CVE-2023-36884
CVEs:CVE-2023-36884
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 37 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2023-36884
Windows Search Remote Code Execution Vulnerability
CVEs:CVE-2023-36884
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_21h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
Windows Search Remote Code Execution Vulnerability
CVEs:CVE-2023-36884
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
CVEs:CVE-2023-37580
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
CVEs:CVE-2023-37580
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| zimbra_collaboration_suite | affected | synacor | — | — |
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
CVEs:CVE-2023-37580
CVEs:CVE-2023-37580
CVEs:CVE-2023-36874
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVEs:CVE-2023-36874
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_21h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVEs:CVE-2023-36874
CVEs:CVE-2023-41993
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
CVEs:CVE-2023-41993
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
CVEs:CVE-2023-41993
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS befor...
CVEs:CVE-2023-41993
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| active_iq_unified_manager | affected | netapp | — | — |
| cloud_insights_acquisition_unit | affected | netapp | — | — |
| cloud_insights_storage_workload_security_agent | affected | netapp | — | — |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| graalvm | affected | oracle | — | — |
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| jdk | affected | oracle | — | — |
| jre | affected | oracle | — | — |
| macos | affected | apple | — | — |
| oncommand_insight | affected | netapp | — | — |
| oncommand_workflow_automation | affected | netapp | — | — |
| webkitgtk\+ | affected | webkitgtk | — | — |
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2023-37450
CVEs:CVE-2023-37450
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2023-37450
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this ...
CVEs:CVE-2023-37450
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| safari | affected | apple | — | — |
| tvos | affected | apple | — | — |
| watchos | affected | apple | — | — |
| webkitgtk\+ | affected | webkitgtk | — | — |
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
CVEs:CVE-2023-42916
CVEs:CVE-2023-42916
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this...
CVEs:CVE-2023-42916
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| safari | affected | apple | — | — |
| webkitgtk\+ | affected | webkitgtk | — | — |
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
CVEs:CVE-2024-23222
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17...
CVEs:CVE-2024-23222
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| safari | affected | apple | — | — |
| tvos | affected | apple | — | — |
| visionos | affected | apple | — | — |
CVEs:CVE-2024-23222
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
CVEs:CVE-2024-23222
CVEs:CVE-2023-32046
Windows MSHTML Platform Elevation of Privilege Vulnerability
CVEs:CVE-2023-32046
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_21h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
Windows MSHTML Platform Elevation of Privilege Vulnerability
CVEs:CVE-2023-32046
ASB-A-278113033
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| external/skia | affected | platform | platform/external/skia | — |
ASB-A-283489460
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modif...
CVEs:CVE-2023-38606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| tvos | affected | apple | — | — |
| watchos | affected | apple | — | — |
CVEs:CVE-2023-38606
This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.
CVEs:CVE-2023-38606
The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.
CVEs:CVE-2023-41990
The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may...
CVEs:CVE-2023-41990
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| tvos | affected | apple | — | — |
| watchos | affected | apple | — | — |
CVEs:CVE-2023-41990
ASB-A-272073598
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-cncf-kubernetes | affected | PyPI | apache-airflow-providers-cncf-kubernetes | — |
| apache-airflow-providers-cncf-kubernetes | affected | PyPI | apache-airflow-providers-cncf-kubernetes | — |
Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apache-airflow-providers-cncf-kubernetes | affected | PyPI | apache-airflow-providers-cncf-kubernetes | — |
ASB-A-226921651
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-21250
In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21250
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-4321
DEBIAN-CVE-2021-4321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2021-4321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-35691
there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35691
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-273851762
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-3344
The Auto Location for WP Job Manager via Google WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_...
CVEs:CVE-2023-3344
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| auto_location_for_wp_job_manager_via_google | affected | auto_location_for_wp_job_manager_via_google_project | — | — |
In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2023-35694
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-35694
PUB-A-267619655
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.
CVEs:CVE-2023-30641
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30641
CVEs:CVE-2023-21251
In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed f...
