVE-2023-3421

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3421

GoogleCoalition ESS < 30%CRITICAL2023-06-26

Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3421

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2023-3216

Open SourceCoalition ESS < 30%HIGH2023-06-13

DEBIAN-CVE-2023-3216

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3216

GoogleCoalition ESS < 30%HIGH2023-06-13

Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3216

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-21144

Open SourceCoalition ESS < 30%HIGH2023-06-05

In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2023-21144

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2023-3422

Open SourceCoalition ESS < 30%CRITICAL2023-06-26

DEBIAN-CVE-2023-3422

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3422

GoogleCoalition ESS < 30%CRITICAL2023-06-26

Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3422

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2023-20965

Open SourceCoalition ESS < 30%CRITICAL2023-06-05

In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2023-20965

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-1943

GoogleCoalition ESS < 30%CRITICAL2023-06-21

Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.

CVEs:CVE-2023-1943

Affected products

ProductStatusVendorPackageEcosystem
operations affected kubernetes
Upstream advisory

CVE-2023-1943

Open SourceCoalition ESS < 30%HIGH2023-06-21

kOps privilege escalation vulnerability

CVEs:CVE-2023-1943

Affected products

ProductStatusVendorPackageEcosystem
kops affected k8s.io k8s.io/kops
Upstream advisory

CVE-2023-21130

Open SourceCoalition ESS < 30%CRITICAL2023-06-05

In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2023-21130

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21066

Open SourceCoalition ESS < 30%CRITICAL2023-06-13

In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2023-21066

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-250100597

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-250100597

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21186

Open SourceCoalition ESS < 30%HIGH2023-06-13

In LogResponse of Dns.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2023-21186

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21201

Open SourceCoalition ESS < 30%HIGH2023-06-13

In on_create_record_event of btif_sdp_server.cc, there is a possible out of bounds read due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2023-21201

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-261079188

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-261079188

Affected products

ProductStatusVendorPackageEcosystem
vendor/google/native affected platform platform/vendor/google/native
Upstream advisory

CVE-2023-21127

Open SourceCoalition ESS < 30%HIGH2023-06-05

In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: ...

CVEs:CVE-2023-21127

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21180

Open SourceCoalition ESS < 30%HIGH2023-06-13

In xmlParseTryOrFinish of parser.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2023-21180

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21224

Open SourceCoalition ESS < 30%HIGH2023-06-13

In ss_ProcessReturnResultComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2023-21224

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-265276966

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-265276966

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21193

Open SourceCoalition ESS < 30%HIGH2023-06-13

In VideoFrame of VideoFrame.h, there is a possible abort due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio...

CVEs:CVE-2023-21193

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21197

Open SourceCoalition ESS < 30%HIGH2023-06-13

In btm_acl_process_sca_cmpl_pkt of btm_acl.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-21197

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21223

Open SourceCoalition ESS < 30%HIGH2023-06-13

In LPP_ConvertGNSS_DataBitAssistance of LPP_CommonUtil.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2023-21223

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21226

Open SourceCoalition ESS < 30%HIGH2023-06-13

In SAEMM_RetrieveTaiList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2023-21226

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-240728187

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-240728187

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-256047000

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-256047000

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21513

Open SourceCoalition ESS < 30%MEDIUM2023-06-05

Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.

CVEs:CVE-2023-21513

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-35772

GoogleCoalition ESS < 30%CRITICAL2023-06-19

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alain Gonzalez Google Map Shortcode plugin <= 3.1.2 versions.

CVEs:CVE-2023-35772

Affected products

ProductStatusVendorPackageEcosystem
google_map_shortcode affected google_map_shortcode_project
Upstream advisory

CVE-2023-21219

Open SourceCoalition ESS < 30%HIGH2023-06-13

there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2023-21219

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21220

Open SourceCoalition ESS < 30%HIGH2023-06-13

there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2023-21220

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-264590585

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-264590585

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-264698379

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-264698379

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-0701

Open SourceCoalition ESS < 30%CRITICAL2023-06-05

In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution priv...

CVEs:CVE-2021-0701

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0945

Open SourceCoalition ESS < 30%CRITICAL2023-06-05

In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via PhysmemNewRamBackedPMR. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2021-0945

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-277775870

GoogleCoalition ESS < 30%2023-06-01

ASB-A-277775870

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-278156680

GoogleCoalition ESS < 30%2023-06-01

ASB-A-278156680

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-263783333

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-263783333

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21108

Open SourceCoalition ESS < 30%HIGH2023-06-05

In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User intera...

