Google Security Advisories · July 2023 — Google Security Advisories
540 advisories 301 CVEs 37 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2023-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 37 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2023-36884

GoogleExploitedCISA KEV listedCRITICAL2023-07-11

Windows Search Remote Code Execution Vulnerability

CVEs:CVE-2023-36884

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

CVE-2023-37580

GoogleExploitedCISA KEV listedCRITICAL2023-07-17

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

CVEs:CVE-2023-37580

Affected products

ProductStatusVendorPackageEcosystem
zimbra_collaboration_suite affected synacor
Upstream advisory

CVE-2023-36874

GoogleExploitedCISA KEV listedCRITICAL2023-07-11

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVEs:CVE-2023-36874

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

CVE-2023-41993

Project ZeroExploitedCISA KEV listed2023-07-18

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVEs:CVE-2023-41993

Upstream advisory

CVE-2023-41993

GoogleExploitedCISA KEV listed2023-07-18

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVEs:CVE-2023-41993

Upstream advisory

CVE-2023-41993

GoogleExploitedCISA KEV listedCRITICAL2023-07-18

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS befor...

CVEs:CVE-2023-41993

Affected products

ProductStatusVendorPackageEcosystem
active_iq_unified_manager affected netapp
cloud_insights_acquisition_unit affected netapp
cloud_insights_storage_workload_security_agent affected netapp
debian_linux affected debian
fedora affected fedoraproject
graalvm affected oracle
ipados affected apple
iphone_os affected apple
jdk affected oracle
jre affected oracle
macos affected apple
oncommand_insight affected netapp
oncommand_workflow_automation affected netapp
webkitgtk\+ affected webkitgtk
Upstream advisory

CVE-2023-37450

GoogleExploitedCISA KEV listed2023-07-10

The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2023-37450

Upstream advisory

CVE-2023-37450

Project ZeroExploitedCISA KEV listed2023-07-10

The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2023-37450

Upstream advisory

CVE-2023-37450

GoogleExploitedCISA KEV listedCRITICAL2023-07-10

The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this ...

CVEs:CVE-2023-37450

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
webkitgtk\+ affected webkitgtk
Upstream advisory

CVE-2023-42916

Project ZeroExploitedCISA KEV listed2023-07-18

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

CVEs:CVE-2023-42916

Upstream advisory

CVE-2023-42916

GoogleExploitedCISA KEV listedHIGH2023-07-18

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this...

CVEs:CVE-2023-42916

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
fedora affected fedoraproject
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
webkitgtk\+ affected webkitgtk
Upstream advisory

CVE-2024-23222

GoogleExploitedCISA KEV listed2023-07-18

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.

CVEs:CVE-2024-23222

Upstream advisory

CVE-2024-23222

GoogleExploitedCISA KEV listedCRITICAL2023-07-18

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17...

CVEs:CVE-2024-23222

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2024-23222

Project ZeroExploitedCISA KEV listed2023-07-18

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.

CVEs:CVE-2024-23222

Upstream advisory

CVE-2023-32046

GoogleExploitedCISA KEV listedCRITICAL2023-07-11

Windows MSHTML Platform Elevation of Privilege Vulnerability

CVEs:CVE-2023-32046

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

ASB-A-278113033

Open SourceExploitedCISA KEV listedHIGH2023-07-01

ASB-A-278113033

Affected products

ProductStatusVendorPackageEcosystem
external/skia affected platform platform/external/skia
Upstream advisory

ASB-A-283489460

GoogleExploitedCISA KEV listed2023-07-01

ASB-A-283489460

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-38606

GoogleExploitedCISA KEV listedMEDIUM2023-07-24

This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modif...

CVEs:CVE-2023-38606

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-38606

Project ZeroExploitedCISA KEV listed2023-07-24

This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.

CVEs:CVE-2023-38606

Upstream advisory

CVE-2023-41990

Project ZeroExploitedCISA KEV listed2023-07-24

The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.

CVEs:CVE-2023-41990

Upstream advisory

CVE-2023-41990

GoogleExploitedCISA KEV listedCRITICAL2023-07-24

The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may...

CVEs:CVE-2023-41990

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

ASB-A-272073598

GoogleExploitedCISA KEV listed2023-07-01

ASB-A-272073598

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-2rx4-9f5h-9gjf

Open SourceActive exploitation (sightings)CRITICAL2023-07-06

Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-cncf-kubernetes affected PyPI apache-airflow-providers-cncf-kubernetes
apache-airflow-providers-cncf-kubernetes affected PyPI apache-airflow-providers-cncf-kubernetes
Upstream advisory

GHSA-2rx4-9f5h-9gjf

Open SourceActive exploitation (sightings)CRITICAL2023-07-06

Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow-providers-cncf-kubernetes affected PyPI apache-airflow-providers-cncf-kubernetes
Upstream advisory

ASB-A-226921651

GoogleActive exploitation (sightings)2023-07-01

ASB-A-226921651

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21250

Open SourceActive exploitation (sightings)CRITICAL2023-07-05

In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21250

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2021-4321

Open SourceActive exploitation (sightings)MEDIUM2023-07-29

DEBIAN-CVE-2021-4321

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4321

GoogleActive exploitation (sightings)MEDIUM2023-07-28

Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2021-4321

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-35691

Open SourceActive exploitation (sightings)HIGH2023-07-05

there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35691

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-273851762

GoogleActive exploitation (sightings)MEDIUM2023-07-01

PUB-A-273851762

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-3344

GoogleActive exploitation (sightings)CRITICAL2023-07-24

The Auto Location for WP Job Manager via Google WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_...

CVEs:CVE-2023-3344

Affected products

ProductStatusVendorPackageEcosystem
auto_location_for_wp_job_manager_via_google affected auto_location_for_wp_job_manager_via_google_project
Upstream advisory

CVE-2023-35694

Open SourceActive exploitation (sightings)HIGH2023-07-05

In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2023-35694

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-267619655

GoogleActive exploitation (sightings)MEDIUM2023-07-01

PUB-A-267619655

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-30641

Open SourceActive exploitation (sightings)MEDIUM2023-07-05

Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.

CVEs:CVE-2023-30641

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21251

Open SourceActive exploitation (sightings)HIGH2023-07-05

In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed f...