CVEs:CVE-2023-21251
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
CVEs:CVE-2023-30644
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30644
CVEs:CVE-2023-30645
Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
CVEs:CVE-2023-30645
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
CVEs:CVE-2023-30651
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30651
Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
CVEs:CVE-2023-30652
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30652
CVEs:CVE-2023-30669
Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2023-30669
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2023-30670
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30670
ASB-A-274005916
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
CVEs:CVE-2023-30659
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30659
CVEs:CVE-2023-30658
Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
CVEs:CVE-2023-30658
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21238
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21238
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2023-21246
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21246
Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.
CVEs:CVE-2023-30663
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30663
CVEs:CVE-2023-30666
Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.
CVEs:CVE-2023-30666
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30660
Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
CVEs:CVE-2023-30660
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
CVEs:CVE-2023-30662
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30662
CVEs:CVE-2023-30665
Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.
CVEs:CVE-2023-30665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30667
Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.
CVEs:CVE-2023-30667
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-21262
In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitation.
CVEs:CVE-2023-21262
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.
CVEs:CVE-2023-30640
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30640
CVEs:CVE-2023-30642
Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.
CVEs:CVE-2023-30642
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-20755
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ...
CVEs:CVE-2023-20755
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-280374982
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-35693
In incfs_kill_sb of fs/incfs/vfs.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35693
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-274172774
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
ASB-A-276750306
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-276750584
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
| vendor/qcom-opensource/wlan/platform | affected | platform | platform/vendor/qcom-opensource/wlan/platform | — |
ASB-A-276750639
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
| vendor/qcom-opensource/wlan/platform | affected | platform | platform/vendor/qcom-opensource/wlan/platform | — |
CVEs:CVE-2023-33905
In iwnpi server, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2023-33905
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21243
In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed....
CVEs:CVE-2023-21243
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...
CVEs:CVE-2023-21256
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21256
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issue ...
CVEs:CVE-2023-20754
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20754
ASB-A-280380543
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-33889
CVEs:CVE-2023-33890
CVEs:CVE-2023-33891
CVEs:CVE-2023-33892
CVEs:CVE-2023-33893
CVEs:CVE-2023-33899
CVEs:CVE-2023-33900
CVEs:CVE-2023-33883
CVEs:CVE-2023-33884
CVEs:CVE-2023-33885
CVEs:CVE-2023-33886
CVEs:CVE-2023-33888
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33893
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33892
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33891
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33890
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33889
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33888
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33885
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33886
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33884
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33883
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33900
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33899
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21241
In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21241
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-33879
CVEs:CVE-2023-33880
In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33880
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33879
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution ...
CVEs:CVE-2023-21254
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21254
In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execu...
CVEs:CVE-2023-21247
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21247
In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution ...
CVEs:CVE-2023-21248
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21248
In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User i...
CVEs:CVE-2023-21145
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21145
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21240
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21240
CVEs:CVE-2023-21239
In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2023-21239
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed....
CVEs:CVE-2023-21257
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21257
In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not n...
CVEs:CVE-2023-21249
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21249
The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space. The contents of this memory could contain sensitive information.
CVEs:CVE-2021-0948
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0948
ASB-A-281905774
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-30928
CVEs:CVE-2023-30929
CVEs:CVE-2023-30917
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
CVEs:CVE-2023-30929
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
CVEs:CVE-2023-30928
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
CVEs:CVE-2023-30917
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-32788
CVEs:CVE-2023-33881
CVEs:CVE-2023-30921
CVEs:CVE-2023-30922
CVEs:CVE-2023-30926
CVEs:CVE-2023-30927
CVEs:CVE-2023-30932
CVEs:CVE-2023-30935
CVEs:CVE-2023-30937
CVEs:CVE-2023-30938
CVEs:CVE-2023-30940
CVEs:CVE-2023-30942
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33881
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-32788
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30942
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30940
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30938
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30937
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30935
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30932
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In opm service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30926
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30927
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30922
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30921
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In getLocationCache of GeoLocation.java, there is a possible way to send a mock location during an emergency call due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User in...