CVEs:CVE-2023-21108

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21512

Open SourceCoalition ESS < 30%LOW2023-06-05

Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.

CVEs:CVE-2023-21512

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-267242697

GoogleCoalition ESS < 30%2023-06-01

ASB-A-267242697

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21195

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In btm_ble_periodic_adv_sync_tx_rcvd of btm_ble_gap.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth, if the firmware were compromised with System execution priv...

CVEs:CVE-2023-21195

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21202

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In btm_delete_stored_link_key_complete of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over Bluetooth with System execution privileges needed. User interaction is n...

CVEs:CVE-2023-21202

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21137

Open SourceCoalition ESS < 30%MEDIUM2023-06-05

In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro...

CVEs:CVE-2023-21137

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21212

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2023-21212

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-250627197

GoogleCoalition ESS < 30%2023-06-01

ASB-A-250627197

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-271880369

GoogleCoalition ESS < 30%2023-06-01

ASB-A-271880369

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-276750663

GoogleCoalition ESS < 30%2023-06-01

ASB-A-276750663

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom/opensource/graphics-kernel affected platform platform/vendor/qcom/opensource/graphics-kernel
Upstream advisory

CVE-2023-21209

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2023-21209

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21136

Open SourceCoalition ESS < 30%MEDIUM2023-06-05

In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-21136

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21206

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In initiateVenueUrlAnqpQueryInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2023-21206

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21115

Open SourceCoalition ESS < 30%HIGH2023-06-05

In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2023-21115

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21122

Open SourceCoalition ESS < 30%HIGH2023-06-05

In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges...

CVEs:CVE-2023-21122

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21123

Open SourceCoalition ESS < 30%HIGH2023-06-05

In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileg...

CVEs:CVE-2023-21123

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21124

Open SourceCoalition ESS < 30%HIGH2023-06-05

In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2023-21124

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-261492548

GoogleCoalition ESS < 30%2023-06-01

PUB-A-261492548

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2023-21205

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2023-21205

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21105

Open SourceCoalition ESS < 30%MEDIUM2023-06-05

In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2023-21105

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21184

Open SourceCoalition ESS < 30%HIGH2023-06-13

In getCurrentPrivilegedPackagesForAllUsers of CarrierPrivilegesTracker.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User i...

CVEs:CVE-2023-21184

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21191

Open SourceCoalition ESS < 30%HIGH2023-06-13

In fixNotification of NotificationManagerService.java, there is a possible bypass of notification hide preference due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User in...

CVEs:CVE-2023-21191

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21147

Open SourceCoalition ESS < 30%HIGH2023-06-13

In lwis_i2c_device_disable of lwis_device_i2c.c, there is a possible UAF due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2023-21147

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21183

Open SourceCoalition ESS < 30%HIGH2023-06-13

In ForegroundUtils of ForegroundUtils.java, there is a possible way to read NFC tag data while the app is still in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges...

CVEs:CVE-2023-21183

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-269661912

GoogleCoalition ESS < 30%NONE2023-06-01

PUB-A-269661912

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21157

Open SourceCoalition ESS < 30%HIGH2023-06-13

In encode of wlandata.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Android...

CVEs:CVE-2023-21157

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21129

Open SourceCoalition ESS < 30%HIGH2023-06-05

In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while the app is in the background due to a BAL bypass. This could lead to local escalation of privilege with no additional execution pri...

CVEs:CVE-2023-21129

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-263783137

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-263783137

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21214

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In addGroupWithConfigInternal of p2p_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2023-21214

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20739

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559819; Issue ID: ALPS07559819.

CVEs:CVE-2023-20739

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20740

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559819; Issue ID: ALPS07559840.

CVEs:CVE-2023-20740

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

CVE-2023-21159

Open SourceCoalition ESS < 30%HIGH2023-06-13

In Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2023-21159

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21161

Open SourceCoalition ESS < 30%HIGH2023-06-13

In Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2023-21161

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21181

Open SourceCoalition ESS < 30%HIGH2023-06-13

In btm_ble_update_inq_result of btm_ble_gap.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2023-21181

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21182

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is n...