CVEs:CVE-2023-21251

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30644

Open SourceActive exploitation (sightings)CRITICAL2023-07-05

Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVEs:CVE-2023-30644

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30645

Open SourceActive exploitation (sightings)CRITICAL2023-07-05

Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVEs:CVE-2023-30645

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30651

Open SourceActive exploitation (sightings)HIGH2023-07-05

Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

CVEs:CVE-2023-30651

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30652

Open SourceActive exploitation (sightings)HIGH2023-07-05

Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

CVEs:CVE-2023-30652

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30669

Open SourceActive exploitation (sightings)HIGH2023-07-05

Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-30669

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30670

Open SourceActive exploitation (sightings)HIGH2023-07-05

Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-30670

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-274005916

GoogleActive exploitation (sightings)2023-07-01

ASB-A-274005916

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-30659

Open SourceActive exploitation (sightings)HIGH2023-07-05

Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2023-30659

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30658

Open SourceActive exploitation (sightings)HIGH2023-07-05

Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2023-30658

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21238

Open SourceActive exploitation (sightings)MEDIUM2023-07-05

In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21238

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21246

Open SourceActive exploitation (sightings)LOW2023-07-05

In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2023-21246

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30663

Open SourceActive exploitation (sightings)HIGH2023-07-05

Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.

CVEs:CVE-2023-30663

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30666

Open SourceActive exploitation (sightings)HIGH2023-07-05

Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.

CVEs:CVE-2023-30666

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30660

Open SourceActive exploitation (sightings)MEDIUM2023-07-05

Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVEs:CVE-2023-30660

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30662

Open SourceActive exploitation (sightings)MEDIUM2023-07-05

Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVEs:CVE-2023-30662

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30665

Open SourceActive exploitation (sightings)MEDIUM2023-07-05

Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.

CVEs:CVE-2023-30665

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30667

Open SourceActive exploitation (sightings)MEDIUM2023-07-05

Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.

CVEs:CVE-2023-30667

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21262

Open SourceActive exploitation (sightings)LOW2023-07-05

In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitation.

CVEs:CVE-2023-21262

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30640

Open SourceActive exploitation (sightings)MEDIUM2023-07-05

Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.

CVEs:CVE-2023-30640

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30642

Open SourceActive exploitation (sightings)MEDIUM2023-07-05

Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.

CVEs:CVE-2023-30642

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-20755

Open SourceActive exploitation (sightings)HIGH2023-07-04

In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ...

CVEs:CVE-2023-20755

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-280374982

GoogleActive exploitation (sightings)2023-07-01

ASB-A-280374982

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-35693

Open SourceActive exploitation (sightings)HIGH2023-07-05

In incfs_kill_sb of fs/incfs/vfs.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35693

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-274172774

GoogleActive exploitation (sightings)HIGH2023-07-01

PUB-A-274172774

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-276750306

GoogleActive exploitation (sightings)2023-07-01

ASB-A-276750306

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-276750584

GoogleActive exploitation (sightings)2023-07-01

ASB-A-276750584

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom-opensource/wlan/platform affected platform platform/vendor/qcom-opensource/wlan/platform
Upstream advisory

ASB-A-276750639

GoogleActive exploitation (sightings)2023-07-01

ASB-A-276750639

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom-opensource/wlan/platform affected platform platform/vendor/qcom-opensource/wlan/platform
Upstream advisory

CVE-2023-33905

Open SourceActive exploitation (sightings)CRITICAL2023-07-12

In iwnpi server, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2023-33905

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21243

Open SourceActive exploitation (sightings)HIGH2023-07-05

In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed....

CVEs:CVE-2023-21243

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21256

Open SourceActive exploitation (sightings)HIGH2023-07-05

In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...

CVEs:CVE-2023-21256

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20754

Open SourceActive exploitation (sightings)HIGH2023-07-04

In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issue ...

CVEs:CVE-2023-20754

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-280380543

GoogleActive exploitation (sightings)2023-07-01

ASB-A-280380543

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-33893

Open SourceActive exploitation (sightings)HIGH2023-07-12

In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33893

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33892

Open SourceActive exploitation (sightings)HIGH2023-07-12

In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33892

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33891

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33891

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33890

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33890

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33889

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33889

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33888

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33888

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33885

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33885

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33886

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33886

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33884

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33884

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33883

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33883

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33900

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33900

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33899

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33899

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21241

Open SourceActive exploitation (sightings)HIGH2023-07-05

In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21241

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33880

Open SourceActive exploitation (sightings)HIGH2023-07-12

In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33880

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33879

Open SourceActive exploitation (sightings)HIGH2023-07-12

In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33879

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21254

Open SourceActive exploitation (sightings)HIGH2023-07-05

In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution ...

CVEs:CVE-2023-21254

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21247

Open SourceActive exploitation (sightings)HIGH2023-07-05

In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execu...

CVEs:CVE-2023-21247

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21248

Open SourceActive exploitation (sightings)HIGH2023-07-05

In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution ...

CVEs:CVE-2023-21248

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21145

Open SourceActive exploitation (sightings)HIGH2023-07-05

In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User i...

CVEs:CVE-2023-21145

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21240

Open SourceActive exploitation (sightings)HIGH2023-07-05

In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21240

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21239

Open SourceActive exploitation (sightings)MEDIUM2023-07-05

In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2023-21239

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21257

Open SourceActive exploitation (sightings)HIGH2023-07-05

In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed....

CVEs:CVE-2023-21257

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21249

Open SourceActive exploitation (sightings)MEDIUM2023-07-05

In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not n...

CVEs:CVE-2023-21249

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2021-0948

Open SourceActive exploitation (sightings)HIGH2023-07-05

The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space. The contents of this memory could contain sensitive information.

CVEs:CVE-2021-0948

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-281905774

GoogleActive exploitation (sightings)HIGH2023-07-01

ASB-A-281905774

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-30929

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVEs:CVE-2023-30929

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30928

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVEs:CVE-2023-30928

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30917

Open SourceActive exploitation (sightings)HIGH2023-07-12

In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVEs:CVE-2023-30917

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33881

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33881

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32788

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-32788

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30942

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30942

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30940

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30940

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30938

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30938

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30937

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30937

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30935

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30935

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30932

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30932

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30926

Open SourceActive exploitation (sightings)HIGH2023-07-12

In opm service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30926

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30927

Open SourceActive exploitation (sightings)HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30927

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30922

Open SourceActive exploitation (sightings)HIGH2023-07-12

In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30922

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30921

Open SourceActive exploitation (sightings)HIGH2023-07-12

In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30921

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35692

Open SourceActive exploitation (sightings)HIGH2023-07-05

In getLocationCache of GeoLocation.java, there is a possible way to send a mock location during an emergency call due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User in...