CVEs:CVE-2023-35692
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-35692
PUB-A-275950631
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21399
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21399
PUB-A-275462898
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Fix CVE(s): CVE-2023-24329
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.5 | affected | TuxCare:Ubuntu:16.04 | idle-python3.5 | — |
| libpython3.5 | affected | TuxCare:Ubuntu:16.04 | libpython3.5 | — |
| libpython3.5-dev | affected | TuxCare:Ubuntu:16.04 | libpython3.5-dev | — |
| libpython3.5-minimal | affected | TuxCare:Ubuntu:16.04 | libpython3.5-minimal | — |
| libpython3.5-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython3.5-stdlib | — |
| libpython3.5-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython3.5-testsuite | — |
| python3.5 | affected | TuxCare:Ubuntu:16.04 | python3.5 | — |
| python3.5-dev | affected | TuxCare:Ubuntu:16.04 | python3.5-dev | — |
| python3.5-doc | affected | TuxCare:Ubuntu:16.04 | python3.5-doc | — |
| python3.5-examples | affected | TuxCare:Ubuntu:16.04 | python3.5-examples | — |
| python3.5-minimal | affected | TuxCare:Ubuntu:16.04 | python3.5-minimal | — |
| python3.5-venv | affected | TuxCare:Ubuntu:16.04 | python3.5-venv | — |
Fix CVE(s): CVE-2023-24329
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:16.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:16.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:16.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:16.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:16.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:16.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:16.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:16.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:16.04 | python2.7-minimal | — |
Fix CVE(s): CVE-2021-3737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:18.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:18.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:18.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:18.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:18.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:18.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:18.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:18.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:18.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:18.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:18.04 | python2.7-minimal | — |
Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| azure-cli-core | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | azure-cli-core | — |
| azure-cli-core | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | azure-cli-core | — |
| azure-cli-core | affected | openSUSE:Leap 15.4 | azure-cli-core | — |
| azure-cli-core | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | azure-cli-core | — |
| azure-cli-core | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | azure-cli-core | — |
| azure-cli-core | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | azure-cli-core | — |
| grpc | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | grpc | — |
| protobuf | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Installer Updates 15 SP1 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | protobuf | — |
| python-aiocontextvars | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-aiocontextvars | — |
| python-aiocontextvars | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-aiocontextvars | — |
| python-aiocontextvars | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-aiocontextvars | — |
| python-aiocontextvars | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-aiocontextvars | — |
| python-Automat | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS | python-Automat | — |
| python-Automat | affected | SUSE:Manager Proxy 4.2 | python-Automat | — |
| python-Automat | affected | SUSE:Manager Server 4.2 | python-Automat | — |
| python-Automat | affected | SUSE:Linux Enterprise Real Time 15 SP3 | python-Automat | — |
| python-Automat | affected | SUSE:Enterprise Storage 7 | python-Automat | — |
| python-Automat | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | python-Automat | — |
| python-Automat | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | python-Automat | — |
| python-Automat | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | python-Automat | — |
| python-Automat | affected | SUSE:Linux Enterprise Server 15 SP3-LTSS | python-Automat | — |
| python-Automat | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS | python-Automat | — |
| python-Automat | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | python-Automat | — |
| python-Automat | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP3 | python-Automat | — |
| python-Automat | affected | SUSE:Enterprise Storage 7.1 | python-Automat | — |
| python-Automat | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | python-Automat | — |
| python-avro | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-avro | — |
| python-avro | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-avro | — |
| python-avro | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-avro | — |
| python-avro | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-avro | — |
| python-constantly | affected | SUSE:Linux Enterprise Real Time 15 SP3 | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS | python-constantly | — |
| python-constantly | affected | openSUSE:Leap 15.4 | python-constantly | — |
| python-constantly | affected | SUSE:Enterprise Storage 7.1 | python-constantly | — |
| python-constantly | affected | SUSE:Enterprise Storage 7 | python-constantly | — |