CVEs:CVE-2023-21182

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21188

Open SourceCoalition ESS < 30%HIGH2023-06-13

In btm_ble_update_inq_result of btm_ble_gap.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2023-21188

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21222

Open SourceCoalition ESS < 30%HIGH2023-06-13

In load_dt_data of storage.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2023-21222

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21236

Open SourceCoalition ESS < 30%HIGH2023-06-13

In aoc_service_set_read_blocked of aoc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2023-21236

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-252764175

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-252764175

Affected products

ProductStatusVendorPackageEcosystem
hardware/google/gchips affected platform platform/hardware/google/gchips
hardware/google/graphics/common affected platform platform/hardware/google/graphics/common
Upstream advisory

PUB-A-263783565

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-263783565

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-263783702

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-263783702

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-266977723

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-266977723

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-270148537

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-270148537

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21151

Open SourceCoalition ESS < 30%HIGH2023-06-13

In the Google BMS kernel module, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2023-21151

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21172

Open SourceCoalition ESS < 30%HIGH2023-06-13

In multiple functions of WifiCallingSettings.java, there is a possible way to change calling preferences for the admin user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. Us...

CVEs:CVE-2023-21172

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21174

Open SourceCoalition ESS < 30%HIGH2023-06-13

In isPageSearchEnabled of BillingCycleSettings.java, there is a possible way for the guest user to change data limits due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User int...

CVEs:CVE-2023-21174

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21199

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In btu_ble_proc_ltk_req of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21199

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21204

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2023-21204

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21213

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In initiateTdlsTeardownInternal of sta_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not ...

CVEs:CVE-2023-21213

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20744

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07519200.

CVEs:CVE-2023-20744

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

PUB-A-265149414

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-265149414

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21146

Open SourceCoalition ESS < 30%HIGH2023-06-13

there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid...

CVEs:CVE-2023-21146

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21153

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In Do_AIMS_SET_CALL_WAITING of imsservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2023-21153

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21158

Open SourceCoalition ESS < 30%HIGH2023-06-13

In encode of miscdata.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2023-21158

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21171

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In verifyInputEvent of InputDispatcher.cpp, there is a possible way to conduct click fraud due to side channel information disclosure. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee...

CVEs:CVE-2023-21171

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21192

Open SourceCoalition ESS < 30%HIGH2023-06-13

In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no additional execution ...

CVEs:CVE-2023-21192

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21203

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In startWpsPbcInternal of sta_iface.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2023-21203

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21207

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In initiateTdlsSetupInternal of sta_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2023-21207

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-239867994

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-239867994

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-263783635

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-263783635

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-264259730

GoogleCoalition ESS < 30%NONE2023-06-01

PUB-A-264259730

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20738

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ...

CVEs:CVE-2023-20738

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20732

Open SourceCoalition ESS < 30%MEDIUM2023-06-06

In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573480; Issue ID: A...

CVEs:CVE-2023-20732

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20734

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ...

CVEs:CVE-2023-20734

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20735

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ...

CVEs:CVE-2023-20735

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

CVE-2023-21148

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In BuildSetConfig of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2023-21148

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21150

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In handle_set_parameters_ctrl of hal_socket.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2023-21150

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21154

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In StoreAdbSerialNumber of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2023-21154

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21156

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In BuildGetRadioNode of protocolmiscbulider.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure from the modem with System execution privileges needed. User interaction is not ne...

CVEs:CVE-2023-21156

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21160

Open SourceCoalition ESS < 30%HIGH2023-06-13

In BuildSetTcsFci of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2023-21160

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21169

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In inviteInternal of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2023-21169

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21170

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In executeSetClientTarget of ComposerCommandEngine.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2023-21170

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21194

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In gatt_dbg_op_name of gatt_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed ...

CVEs:CVE-2023-21194

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21196

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In btm_ble_batchscan_filter_track_adv_vse_cback of btm_ble_batchscan.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges need...

CVEs:CVE-2023-21196

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21208

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In setCountryCodeInternal of sta_iface.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2023-21208

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21210

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In initiateHs20IconQueryInternal of sta_iface.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2023-21210

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21211

Open SourceCoalition ESS < 30%HIGH2023-06-13

In multiple files, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...