CVEs:CVE-2023-35692

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-275950631

GoogleActive exploitation (sightings)NONE2023-07-01

PUB-A-275950631

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21399

Open SourceActive exploitation (sightings)HIGH2023-07-05

there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21399

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-275462898

GoogleActive exploitation (sightings)NONE2023-07-01

PUB-A-275462898

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CLSA-2023-1689885970

Open SourcePoC exploit2023-07-20

Fix CVE(s): CVE-2023-24329

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

CLSA-2023-1689885838

Open SourcePoC exploit2023-07-20

Fix CVE(s): CVE-2023-24329

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

CLSA-2023-1689701064

Open SourcePoC exploitHIGH2023-07-20

Fix CVE(s): CVE-2021-3737

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:18.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:18.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:18.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:18.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:18.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:18.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:18.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:18.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:18.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:18.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:18.04 python2.7-minimal
Upstream advisory

SUSE-SU-2023:2783-1

Open SourcePoC exploitCRITICAL2023-07-04

Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets

Affected products

ProductStatusVendorPackageEcosystem
azure-cli-core affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 azure-cli-core
azure-cli-core affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 azure-cli-core
azure-cli-core affected openSUSE:Leap 15.4 azure-cli-core
azure-cli-core affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 azure-cli-core
azure-cli-core affected SUSE:Linux Enterprise Module for Public Cloud 15 SP5 azure-cli-core
azure-cli-core affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 azure-cli-core
grpc affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 grpc
protobuf affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS protobuf
protobuf affected SUSE:Linux Enterprise Installer Updates 15 SP1 protobuf
protobuf affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 protobuf
protobuf affected SUSE:Linux Enterprise Server 15 SP1-LTSS protobuf
protobuf affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 protobuf
python-aiocontextvars affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-aiocontextvars
python-aiocontextvars affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-aiocontextvars
python-aiocontextvars affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-aiocontextvars
python-aiocontextvars affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-aiocontextvars
python-Automat affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS python-Automat
python-Automat affected SUSE:Manager Proxy 4.2 python-Automat
python-Automat affected SUSE:Manager Server 4.2 python-Automat
python-Automat affected SUSE:Linux Enterprise Real Time 15 SP3 python-Automat
python-Automat affected SUSE:Enterprise Storage 7 python-Automat
python-Automat affected SUSE:Linux Enterprise Server 15 SP1-LTSS python-Automat
python-Automat affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS python-Automat
python-Automat affected SUSE:Linux Enterprise Server 15 SP2-LTSS python-Automat
python-Automat affected SUSE:Linux Enterprise Server 15 SP3-LTSS python-Automat
python-Automat affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS python-Automat
python-Automat affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 python-Automat
python-Automat affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 python-Automat
python-Automat affected SUSE:Enterprise Storage 7.1 python-Automat
python-Automat affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 python-Automat
python-avro affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-avro
python-avro affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-avro
python-avro affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-avro
python-avro affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-avro
python-constantly affected SUSE:Linux Enterprise Real Time 15 SP3 python-constantly
python-constantly affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS python-constantly
python-constantly affected openSUSE:Leap 15.4 python-constantly
python-constantly affected SUSE:Enterprise Storage 7.1 python-constantly
python-constantly affected SUSE:Enterprise Storage 7 python-constantly
python-constantly affected SUSE:Manager Server 4.2 python-constantly
python-constantly affected SUSE:Manager Proxy 4.2 python-constantly
python-constantly affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 python-constantly
python-constantly affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 python-constantly
python-constantly affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 python-constantly
python-constantly affected SUSE:Linux Enterprise Server 15 SP3-LTSS python-constantly
python-constantly affected SUSE:Linux Enterprise Module for Server Applications 15 SP4 python-constantly
python-constantly affected SUSE:Linux Enterprise Server 15 SP2-LTSS python-constantly
python-constantly affected SUSE:Linux Enterprise Module for Server Applications 15 SP5 python-constantly
python-constantly affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS python-constantly
python-constantly affected SUSE:Linux Enterprise Server 15 SP1-LTSS python-constantly
python-constantly affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS python-constantly
python-cryptography affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 python-cryptography
python-cryptography affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-cryptography
python-cryptography affected SUSE:Linux Enterprise Server 15 SP1-LTSS python-cryptography
python-cryptography affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS python-cryptography
python-cryptography-vectors affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-cryptography-vectors
python-cryptography-vectors affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-cryptography-vectors
python-Deprecated affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-Deprecated
python-Deprecated affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-Deprecated
python-Deprecated affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-Deprecated
python-Deprecated affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-Deprecated
python-google-api-core affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-google-api-core
python-googleapis-common-protos affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-googleapis-common-protos
python-grpcio-gcp affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-grpcio-gcp
python-humanfriendly affected SUSE:Linux Enterprise Module for Package Hub 15 SP5 python-humanfriendly
python-humanfriendly affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-humanfriendly
python-humanfriendly affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-humanfriendly
python-humanfriendly affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-humanfriendly
python-humanfriendly affected SUSE:Linux Enterprise Module for Public Cloud 15 SP5 python-humanfriendly
python-humanfriendly affected openSUSE:Leap 15.4 python-humanfriendly
python-humanfriendly affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-humanfriendly
python-hyperlink affected SUSE:Enterprise Storage 7.1 python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 python-hyperlink
python-hyperlink affected openSUSE:Leap 15.4 python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise Server 15 SP3-LTSS python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise Server 15 SP2-LTSS python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise Module for Server Applications 15 SP4 python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise Module for Server Applications 15 SP5 python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise Server 15 SP1-LTSS python-hyperlink
python-hyperlink affected SUSE:Manager Server 4.2 python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS python-hyperlink
python-hyperlink affected SUSE:Enterprise Storage 7 python-hyperlink
python-hyperlink affected SUSE:Manager Proxy 4.2 python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 python-hyperlink
python-hyperlink affected SUSE:Linux Enterprise Real Time 15 SP3 python-hyperlink
python-incremental affected SUSE:Enterprise Storage 7.1 python-incremental
python-incremental affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS python-incremental
python-incremental affected SUSE:Manager Server 4.2 python-incremental
python-incremental affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS python-incremental
python-incremental affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS python-incremental
python-incremental affected SUSE:Enterprise Storage 7 python-incremental
python-incremental affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 python-incremental
python-incremental affected SUSE:Manager Proxy 4.2 python-incremental
python-incremental affected SUSE:Linux Enterprise Server 15 SP2-LTSS python-incremental
python-incremental affected SUSE:Linux Enterprise Real Time 15 SP3 python-incremental
python-incremental affected SUSE:Linux Enterprise Server 15 SP3-LTSS python-incremental
python-incremental affected SUSE:Linux Enterprise Server 15 SP1-LTSS python-incremental
python-incremental affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 python-incremental
python-incremental affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 python-incremental
python-jsondiff affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-jsondiff
python-jsondiff affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-jsondiff
python-jsondiff affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-jsondiff
python-jsondiff affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-jsondiff
python-jsondiff affected SUSE:Linux Enterprise Module for Public Cloud 15 SP5 python-jsondiff
python-jsondiff affected openSUSE:Leap 15.4 python-jsondiff
python-knack affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-knack
python-knack affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-knack
python-knack affected SUSE:Linux Enterprise Module for Public Cloud 15 SP5 python-knack
python-knack affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-knack
python-knack affected openSUSE:Leap 15.4 python-knack
python-knack affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-knack
python-opencensus affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-opencensus
python-opencensus affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-opencensus
python-opencensus affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-opencensus
python-opencensus affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-opencensus
python-opencensus-context affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-opencensus-context
python-opencensus-context affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-opencensus-context
python-opencensus-context affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-opencensus-context
python-opencensus-context affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-opencensus-context
python-opencensus-ext-threading affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-opencensus-ext-threading
python-opencensus-ext-threading affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-opencensus-ext-threading
python-opencensus-ext-threading affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-opencensus-ext-threading
python-opencensus-ext-threading affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-opencensus-ext-threading
python-opentelemetry-api affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-opentelemetry-api
python-opentelemetry-api affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-opentelemetry-api
python-opentelemetry-api affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-opentelemetry-api
python-opentelemetry-api affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-opentelemetry-api
python-psutil affected SUSE:Linux Enterprise Server 15 SP1-LTSS python-psutil
python-psutil affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-psutil
python-psutil affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 python-psutil
python-psutil affected SUSE:Enterprise Storage 7 python-psutil
python-psutil affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 python-psutil
python-psutil affected SUSE:Linux Enterprise Server 15 SP2-LTSS python-psutil
python-psutil affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS python-psutil
python-psutil affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS python-psutil
python-PyGithub affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-PyGithub
python-PyGithub affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-PyGithub
python-PyGithub affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-PyGithub
python-PyGithub affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-PyGithub
python-pytest affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-pytest
python-pytest affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-pytest
python-pytest-asyncio affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-pytest-asyncio
python-pytest-asyncio affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-pytest-asyncio
python-requests affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-requests
python-requests affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS python-requests
python-requests affected SUSE:Enterprise Storage 7 python-requests
python-requests affected SUSE:Linux Enterprise Server 15 SP2-LTSS python-requests
python-requests affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS python-requests
python-requests affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 python-requests
python-requests affected SUSE:Linux Enterprise Server 15 SP1-LTSS python-requests
python-requests affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 python-requests
python-Twisted affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 python-Twisted
python-Twisted affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-Twisted
python-Twisted affected SUSE:Linux Enterprise Server 15 SP1-LTSS python-Twisted
python-websocket-client affected SUSE:Manager Proxy 4.2 python-websocket-client
python-websocket-client affected SUSE:Manager Server 4.2 python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Server 15 SP3-LTSS python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Real Time 15 SP3 python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Module for Basesystem 15 SP4 python-websocket-client
python-websocket-client affected SUSE:Enterprise Storage 7.1 python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Server 15 SP2-LTSS python-websocket-client
python-websocket-client affected openSUSE:Leap 15.4 python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Server 15 SP1-LTSS python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Module for Basesystem 15 SP5 python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-websocket-client
python-websocket-client affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 python-websocket-client
python-websocket-client affected SUSE:Enterprise Storage 7 python-websocket-client
python-websockets affected SUSE:Linux Enterprise Module for Public Cloud 15 SP2 python-websockets
python-websockets affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 python-websockets
python-websockets affected SUSE:Linux Enterprise Module for Public Cloud 15 SP3 python-websockets
python-websockets affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-websockets
python-zope.interface affected SUSE:Manager Server 4.2 python-zope.interface
python-zope.interface affected SUSE:Manager Proxy 4.2 python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 python-zope.interface
python-zope.interface affected SUSE:Enterprise Storage 7 python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise Module for Public Cloud 15 SP1 python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise Server 15 SP3-LTSS python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise Server 15 SP2-LTSS python-zope.interface
python-zope.interface affected SUSE:Enterprise Storage 7.1 python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise Module for Server Applications 15 SP4 python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise Module for Server Applications 15 SP5 python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise Server 15 SP1-LTSS python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise Real Time 15 SP3 python-zope.interface
python-zope.interface affected openSUSE:Leap 15.4 python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS python-zope.interface
python-zope.interface affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS python-zope.interface
Upstream advisory