| python-constantly | affected | SUSE:Manager Server 4.2 | python-constantly | — |
| python-constantly | affected | SUSE:Manager Proxy 4.2 | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP3 | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise Server 15 SP3-LTSS | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise Module for Server Applications 15 SP4 | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise Module for Server Applications 15 SP5 | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | python-constantly | — |
| python-constantly | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS | python-constantly | — |
| python-cryptography | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | python-cryptography | — |
| python-cryptography | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-cryptography | — |
| python-cryptography | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | python-cryptography | — |
| python-cryptography | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS | python-cryptography | — |
| python-cryptography-vectors | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-cryptography-vectors | — |
| python-cryptography-vectors | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-cryptography-vectors | — |
| python-Deprecated | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-Deprecated | — |
| python-Deprecated | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-Deprecated | — |
| python-Deprecated | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-Deprecated | — |
| python-Deprecated | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-Deprecated | — |
| python-google-api-core | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-google-api-core | — |
| python-googleapis-common-protos | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-googleapis-common-protos | — |
| python-grpcio-gcp | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-grpcio-gcp | — |
| python-humanfriendly | affected | SUSE:Linux Enterprise Module for Package Hub 15 SP5 | python-humanfriendly | — |
| python-humanfriendly | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-humanfriendly | — |
| python-humanfriendly | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-humanfriendly | — |
| python-humanfriendly | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-humanfriendly | — |
| python-humanfriendly | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-humanfriendly | — |
| python-humanfriendly | affected | openSUSE:Leap 15.4 | python-humanfriendly | — |
| python-humanfriendly | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-humanfriendly | — |
| python-hyperlink | affected | SUSE:Enterprise Storage 7.1 | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | python-hyperlink | — |
| python-hyperlink | affected | openSUSE:Leap 15.4 | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise Server 15 SP3-LTSS | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise Module for Server Applications 15 SP4 | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise Module for Server Applications 15 SP5 | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Manager Server 4.2 | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Enterprise Storage 7 | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Manager Proxy 4.2 | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP3 | python-hyperlink | — |
| python-hyperlink | affected | SUSE:Linux Enterprise Real Time 15 SP3 | python-hyperlink | — |
| python-incremental | affected | SUSE:Enterprise Storage 7.1 | python-incremental | — |
| python-incremental | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS | python-incremental | — |
| python-incremental | affected | SUSE:Manager Server 4.2 | python-incremental | — |
| python-incremental | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS | python-incremental | — |
| python-incremental | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | python-incremental | — |
| python-incremental | affected | SUSE:Enterprise Storage 7 | python-incremental | — |
| python-incremental | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP3 | python-incremental | — |
| python-incremental | affected | SUSE:Manager Proxy 4.2 | python-incremental | — |
| python-incremental | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | python-incremental | — |
| python-incremental | affected | SUSE:Linux Enterprise Real Time 15 SP3 | python-incremental | — |
| python-incremental | affected | SUSE:Linux Enterprise Server 15 SP3-LTSS | python-incremental | — |
| python-incremental | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | python-incremental | — |
| python-incremental | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | python-incremental | — |
| python-incremental | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | python-incremental | — |
| python-jsondiff | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-jsondiff | — |
| python-jsondiff | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-jsondiff | — |
| python-jsondiff | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-jsondiff | — |
| python-jsondiff | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-jsondiff | — |
| python-jsondiff | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-jsondiff | — |
| python-jsondiff | affected | openSUSE:Leap 15.4 | python-jsondiff | — |
| python-knack | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-knack | — |
| python-knack | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-knack | — |
| python-knack | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | python-knack | — |
| python-knack | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-knack | — |
| python-knack | affected | openSUSE:Leap 15.4 | python-knack | — |