CVEs:CVE-2023-21211

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-263783657

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-263783657

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-263783910

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-263783910

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-263784118

GoogleCoalition ESS < 30%HIGH2023-06-01

PUB-A-263784118

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-264540759

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-264540759

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-267312009

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-267312009

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21176

Open SourceCoalition ESS < 30%HIGH2023-06-13

In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2023-21176

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21187

Open SourceCoalition ESS < 30%HIGH2023-06-13

In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2023-21187

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20751

Open SourceCoalition ESS < 30%HIGH2023-06-06

In keymange, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07825502; Issue...

CVEs:CVE-2023-20751

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20752

Open SourceCoalition ESS < 30%HIGH2023-06-06

In keymange, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07826586; Issue...

CVEs:CVE-2023-20752

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20742

Open SourceCoalition ESS < 30%MEDIUM2023-06-06

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628591; Issue ID: AL...

CVEs:CVE-2023-20742

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20741

Open SourceCoalition ESS < 30%MEDIUM2023-06-06

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628591; Issue ID: AL...

CVEs:CVE-2023-20741

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20728

Open SourceCoalition ESS < 30%MEDIUM2023-06-06

In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573603; Issue ID: A...

CVEs:CVE-2023-20728

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20729

Open SourceCoalition ESS < 30%MEDIUM2023-06-06

In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573552; Issue ID: A...

CVEs:CVE-2023-20729

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20730

Open SourceCoalition ESS < 30%MEDIUM2023-06-06

In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573552; Issue ID: A...

CVEs:CVE-2023-20730

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20731

Open SourceCoalition ESS < 30%MEDIUM2023-06-06

In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573495; Issue ID: A...

CVEs:CVE-2023-20731

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20715

Open SourceCoalition ESS < 30%HIGH2023-06-06

In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07796900; Issue ID:...

CVEs:CVE-2023-20715

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20716

Open SourceCoalition ESS < 30%HIGH2023-06-06

In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07796883; Issue ID:...

CVEs:CVE-2023-20716

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20725

Open SourceCoalition ESS < 30%HIGH2023-06-06

In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07734004 / ALP...

CVEs:CVE-2023-20725

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
Upstream advisory

CVE-2023-20712

Open SourceCoalition ESS < 30%HIGH2023-06-06

In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07796914; Issue ID:...

CVEs:CVE-2023-20712

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20727

Open SourceCoalition ESS < 30%MEDIUM2023-06-06

In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588531; Issue ID: A...

CVEs:CVE-2023-20727

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-21135

Open SourceCoalition ESS < 30%HIGH2023-06-05

In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2023-21135

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21152

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In FaceStatsAnalyzer::InterpolateWeightList of face_stats_analyzer.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not ...

CVEs:CVE-2023-21152

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21155

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In BuildSetRadioNode of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2023-21155

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21168

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In convertCbYCrY of ColorConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2023-21168

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21198

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In remove_sdp_record of btif_sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2023-21198

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21200

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2023-21200

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20749

Open SourceCoalition ESS < 30%HIGH2023-06-06

In swpm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID:...

CVEs:CVE-2023-20749

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-264540700

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-264540700

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-269174022

GoogleCoalition ESS < 30%MEDIUM2023-06-01

PUB-A-269174022

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21225

Open SourceCoalition ESS < 30%HIGH2023-06-13

there is a possible way to bypass the protected confirmation screen due to Failure to lock display power. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Produ...

CVEs:CVE-2023-21225

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20747

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue ID: ALPS07519121.

CVEs:CVE-2023-20747

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

PUB-A-270403821

GoogleCoalition ESS < 30%NONE2023-06-01

PUB-A-270403821

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21167

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In setProfileName of DevicePolicyManagerService.java, there is a possible way to crash the SystemUI menu due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2023-21167

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20723

Open SourceCoalition ESS < 30%MEDIUM2023-06-06

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07843845; Issue...

CVEs:CVE-2023-20723

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20724

Open SourceCoalition ESS < 30%MEDIUM2023-06-06

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07843845; Issue...

CVEs:CVE-2023-20724

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21128

Open SourceCoalition ESS < 30%HIGH2023-06-05

In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...

CVEs:CVE-2023-21128

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21131

Open SourceCoalition ESS < 30%HIGH2023-06-05

In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of Parcel Mismatch mitigations due to a logic error in the code. This could lead to local escalation of privilege and the ability to launch arbitrary activi...