CLSA-2023-1689259392

Open SourcePoC exploit2023-07-13

Fix CVE(s): CVE-2021-28861

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.6 affected TuxCare:Ubuntu:18.04 idle-python3.6
libpython3.6 affected TuxCare:Ubuntu:18.04 libpython3.6
libpython3.6-dev affected TuxCare:Ubuntu:18.04 libpython3.6-dev
libpython3.6-minimal affected TuxCare:Ubuntu:18.04 libpython3.6-minimal
libpython3.6-stdlib affected TuxCare:Ubuntu:18.04 libpython3.6-stdlib
libpython3.6-testsuite affected TuxCare:Ubuntu:18.04 libpython3.6-testsuite
python3.6 affected TuxCare:Ubuntu:18.04 python3.6
python3.6-dev affected TuxCare:Ubuntu:18.04 python3.6-dev
python3.6-doc affected TuxCare:Ubuntu:18.04 python3.6-doc
python3.6-examples affected TuxCare:Ubuntu:18.04 python3.6-examples
python3.6-minimal affected TuxCare:Ubuntu:18.04 python3.6-minimal
python3.6-venv affected TuxCare:Ubuntu:18.04 python3.6-venv
Upstream advisory

OESA-2023-1413

Open SourcePoC exploitHIGH2023-07-08

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:20.03-LTS-SP3 kubernetes
Upstream advisory

OESA-2023-1414

Open SourcePoC exploitHIGH2023-07-08

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:22.03-LTS kubernetes
Upstream advisory

OESA-2023-1415

Open SourcePoC exploitHIGH2023-07-08

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:22.03-LTS-SP1 kubernetes
Upstream advisory

OESA-2023-1416

Open SourcePoC exploitHIGH2023-07-08

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:22.03-LTS-SP2 kubernetes
Upstream advisory

GHSA-cgcv-5272-97pr

Open SourcePoC exploitCRITICAL2023-07-03

Kubernetes mountable secrets policy bypass

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-cgcv-5272-97pr

Open SourcePoC exploitCRITICAL2023-07-03

Kubernetes mountable secrets policy bypass

Affected products

ProductStatusVendorPackageEcosystem
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
Upstream advisory

DEBIAN-CVE-2023-2728

Open SourcePoC exploitCRITICAL2023-07-03

DEBIAN-CVE-2023-2728

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

RLSA-2023:3923

Open SourcePoC exploitCRITICAL2023-07-08

Critical: go-toolset and golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Rocky Linux:9 golang
go-toolset affected Rocky Linux:9 go-toolset
Upstream advisory