| python-knack | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-knack | — |
| python-opencensus | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-opencensus | — |
| python-opencensus | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-opencensus | — |
| python-opencensus | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-opencensus | — |
| python-opencensus | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-opencensus | — |
| python-opencensus-context | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-opencensus-context | — |
| python-opencensus-context | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-opencensus-context | — |
| python-opencensus-context | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-opencensus-context | — |
| python-opencensus-context | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-opencensus-context | — |
| python-opencensus-ext-threading | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-opencensus-ext-threading | — |
| python-opencensus-ext-threading | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-opencensus-ext-threading | — |
| python-opencensus-ext-threading | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-opencensus-ext-threading | — |
| python-opencensus-ext-threading | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-opencensus-ext-threading | — |
| python-opentelemetry-api | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-opentelemetry-api | — |
| python-opentelemetry-api | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-opentelemetry-api | — |
| python-opentelemetry-api | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-opentelemetry-api | — |
| python-opentelemetry-api | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-opentelemetry-api | — |
| python-psutil | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | python-psutil | — |
| python-psutil | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-psutil | — |
| python-psutil | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | python-psutil | — |
| python-psutil | affected | SUSE:Enterprise Storage 7 | python-psutil | — |
| python-psutil | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | python-psutil | — |
| python-psutil | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | python-psutil | — |
| python-psutil | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS | python-psutil | — |
| python-psutil | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | python-psutil | — |
| python-PyGithub | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-PyGithub | — |
| python-PyGithub | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-PyGithub | — |
| python-PyGithub | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-PyGithub | — |
| python-PyGithub | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-PyGithub | — |
| python-pytest | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-pytest | — |
| python-pytest | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-pytest | — |
| python-pytest-asyncio | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-pytest-asyncio | — |
| python-pytest-asyncio | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-pytest-asyncio | — |
| python-requests | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | python-requests | — |
| python-requests | affected | SUSE:Enterprise Storage 7 | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | python-requests | — |
| python-requests | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | python-requests | — |
| python-Twisted | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | python-Twisted | — |
| python-Twisted | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-Twisted | — |
| python-Twisted | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | python-Twisted | — |
| python-websocket-client | affected | SUSE:Manager Proxy 4.2 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Manager Server 4.2 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Server 15 SP3-LTSS | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Real Time 15 SP3 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Module for Basesystem 15 SP4 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Enterprise Storage 7.1 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | python-websocket-client | — |
| python-websocket-client | affected | openSUSE:Leap 15.4 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Module for Basesystem 15 SP5 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP3 | python-websocket-client | — |
| python-websocket-client | affected | SUSE:Enterprise Storage 7 | python-websocket-client | — |
| python-websockets | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP2 | python-websockets | — |
| python-websockets | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | python-websockets | — |
| python-websockets | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP3 | python-websockets | — |
| python-websockets | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-websockets | — |
| python-zope.interface | affected | SUSE:Manager Server 4.2 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Manager Proxy 4.2 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP3 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Enterprise Storage 7 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP1 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP1 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise Server 15 SP3-LTSS | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Enterprise Storage 7.1 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise Module for Server Applications 15 SP4 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise Module for Server Applications 15 SP5 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise Server 15 SP1-LTSS | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise Real Time 15 SP3 | python-zope.interface | — |