CVEs:CVE-2023-21131

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21175

Open SourceCoalition ESS < 30%HIGH2023-06-13

In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2023-21175

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21149

Open SourceCoalition ESS < 30%HIGH2023-06-13

In registerGsmaServiceIntentReceiver of ShannonRcsService.java, there is a possible way to activate/deactivate RCS service due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges neede...

CVEs:CVE-2023-21149

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21185

Open SourceCoalition ESS < 30%HIGH2023-06-13

In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2023-21185

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-270050709

GoogleCoalition ESS < 30%NONE2023-06-01

PUB-A-270050709

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21177

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges ...

CVEs:CVE-2023-21177

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21189

Open SourceCoalition ESS < 30%HIGH2023-06-13

In startLockTaskMode of LockTaskController.java, there is a possible bypass of lock task mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed ...

CVEs:CVE-2023-21189

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21126

Open SourceCoalition ESS < 30%HIGH2023-06-05

In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User int...

CVEs:CVE-2023-21126

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48438

Open SourceCoalition ESS < 30%CRITICAL2023-06-05

In cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2022-48438

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21143

Open SourceCoalition ESS < 30%MEDIUM2023-06-05

In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2023-21143

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-278801630

GoogleCoalition ESS < 30%2023-06-01

ASB-A-278801630

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-48390

Open SourceCoalition ESS < 30%HIGH2023-06-05

In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVEs:CVE-2022-48390

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48392

Open SourceCoalition ESS < 30%HIGH2023-06-05

In dialer service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVEs:CVE-2022-48392

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-278775987

GoogleCoalition ESS < 30%2023-06-01

ASB-A-278775987

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-278775990

GoogleCoalition ESS < 30%2023-06-01

ASB-A-278775990

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-278796976

GoogleCoalition ESS < 30%2023-06-01

ASB-A-278796976

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-48391

Open SourceCoalition ESS < 30%HIGH2023-06-05

In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVEs:CVE-2022-48391

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48446

Open SourceCoalition ESS < 30%HIGH2023-06-05

In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVEs:CVE-2022-48446

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48447

Open SourceCoalition ESS < 30%HIGH2023-06-05

In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVEs:CVE-2022-48447

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21121

Open SourceCoalition ESS < 30%HIGH2023-06-05

In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges ne...

CVEs:CVE-2023-21121

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21138

Open SourceCoalition ESS < 30%HIGH2023-06-05

In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User...

CVEs:CVE-2023-21138

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21139

Open SourceCoalition ESS < 30%HIGH2023-06-05

In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2023-21139

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21141

Open SourceCoalition ESS < 30%MEDIUM2023-06-05

In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2023-21141

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21142

Open SourceCoalition ESS < 30%MEDIUM2023-06-05

In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2023-21142

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48448

Open SourceCoalition ESS < 30%HIGH2023-06-05

In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVEs:CVE-2022-48448

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21179

Open SourceCoalition ESS < 30%HIGH2023-06-13

In parseSecurityParamsFromXml of XmlUtil.java, there is a possible bypass of user specified wifi encryption protocol due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User in...

CVEs:CVE-2023-21179

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21190

Open SourceCoalition ESS < 30%HIGH2023-06-13

In btm_acl_encrypt_change of btm_acl.cc, there is a possible way for a remote device to turn off encryption without resulting in a terminated connection due to an unusual root cause. This could lead to local information disclosure with no additional ex...

CVEs:CVE-2023-21190

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20743

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07...

CVEs:CVE-2023-20743

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20745

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07...

CVEs:CVE-2023-20745

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20746

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07...

CVEs:CVE-2023-20746

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20737

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645167.

CVEs:CVE-2023-20737

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20733

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645149.

CVEs:CVE-2023-20733

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

CVE-2022-48440

Open SourceCoalition ESS < 30%HIGH2023-06-05

In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVEs:CVE-2022-48440

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21120

Open SourceCoalition ESS < 30%HIGH2023-06-05

In multiple functions of cdm_engine.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2023-21120

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-258188673

GoogleCoalition ESS < 30%HIGH2023-06-01

ASB-A-258188673

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-20736

Open SourceCoalition ESS < 30%HIGH2023-06-06

In vcu, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07...

CVEs:CVE-2023-20736

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot-yocto affected linuxfoundation
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20750

Open SourceCoalition ESS < 30%HIGH2023-06-06

In swpm, there is a possible out of bounds write due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID: ALPS07...