MGASA-2023-0227

Open SourcePoC exploitCRITICAL2023-07-07

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

OESA-2023-1386

Open SourcePoC exploitCRITICAL2023-07-01

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP3 golang
golang affected openEuler:22.03-LTS golang
Upstream advisory

DLA-3479-1

Open SourcePoC exploit2023-07-05

golang-yaml.v2 - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-yaml.v2 affected Debian:10 golang-yaml.v2
Upstream advisory

GHSA-h755-8qp9-cq85

Open SourcePoC exploitCRITICAL2023-07-05

protobufjs Prototype Pollution vulnerability

Affected products

ProductStatusVendorPackageEcosystem
kibana-8 affected chainguard kibana-8
protobufjs affected npm protobufjs
Upstream advisory

GHSA-h755-8qp9-cq85

Open SourcePoC exploitCRITICAL2023-07-05

protobufjs Prototype Pollution vulnerability

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected npm protobufjs
Upstream advisory

CVE-2023-36665

Open SourcePoC exploitCRITICAL2023-07-05

protobufjs Prototype Pollution vulnerability

CVEs:CVE-2023-36665

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected npm protobufjs
Upstream advisory

CVE-2023-36665

Open SourcePoC exploitCRITICAL2023-07-05

"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by addin...

CVEs:CVE-2023-36665

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected protobufjs_project
Upstream advisory

CVE-2023-36665

Open SourcePoC exploitCRITICAL2023-07-05

protobufjs Prototype Pollution vulnerability

CVEs:CVE-2023-36665

Affected products

ProductStatusVendorPackageEcosystem
protobufjs affected npm protobufjs
Upstream advisory

AZL-27410

Open SourcePoC exploitMEDIUM2023-07-11

CVE-2023-29406 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-28831

Open SourcePoC exploitMEDIUM2023-07-11

CVE-2023-29406 affecting package msft-golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37418

Open SourcePoC exploitMEDIUM2023-07-11

CVE-2023-29406 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37420

Open SourcePoC exploitMEDIUM2023-07-11

CVE-2023-29406 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-52711

Open SourcePoC exploitMEDIUM2023-07-11

CVE-2023-29406 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-79070

Open SourcePoC exploitMEDIUM2023-07-11

CVE-2023-29406 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-29406

Open SourcePoC exploitMEDIUM2023-07-11

DEBIAN-CVE-2023-29406

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2023-29406

GooglePoC exploitMEDIUM2023-07-11

The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host o...

CVEs:CVE-2023-29406

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2023-29406

GooglePoC exploit2023-07-11

The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.

CVEs:CVE-2023-29406

Upstream advisory

GO-2023-1878

Open SourcePoC exploit2023-07-11

Insufficient sanitization of Host header in net/http

Affected products

ProductStatusVendorPackageEcosystem
go-1.20 affected chainguard go-1.20
go-1.20 affected wolfi go-1.20
kind affected chainguard kind
kind affected wolfi kind
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

GHSA-w33c-445m-f8w7

Open SourcePoC exploitCRITICAL2023-07-12

Okio Signed to Unsigned Conversion Error vulnerability

Affected products

ProductStatusVendorPackageEcosystem
com.squareup.okio:okio affected Maven com.squareup.okio:okio
com.squareup.okio:okio-jvm affected Maven com.squareup.okio:okio-jvm
docker-selenium-jre-bcfips affected chainguard docker-selenium-jre-bcfips
druid affected chainguard druid
druid affected wolfi druid
grpc-java-fips-1.56.0 affected chainguard grpc-java-fips-1.56.0
knative-kafka-broker-1.17 affected chainguard knative-kafka-broker-1.17
s3proxy affected chainguard s3proxy
s3proxy-fips affected chainguard s3proxy-fips
thingsboard affected chainguard thingsboard
thingsboard affected wolfi thingsboard
trino affected chainguard trino
trino affected wolfi trino
wavefront-proxy affected chainguard wavefront-proxy
wavefront-proxy affected wolfi wavefront-proxy
Upstream advisory

GHSA-w33c-445m-f8w7

GooglePoC exploitCRITICAL2023-07-12

Okio Signed to Unsigned Conversion Error vulnerability

Affected products

ProductStatusVendorPackageEcosystem
com.squareup.okio:okio affected Maven com.squareup.okio:okio
com.squareup.okio:okio-jvm affected Maven com.squareup.okio:okio-jvm
Upstream advisory

GHSA-qc2g-gmh6-95p4

Open SourcePoC exploitMEDIUM2023-07-03

kube-apiserver vulnerable to policy bypass

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

GHSA-qc2g-gmh6-95p4

Open SourcePoC exploitMEDIUM2023-07-03

kube-apiserver vulnerable to policy bypass

Affected products

ProductStatusVendorPackageEcosystem
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
calico affected chainguard calico
calico affected wolfi calico
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
Upstream advisory

DEBIAN-CVE-2023-2727

Open SourcePoC exploitMEDIUM2023-07-03

DEBIAN-CVE-2023-2727

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

DSA-5456-1

Open SourcePoC exploit2023-07-20

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-37788

Open SourcePoC exploitHIGH2023-07-18

DEBIAN-CVE-2023-37788

Affected products

ProductStatusVendorPackageEcosystem
golang-github-elazarl-goproxy affected Debian:12 golang-github-elazarl-goproxy
golang-github-elazarl-goproxy affected Debian:11 golang-github-elazarl-goproxy
golang-github-elazarl-goproxy affected Debian:13 golang-github-elazarl-goproxy
golang-github-elazarl-goproxy affected Debian:14 golang-github-elazarl-goproxy
Upstream advisory

ASB-A-253167854

GooglePoC exploitHIGH2023-07-01

ASB-A-253167854

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

GHSA-9hxf-ppjv-w6rq

Open SourcePoC exploitMEDIUM2023-07-06

gRPC connection termination issue

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
grpcio affected PyPI grpcio
hive affected chainguard hive
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
stargate affected chainguard stargate
wavefront-proxy affected chainguard wavefront-proxy
wavefront-proxy affected wolfi wavefront-proxy
Upstream advisory

GHSA-9hxf-ppjv-w6rq

Open SourcePoC exploitMEDIUM2023-07-06

gRPC connection termination issue

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
Upstream advisory

GHSA-cfgp-2977-2fmm

Open SourcePoC exploitCRITICAL2023-07-05

Connection confusion in gRPC

Affected products

ProductStatusVendorPackageEcosystem
calico affected wolfi calico
calico affected chainguard calico
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
grpcio affected PyPI grpcio
hive affected chainguard hive
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
stargate affected chainguard stargate
wavefront-proxy affected wolfi wavefront-proxy
wavefront-proxy affected chainguard wavefront-proxy
Upstream advisory