| python-zope.interface | affected | openSUSE:Leap 15.4 | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS | python-zope.interface | — |
| python-zope.interface | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS | python-zope.interface | — |
Fix CVE(s): CVE-2021-28861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.6 | affected | TuxCare:Ubuntu:18.04 | idle-python3.6 | — |
| libpython3.6 | affected | TuxCare:Ubuntu:18.04 | libpython3.6 | — |
| libpython3.6-dev | affected | TuxCare:Ubuntu:18.04 | libpython3.6-dev | — |
| libpython3.6-minimal | affected | TuxCare:Ubuntu:18.04 | libpython3.6-minimal | — |
| libpython3.6-stdlib | affected | TuxCare:Ubuntu:18.04 | libpython3.6-stdlib | — |
| libpython3.6-testsuite | affected | TuxCare:Ubuntu:18.04 | libpython3.6-testsuite | — |
| python3.6 | affected | TuxCare:Ubuntu:18.04 | python3.6 | — |
| python3.6-dev | affected | TuxCare:Ubuntu:18.04 | python3.6-dev | — |
| python3.6-doc | affected | TuxCare:Ubuntu:18.04 | python3.6-doc | — |
| python3.6-examples | affected | TuxCare:Ubuntu:18.04 | python3.6-examples | — |
| python3.6-minimal | affected | TuxCare:Ubuntu:18.04 | python3.6-minimal | — |
| python3.6-venv | affected | TuxCare:Ubuntu:18.04 | python3.6-venv | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:20.03-LTS-SP3 | kubernetes | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:22.03-LTS | kubernetes | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:22.03-LTS-SP1 | kubernetes | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:22.03-LTS-SP2 | kubernetes | — |
Kubernetes mountable secrets policy bypass
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Kubernetes mountable secrets policy bypass
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aws-ebs-csi-driver-1.18 | affected | chainguard | aws-ebs-csi-driver-1.18 | — |
| aws-efs-csi-driver | affected | wolfi | aws-efs-csi-driver | — |
| aws-efs-csi-driver | affected | chainguard | aws-efs-csi-driver | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
| nodetaint | affected | chainguard | nodetaint | — |
| nodetaint | affected | wolfi | nodetaint | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spark-operator | affected | chainguard | spark-operator | — |
DEBIAN-CVE-2023-2728
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:13 | kubernetes | — |
| kubernetes | affected | Debian:14 | kubernetes | — |
Critical: go-toolset and golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Rocky Linux:9 | golang | — |
| go-toolset | affected | Rocky Linux:9 | go-toolset | — |
Updated golang packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:8 | golang | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:22.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
| golang | affected | openEuler:22.03-LTS | golang | — |
golang-yaml.v2 - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-yaml.v2 | affected | Debian:10 | golang-yaml.v2 | — |
protobufjs Prototype Pollution vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kibana-8 | affected | chainguard | kibana-8 | — |
| protobufjs | affected | npm | protobufjs | — |
protobufjs Prototype Pollution vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobufjs | affected | npm | protobufjs | — |
protobufjs Prototype Pollution vulnerability
CVEs:CVE-2023-36665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobufjs | affected | npm | protobufjs | — |
"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by addin...
CVEs:CVE-2023-36665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobufjs | affected | protobufjs_project | — | — |
protobufjs Prototype Pollution vulnerability
CVEs:CVE-2023-36665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobufjs | affected | npm | protobufjs | — |
CVE-2023-29406 affecting package golang for versions less than 1.20.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-29406 affecting package msft-golang for versions less than 1.20.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| msft-golang | affected | Azure Linux:2 | msft-golang | — |
CVE-2023-29406 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-29406 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-29406 affecting package golang for versions less than 1.20.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVE-2023-29406 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVEs:CVE-2023-29406
DEBIAN-CVE-2023-29406
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian | — | — |
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host o...
CVEs:CVE-2023-29406
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.
CVEs:CVE-2023-29406
Insufficient sanitization of Host header in net/http
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go-1.20 | affected | chainguard | go-1.20 | — |
| go-1.20 | affected | wolfi | go-1.20 | — |
| kind | affected | chainguard | kind | — |
| kind | affected | wolfi | kind | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| stdlib | affected | Go | stdlib | — |
Okio Signed to Unsigned Conversion Error vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.squareup.okio:okio | affected | Maven | com.squareup.okio:okio | — |
| com.squareup.okio:okio-jvm | affected | Maven | com.squareup.okio:okio-jvm | — |
| docker-selenium-jre-bcfips | affected | chainguard | docker-selenium-jre-bcfips | — |
| druid | affected | chainguard | druid | — |
| druid | affected | wolfi | druid | — |
| grpc-java-fips-1.56.0 | affected | chainguard | grpc-java-fips-1.56.0 | — |