CVEs:CVE-2023-20750

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21101

Open SourceCoalition ESS < 30%HIGH2023-06-05

In multiple functions of WVDrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2023-21101

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-258189255

GoogleCoalition ESS < 30%HIGH2023-06-01

ASB-A-258189255

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21095

Open SourceCoalition ESS < 30%MEDIUM2023-06-05

In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...

CVEs:CVE-2023-21095

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21178

Open SourceCoalition ESS < 30%MEDIUM2023-06-13

In installKey of KeyUtil.cpp, there is a possible failure of file encryption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2023-21178

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-29345

Open SourceEPSS <= 49%MEDIUM2023-06-04

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVEs:CVE-2023-29345

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-2326

GoogleEPSS <= 49%MEDIUM2023-06-27

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change t...

CVEs:CVE-2023-2326

Affected products

ProductStatusVendorPackageEcosystem
gravity_forms_google_sheets_connector affected gsheetconnector
Upstream advisory

CVE-2023-2526

GoogleEPSS <= 49%MEDIUM2023-06-09

The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.7. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated ...

CVEs:CVE-2023-2526

Affected products

ProductStatusVendorPackageEcosystem
easy_google_maps affected supsystic
Upstream advisory

CVE-2023-23802

GoogleEPSS <= 49%HIGH2023-06-15

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions.

CVEs:CVE-2023-23802

Affected products

ProductStatusVendorPackageEcosystem
ht_easy_ga4_\(google_analytics_4\) affected hasthemes
Upstream advisory

CVE-2023-30864

Open SourceEPSS <= 49%HIGH2023-06-05

In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVEs:CVE-2023-30864

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30865

Open SourceEPSS <= 49%HIGH2023-06-05

In dialer service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30865

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30915

Open SourceEPSS <= 49%HIGH2023-06-05

In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30915

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

SUSE-SU-2023:2664-1

Open SourceAll remaining2023-06-27

Security update for kubernetes1.24

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.24 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.24
kubernetes1.24 affected openSUSE:Leap 15.5 kubernetes1.24
Upstream advisory

SUSE-SU-2023:2654-1

Open SourceAll remaining2023-06-27

Security update for kubernetes1.24

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.24 affected SUSE:Linux Enterprise Module for Containers 15 SP4 kubernetes1.24
kubernetes1.24 affected openSUSE:Leap 15.4 kubernetes1.24
Upstream advisory

SUSE-SU-2023:2297-2

Open SourceAll remaining2023-06-23

Security update for golang-github-vpenso-prometheus_slurm_exporter

Affected products

ProductStatusVendorPackageEcosystem
golang-github-vpenso-prometheus_slurm_exporter affected SUSE:Linux Enterprise Module for Package Hub 15 SP5 golang-github-vpenso-prometheus_slurm_exporter
golang-github-vpenso-prometheus_slurm_exporter affected openSUSE:Leap 15.5 golang-github-vpenso-prometheus_slurm_exporter
Upstream advisory

SUSE-SU-2023:2617-1

Open SourceAll remaining2023-06-23

Security update for google-cloud-sap-agent

Affected products

ProductStatusVendorPackageEcosystem
google-cloud-sap-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 google-cloud-sap-agent
google-cloud-sap-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 google-cloud-sap-agent
google-cloud-sap-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 google-cloud-sap-agent
google-cloud-sap-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 google-cloud-sap-agent
google-cloud-sap-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP5 google-cloud-sap-agent
google-cloud-sap-agent affected openSUSE:Leap 15.5 google-cloud-sap-agent
Upstream advisory

SUSE-SU-2023:2445-1

Open SourceAll remaining2023-06-07

Security update for google-cloud-sap-agent

Affected products

ProductStatusVendorPackageEcosystem
google-cloud-sap-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 google-cloud-sap-agent
google-cloud-sap-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 google-cloud-sap-agent
google-cloud-sap-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 google-cloud-sap-agent
google-cloud-sap-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 google-cloud-sap-agent
google-cloud-sap-agent affected SUSE:Linux Enterprise Module for Public Cloud 15 SP5 google-cloud-sap-agent
google-cloud-sap-agent affected openSUSE:Leap 15.5 google-cloud-sap-agent
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.