GHSA-cfgp-2977-2fmm

Open SourcePoC exploitCRITICAL2023-07-05

Connection confusion in gRPC

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
Upstream advisory

OESA-2023-1404

Open SourcePoC exploit2023-07-08

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS-SP2 golang
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP3 golang
golang affected openEuler:22.03-LTS golang
golang affected openEuler:22.03-LTS-SP1 golang
Upstream advisory

GHSA-6628-q6j9-w8vg

Open SourcePoC exploitHIGH2023-07-06

gRPC Reachable Assertion issue

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
Upstream advisory

GHSA-6628-q6j9-w8vg

Open SourcePoC exploitHIGH2023-07-06

gRPC Reachable Assertion issue

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
grpcio affected PyPI grpcio
hive affected chainguard hive
io.grpc:grpc-protobuf affected Maven io.grpc:grpc-protobuf
stargate affected chainguard stargate
wavefront-proxy affected wolfi wavefront-proxy
wavefront-proxy affected chainguard wavefront-proxy
Upstream advisory

CVE-2023-21400

GooglePoC exploit2023-07-05

In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21400

Upstream advisory

CVE-2023-21400

Open SourcePoC exploitHIGH2023-07-05

In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2023-21400

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

PUB-A-264663832

GooglePoC exploitHIGH2023-07-01

PUB-A-264663832

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-33902

Open SourcePoC exploitHIGH2023-07-12

In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33902

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20768

Open SourcePoC exploitMEDIUM2023-07-04

In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07559...

CVEs:CVE-2023-20768

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-4906

GoogleCoalition ESS < 30%HIGH2023-07-29

Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4906

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4906

Open SourceCoalition ESS < 30%HIGH2023-07-29

DEBIAN-CVE-2022-4906

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2023-1260

GoogleCoalition ESS < 30%HIGH2023-07-11

kube-apiserver authentication bypass vulnerability

CVEs:CVE-2023-1260

Affected products

ProductStatusVendorPackageEcosystem
openshift/apiserver-library-go affected github.com github.com/openshift/apiserver-library-go
Upstream advisory

CVE-2023-1260

Open SourceCoalition ESS < 30%HIGH2023-07-11

An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They ...

CVEs:CVE-2023-1260

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver affected kubernetes
openshift_container_platform affected redhat
Upstream advisory

CVE-2023-36887

Open SourceCoalition ESS < 30%CRITICAL2023-07-11

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2023-36887

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-4907

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4907

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-4907

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2022-4907

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
ffmpeg affected Debian:12 ffmpeg
ffmpeg affected Debian:13 ffmpeg
ffmpeg affected Debian:14 ffmpeg
Upstream advisory

openSUSE-SU-2023:0193-1

Open SourceCoalition ESS < 30%CRITICAL2023-07-26

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

CVE-2023-35392

Open SourceCoalition ESS < 30%MEDIUM2023-07-11

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2023-35392

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-38187

Open SourceCoalition ESS < 30%CRITICAL2023-07-11

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2023-38187

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-4920

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4920

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4920

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2022-4920

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4908

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4908

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4908

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2022-4908

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3730

GoogleCoalition ESS < 30%CRITICAL2023-07-18

Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3730

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4912

GoogleCoalition ESS < 30%HIGH2023-07-29

Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4912

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4912

Open SourceCoalition ESS < 30%HIGH2023-07-29

DEBIAN-CVE-2022-4912

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4319

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Use after free in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2021-4319

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2021-4319

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2021-4319

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4318

GoogleCoalition ESS < 30%HIGH2023-07-29

Object corruption in Blink in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2021-4318

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2021-4318

Open SourceCoalition ESS < 30%HIGH2023-07-29

DEBIAN-CVE-2021-4318

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2022-4916

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Use after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4916

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4918

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4918

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4919

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4919

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4916

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2022-4916

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4918

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2022-4918

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4919

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2022-4919

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3598

GoogleCoalition ESS < 30%2023-07-28

Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3598

Upstream advisory

CVE-2023-3598

GoogleCoalition ESS < 30%HIGH2023-07-28

Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3598

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-3598

Open SourceCoalition ESS < 30%HIGH2023-07-28

DEBIAN-CVE-2023-3598

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2022-4921

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2022-4921

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4924

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4924

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4921

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2022-4921

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4924

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2022-4924

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2021-4317

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2021-4317

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-4320

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2021-4320

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2021-4317

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2021-4317

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2021-4320

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2021-4320

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4324

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to read arbitrary files via a malicious file. (Chromium security severity: Medium)

CVEs:CVE-2021-4324

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-38173

Open SourceCoalition ESS < 30%MEDIUM2023-07-11

Microsoft Edge for Android Spoofing Vulnerability

CVEs:CVE-2023-38173

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-3734

GoogleCoalition ESS < 30%MEDIUM2023-07-18

Inappropriate implementation in Picture In Picture in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-3734

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4911

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2022-4911

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4911

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2022-4911

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4913

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to spoof extension storage via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4913

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4915

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4915

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4913

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2022-4913

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4915

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2022-4915

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3733

GoogleCoalition ESS < 30%MEDIUM2023-07-18

Inappropriate implementation in WebApp Installs in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-3733

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4922

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4922

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4922

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2022-4922

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4926

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4926

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-4926

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2022-4926

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4925

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via malicious network traffic. (Chromium security severity: Low)

CVEs:CVE-2022-4925

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4925

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2022-4925

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3737

GoogleCoalition ESS < 30%MEDIUM2023-07-18

Inappropriate implementation in Notifications in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to spoof the contents of media notifications via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-3737

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-36888

Open SourceCoalition ESS < 30%MEDIUM2023-07-11

Microsoft Edge for Android (Chromium-based) Tampering Vulnerability

CVEs:CVE-2023-36888

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2022-4914

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4914

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4914

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2022-4914

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3740

GoogleCoalition ESS < 30%MEDIUM2023-07-18

Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content to a user via a crafted background URL. (Chromium security severity: Low)

CVEs:CVE-2023-3740

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-4322

GoogleCoalition ESS < 30%CRITICAL2023-07-29

Use after free in DevTools in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium)

CVEs:CVE-2021-4322

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2021-4322

Open SourceCoalition ESS < 30%CRITICAL2023-07-29

DEBIAN-CVE-2021-4322

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3738

GoogleCoalition ESS < 30%MEDIUM2023-07-18

Inappropriate implementation in Autofill in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-3738

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2021-4316

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2021-4316

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2021-4316

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2021-4316

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2021-4323

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to access local files via a crafted Chrome Extension. (Chromium security severity:...

CVEs:CVE-2021-4323

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2021-4323

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2021-4323

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4910

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4910

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4910

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2022-4910

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-20689

Open SourceCoalition ESS < 30%HIGH2023-07-04

In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664741; Issue ID: ...