| knative-kafka-broker-1.17 | affected | chainguard | knative-kafka-broker-1.17 | — |
| s3proxy | affected | chainguard | s3proxy | — |
| s3proxy-fips | affected | chainguard | s3proxy-fips | — |
| thingsboard | affected | chainguard | thingsboard | — |
| thingsboard | affected | wolfi | thingsboard | — |
| trino | affected | chainguard | trino | — |
| trino | affected | wolfi | trino | — |
| wavefront-proxy | affected | chainguard | wavefront-proxy | — |
| wavefront-proxy | affected | wolfi | wavefront-proxy | — |
Okio Signed to Unsigned Conversion Error vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.squareup.okio:okio | affected | Maven | com.squareup.okio:okio | — |
| com.squareup.okio:okio-jvm | affected | Maven | com.squareup.okio:okio-jvm | — |
kube-apiserver vulnerable to policy bypass
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
kube-apiserver vulnerable to policy bypass
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aws-ebs-csi-driver-1.18 | affected | chainguard | aws-ebs-csi-driver-1.18 | — |
| aws-efs-csi-driver | affected | chainguard | aws-efs-csi-driver | — |
| aws-efs-csi-driver | affected | wolfi | aws-efs-csi-driver | — |
| calico | affected | chainguard | calico | — |
| calico | affected | wolfi | calico | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
| nodetaint | affected | wolfi | nodetaint | — |
| nodetaint | affected | chainguard | nodetaint | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spark-operator | affected | chainguard | spark-operator | — |
DEBIAN-CVE-2023-2727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:13 | kubernetes | — |
| kubernetes | affected | Debian:14 | kubernetes | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
DEBIAN-CVE-2023-37788
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-elazarl-goproxy | affected | Debian:12 | golang-github-elazarl-goproxy | — |
| golang-github-elazarl-goproxy | affected | Debian:11 | golang-github-elazarl-goproxy | — |
| golang-github-elazarl-goproxy | affected | Debian:13 | golang-github-elazarl-goproxy | — |
| golang-github-elazarl-goproxy | affected | Debian:14 | golang-github-elazarl-goproxy | — |
ASB-A-253167854
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
gRPC connection termination issue
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc | affected | RubyGems | grpc | — |
| grpcio | affected | PyPI | grpcio | — |
| grpcio | affected | PyPI | grpcio | — |
| hive | affected | chainguard | hive | — |
| io.grpc:grpc-protobuf | affected | Maven | io.grpc:grpc-protobuf | — |
| stargate | affected | chainguard | stargate | — |
| wavefront-proxy | affected | chainguard | wavefront-proxy | — |
| wavefront-proxy | affected | wolfi | wavefront-proxy | — |
gRPC connection termination issue
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc | affected | RubyGems | grpc | — |
| grpcio | affected | PyPI | grpcio | — |
| io.grpc:grpc-protobuf | affected | Maven | io.grpc:grpc-protobuf | — |
Connection confusion in gRPC
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| calico | affected | wolfi | calico | — |
| calico | affected | chainguard | calico | — |
| grpc | affected | RubyGems | grpc | — |
| grpcio | affected | PyPI | grpcio | — |
| grpcio | affected | PyPI | grpcio | — |
| hive | affected | chainguard | hive | — |
| io.grpc:grpc-protobuf | affected | Maven | io.grpc:grpc-protobuf | — |
| stargate | affected | chainguard | stargate | — |
| wavefront-proxy | affected | wolfi | wavefront-proxy | — |
| wavefront-proxy | affected | chainguard | wavefront-proxy | — |
Connection confusion in gRPC
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc | affected | RubyGems | grpc | — |
| grpcio | affected | PyPI | grpcio | — |
| io.grpc:grpc-protobuf | affected | Maven | io.grpc:grpc-protobuf | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:22.03-LTS-SP2 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
| golang | affected | openEuler:22.03-LTS | golang | — |
| golang | affected | openEuler:22.03-LTS-SP1 | golang | — |
gRPC Reachable Assertion issue
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc | affected | RubyGems | grpc | — |
| grpcio | affected | PyPI | grpcio | — |
| io.grpc:grpc-protobuf | affected | Maven | io.grpc:grpc-protobuf | — |
gRPC Reachable Assertion issue
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| grpc | affected | RubyGems | grpc | — |
| grpcio | affected | PyPI | grpcio | — |
| grpcio | affected | PyPI | grpcio | — |
| hive | affected | chainguard | hive | — |
| io.grpc:grpc-protobuf | affected | Maven | io.grpc:grpc-protobuf | — |
| stargate | affected | chainguard | stargate | — |
| wavefront-proxy | affected | wolfi | wavefront-proxy | — |
| wavefront-proxy | affected | chainguard | wavefront-proxy | — |
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21400
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2023-21400
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| debian_linux | affected | debian | — | — |
CVEs:CVE-2023-21400
PUB-A-264663832
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-33902
In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33902
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20768
In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07559...
CVEs:CVE-2023-20768
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4906
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4906
DEBIAN-CVE-2022-4906
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
kube-apiserver authentication bypass vulnerability
CVEs:CVE-2023-1260
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| openshift/apiserver-library-go | affected | github.com | github.com/openshift/apiserver-library-go | — |
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They ...