CVEs:CVE-2023-20689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20690

Open SourceCoalition ESS < 30%HIGH2023-07-04

In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664735; Issue ID: ...

CVEs:CVE-2023-20690

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20691

Open SourceCoalition ESS < 30%HIGH2023-07-04

In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664731; Issue ID: ...

CVEs:CVE-2023-20691

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20692

Open SourceCoalition ESS < 30%HIGH2023-07-04

In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664720; Issue ID...

CVEs:CVE-2023-20692

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20693

Open SourceCoalition ESS < 30%HIGH2023-07-04

In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664711; Issue ID...

CVEs:CVE-2023-20693

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2022-4909

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially perform an ASLR bypass via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2022-4909

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4909

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2022-4909

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4917

GoogleCoalition ESS < 30%MEDIUM2023-07-29

Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2022-4917

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2022-4917

Open SourceCoalition ESS < 30%MEDIUM2023-07-29

DEBIAN-CVE-2022-4917

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4923

GoogleCoalition ESS < 30%LOW2023-07-29

Inappropriate implementation in Omnibox in Google Chrome prior to 99.0.4844.51 allowed an attacker in a privileged network position to perform a man-in-the-middle attack via malicious network traffic. (Chromium security severity: Low)

CVEs:CVE-2022-4923

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4923

Open SourceCoalition ESS < 30%LOW2023-07-29

DEBIAN-CVE-2022-4923

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-8934

GoogleCoalition ESS < 30%MEDIUM2023-07-07

The Site Kit by Google plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 1.8.0 This is due to the lack of capability checks on the admin_enqueue_scripts action which displays the connection key. Th...

CVEs:CVE-2020-8934

Affected products

ProductStatusVendorPackageEcosystem
site_kit affected google
Upstream advisory

CVE-2023-21255

Open SourceCoalition ESS < 30%HIGH2023-07-05

In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21255

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

CVE-2023-21255

GoogleCoalition ESS < 30%2023-07-05

In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21255

Upstream advisory

ASB-A-275041864

GoogleCoalition ESS < 30%HIGH2023-07-01

ASB-A-275041864

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2023-3497

GoogleCoalition ESS < 30%MEDIUM2023-07-03

Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of service via physical access to the device. (Chromium security severity: Medium)

CVEs:CVE-2023-3497

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-33882

Open SourceCoalition ESS < 30%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33882

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20760

Open SourceCoalition ESS < 30%HIGH2023-07-04

In apu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629578; Issue ID: ...

CVEs:CVE-2023-20760

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20761

Open SourceCoalition ESS < 30%HIGH2023-07-04

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628604; Issue ID: ...

CVEs:CVE-2023-20761

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20766

Open SourceCoalition ESS < 30%HIGH2023-07-04

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573237; Issue ID: ...

CVEs:CVE-2023-20766

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20767

Open SourceCoalition ESS < 30%HIGH2023-07-04

In pqframework, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629585; Is...

CVEs:CVE-2023-20767

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20774

Open SourceCoalition ESS < 30%MEDIUM2023-07-04

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292228; Issue I...

CVEs:CVE-2023-20774

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20775

Open SourceCoalition ESS < 30%HIGH2023-07-04

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07978760; Issue ...

CVEs:CVE-2023-20775

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
Upstream advisory

CVE-2023-33904

Open SourceCoalition ESS < 30%HIGH2023-07-12

In hci_server, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2023-33904

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33903

Open SourceCoalition ESS < 30%HIGH2023-07-12

In FM service, there is a possible missing params check. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2023-33903

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20757

Open SourceCoalition ESS < 30%HIGH2023-07-04

In cmdq, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07636133; Issue ID:...

CVEs:CVE-2023-20757

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20772

Open SourceCoalition ESS < 30%MEDIUM2023-07-04

In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441...

CVEs:CVE-2023-20772

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33897

Open SourceCoalition ESS < 30%CRITICAL2023-07-12

In libimpl-ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2023-33897

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33896

Open SourceCoalition ESS < 30%CRITICAL2023-07-12

In libimpl-ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2023-33896

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20773

Open SourceCoalition ESS < 30%HIGH2023-07-04

In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07611...

CVEs:CVE-2023-20773

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20758

Open SourceCoalition ESS < 30%HIGH2023-07-04

In cmdq, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07636133; Issue ID: ALPS076...

CVEs:CVE-2023-20758

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20759

Open SourceCoalition ESS < 30%HIGH2023-07-04

In cmdq, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07636133; Issue ID: ALPS076...

CVEs:CVE-2023-20759

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33895

Open SourceCoalition ESS < 30%HIGH2023-07-12

In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33895

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33894

Open SourceCoalition ESS < 30%HIGH2023-07-12

In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33894

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33887

Open SourceCoalition ESS < 30%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33887

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20753

Open SourceCoalition ESS < 30%HIGH2023-07-04

In rpmb, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07460390; Issue ID: ALPS0758...

CVEs:CVE-2023-20753

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21245

Open SourceCoalition ESS < 30%HIGH2023-07-05

In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead to local escalation of privilege with no additional e...

CVEs:CVE-2023-21245

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20748

Open SourceCoalition ESS < 30%MEDIUM2023-07-04

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07536951; Issue ID...

CVEs:CVE-2023-20748

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20756

Open SourceCoalition ESS < 30%HIGH2023-07-04

In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ...

CVEs:CVE-2023-20756

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48450

Open SourceCoalition ESS < 30%HIGH2023-07-12

In bluetooth service, there is a possible missing params check. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2022-48450

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33901

Open SourceCoalition ESS < 30%HIGH2023-07-12

In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-33901

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32789

Open SourceCoalition ESS < 30%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-32789

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20771

Open SourceCoalition ESS < 30%HIGH2023-07-04

In display, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07671046; Issue ID: ALPS...

CVEs:CVE-2023-20771

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21260

Open SourceCoalition ESS < 30%MEDIUM2023-07-13

In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation.

CVEs:CVE-2023-21260

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48451

Open SourceCoalition ESS < 30%CRITICAL2023-07-12

In bluetooth service, there is a possible out of bounds write due to race condition. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2022-48451

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-3732

GoogleEPSS <= 49%HIGH2023-07-18

Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3732

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

ASB-A-268589017

GoogleEPSS <= 49%HIGH2023-07-01

ASB-A-268589017

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2023-2333

GoogleEPSS <= 49%CRITICAL2023-07-04

The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting whic...

CVEs:CVE-2023-2333

Affected products

ProductStatusVendorPackageEcosystem
ninja_forms_google_sheet_connector affected gsheetconnector
Upstream advisory

CVE-2023-3728

GoogleEPSS <= 49%CRITICAL2023-07-18

Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3728

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-3728

GoogleEPSS <= 49%2023-07-18

Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3728

Upstream advisory

CVE-2023-3727

GoogleEPSS <= 49%CRITICAL2023-07-18

Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-3727

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-2313

GoogleEPSS <= 49%HIGH2023-07-29

Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High)

CVEs:CVE-2023-2313

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-2313

Open SourceEPSS <= 49%HIGH2023-07-29

DEBIAN-CVE-2023-2313

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3736

GoogleEPSS <= 49%2023-07-18

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 115.0.5790.98 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-3736

Upstream advisory

CVE-2023-3736

GoogleEPSS <= 49%MEDIUM2023-07-18

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 115.0.5790.98 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-3736

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-2311

GoogleEPSS <= 49%CRITICAL2023-07-29

Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-2311

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-2311

Open SourceEPSS <= 49%CRITICAL2023-07-29

DEBIAN-CVE-2023-2311

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3735

GoogleEPSS <= 49%MEDIUM2023-07-18

Inappropriate implementation in Web API Permission Prompts in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-3735

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-2320

GoogleEPSS <= 49%CRITICAL2023-07-04

The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could...

CVEs:CVE-2023-2320

Affected products

ProductStatusVendorPackageEcosystem
cf7_google_sheets_connector affected gsheetconnector
Upstream advisory

CVE-2023-2321

GoogleEPSS <= 49%CRITICAL2023-07-04

The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could ...

CVEs:CVE-2023-2321

Affected products

ProductStatusVendorPackageEcosystem
wpforms_google_sheet_connector affected gsheetconnector
Upstream advisory

CVE-2023-2324

GoogleEPSS <= 49%CRITICAL2023-07-04

The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site ...

CVEs:CVE-2023-2324

Affected products

ProductStatusVendorPackageEcosystem
elementor_forms_google_sheet_connector affected gsheetconnector
Upstream advisory

CVE-2023-2329

GoogleEPSS <= 49%HIGH2023-07-17

The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVEs:CVE-2023-2329

Affected products

ProductStatusVendorPackageEcosystem
woocommerce_google_sheet_connector affected gsheetconnector
Upstream advisory

CVE-2023-2330

GoogleEPSS <= 49%HIGH2023-07-17

The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVEs:CVE-2023-2330

Affected products

ProductStatusVendorPackageEcosystem
caldera_forms_google_sheets_connector affected gsheetconnector
Upstream advisory

DEBIAN-CVE-2023-2314

Open SourceEPSS <= 49%MEDIUM2023-07-29

DEBIAN-CVE-2023-2314

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-23869

GoogleEPSS <= 49%HIGH2023-07-10

Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions.

CVEs:CVE-2023-23869

Affected products

ProductStatusVendorPackageEcosystem
google_xml_sitemap_for_mobile affected digitalinspiration
Upstream advisory

CVE-2023-30646

Open SourceEPSS <= 49%CRITICAL2023-07-05

Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVEs:CVE-2023-30646

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30647

Open SourceEPSS <= 49%CRITICAL2023-07-05

Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVEs:CVE-2023-30647

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30649

Open SourceEPSS <= 49%CRITICAL2023-07-05

Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVEs:CVE-2023-30649

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30650

Open SourceEPSS <= 49%HIGH2023-07-05

Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

CVEs:CVE-2023-30650

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30653

Open SourceEPSS <= 49%HIGH2023-07-05

Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

CVEs:CVE-2023-30653

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30668

Open SourceEPSS <= 49%HIGH2023-07-05

Out-of-bounds Write in BuildOemSecureSimLockResponse of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-30668

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30656

Open SourceEPSS <= 49%HIGH2023-07-05

Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.

CVEs:CVE-2023-30656

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30657

Open SourceEPSS <= 49%HIGH2023-07-05

Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2023-30657

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30655

Open SourceEPSS <= 49%HIGH2023-07-05

Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2023-30655

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30664

Open SourceEPSS <= 49%HIGH2023-07-05

Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2023-30664

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30661

Open SourceEPSS <= 49%MEDIUM2023-07-05

Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVEs:CVE-2023-30661

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30648

Open SourceEPSS <= 49%CRITICAL2023-07-05

Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.

CVEs:CVE-2023-30648

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30671

Open SourceEPSS <= 49%MEDIUM2023-07-05

Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.

CVEs:CVE-2023-30671

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30643

Open SourceEPSS <= 49%HIGH2023-07-05

Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications.

CVEs:CVE-2023-30643

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-276751076

GoogleEPSS <= 49%2023-07-01

ASB-A-276751076

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom-opensource/wlan/platform affected platform platform/vendor/qcom-opensource/wlan/platform
Upstream advisory

CVE-2023-2626

GoogleEPSS <= 49%HIGH2023-07-25

There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypas...

CVEs:CVE-2023-2626

Affected products

ProductStatusVendorPackageEcosystem
nest_hub_firmware affected google
nest_hub_max_firmware affected google
nest_wifi_6e_firmware affected google
nest_wifi_point_firmware affected google
wifi_firmware affected google
Upstream advisory

CVE-2023-30916

Open SourceEPSS <= 49%HIGH2023-07-12

In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVEs:CVE-2023-30916

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30913

Open SourceEPSS <= 49%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30913

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30941

Open SourceEPSS <= 49%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30941

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30939

Open SourceEPSS <= 49%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30939

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30934

Open SourceEPSS <= 49%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30934

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30933

Open SourceEPSS <= 49%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30933

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30931

Open SourceEPSS <= 49%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30931

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30930

Open SourceEPSS <= 49%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30930

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30925

Open SourceEPSS <= 49%HIGH2023-07-12

In opm service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30925

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30924

Open SourceEPSS <= 49%HIGH2023-07-12

In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30924

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30923

Open SourceEPSS <= 49%HIGH2023-07-12

In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30923

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30920

Open SourceEPSS <= 49%HIGH2023-07-12

In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30920

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30919

Open SourceEPSS <= 49%HIGH2023-07-12

In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30919

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30918

Open SourceEPSS <= 49%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30918

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30936

Open SourceEPSS <= 49%HIGH2023-07-12

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVEs:CVE-2023-30936

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

SUSE-SU-2023:2773-1

Open SourceAll remaining2023-07-04

Security update for kubernetes1.18

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.18 affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS kubernetes1.18
kubernetes1.18 affected openSUSE:Leap 15.4 kubernetes1.18
kubernetes1.18 affected openSUSE:Leap 15.5 kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Module for Containers 15 SP4 kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server 15 SP2-LTSS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server 15 SP3-LTSS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kubernetes1.18
kubernetes1.18 affected SUSE:Enterprise Storage 7 kubernetes1.18
kubernetes1.18 affected SUSE:Enterprise Storage 7.1 kubernetes1.18
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.