CVEs:CVE-2023-1260
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver | affected | kubernetes | — | — |
| openshift_container_platform | affected | redhat | — | — |
CVEs:CVE-2023-36887
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2023-36887
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4907
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-4907
DEBIAN-CVE-2022-4907
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| ffmpeg | affected | Debian:12 | ffmpeg | — |
| ffmpeg | affected | Debian:13 | ffmpeg | — |
| ffmpeg | affected | Debian:14 | ffmpeg | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP4 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP5 | chromium | — |
| chromium | affected | openSUSE:Leap 15.4 | chromium | — |
| chromium | affected | openSUSE:Leap 15.5 | chromium | — |
CVEs:CVE-2023-35392
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2023-35392
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2023-38187
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2023-38187
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4920
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4920
DEBIAN-CVE-2022-4920
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-4908
Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4908
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2022-4908
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-3730
Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3730
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4912
Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4912
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2022-4912
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-4319
Use after free in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2021-4319
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2021-4319
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Object corruption in Blink in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2021-4318
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2021-4318
DEBIAN-CVE-2021-4318
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
Use after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4916
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4916
Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4918
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4918
Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4919
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4919
DEBIAN-CVE-2022-4916
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-4918
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-4919
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3598
CVEs:CVE-2023-3598
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3598
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2023-3598
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
CVEs:CVE-2022-4921
Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2022-4921
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4924
Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4924
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2022-4921
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-4924
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2021-4317
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2021-4317
Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2021-4320
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2021-4320
DEBIAN-CVE-2021-4317
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-4320
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to read arbitrary files via a malicious file. (Chromium security severity: Medium)
CVEs:CVE-2021-4324
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2021-4324
CVEs:CVE-2023-38173
Microsoft Edge for Android Spoofing Vulnerability
CVEs:CVE-2023-38173
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2023-3734
Inappropriate implementation in Picture In Picture in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-3734
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2022-4911
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4911
DEBIAN-CVE-2022-4911
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to spoof extension storage via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4913
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4913
Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4915
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4915
DEBIAN-CVE-2022-4913
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2022-4915
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in WebApp Installs in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-3733
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-3733
Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4922
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4922
DEBIAN-CVE-2022-4922
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2022-4926
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4926
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2022-4926
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via malicious network traffic. (Chromium security severity: Low)
CVEs:CVE-2022-4925
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4925
DEBIAN-CVE-2022-4925
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-3737
Inappropriate implementation in Notifications in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to spoof the contents of media notifications via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-3737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-36888
Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
CVEs:CVE-2023-36888
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2022-4914
Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4914
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2022-4914
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content to a user via a crafted background URL. (Chromium security severity: Low)
CVEs:CVE-2023-3740
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-3740
Use after free in DevTools in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium)
CVEs:CVE-2021-4322
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2021-4322
DEBIAN-CVE-2021-4322
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Autofill in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-3738
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-3738
Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2021-4316
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2021-4316
DEBIAN-CVE-2021-4316
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-4323
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to access local files via a crafted Chrome Extension. (Chromium security severity:...
CVEs:CVE-2021-4323
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2021-4323
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4910
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4910
DEBIAN-CVE-2022-4910
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-20689
In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664741; Issue ID: ...
CVEs:CVE-2023-20689
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | linuxfoundation | — | — |
In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664735; Issue ID: ...
CVEs:CVE-2023-20690
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | linuxfoundation | — | — |
CVEs:CVE-2023-20690
CVEs:CVE-2023-20691
In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664731; Issue ID: ...
CVEs:CVE-2023-20691
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | linuxfoundation | — | — |
In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664720; Issue ID...
CVEs:CVE-2023-20692
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | linuxfoundation | — | — |
CVEs:CVE-2023-20692
In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664711; Issue ID...
CVEs:CVE-2023-20693
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | linuxfoundation | — | — |
CVEs:CVE-2023-20693
Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially perform an ASLR bypass via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2022-4909
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4909
DEBIAN-CVE-2022-4909
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2022-4917
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2022-4917
DEBIAN-CVE-2022-4917
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Omnibox in Google Chrome prior to 99.0.4844.51 allowed an attacker in a privileged network position to perform a man-in-the-middle attack via malicious network traffic. (Chromium security severity: Low)
CVEs:CVE-2022-4923
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2022-4923
DEBIAN-CVE-2022-4923
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2020-8934
The Site Kit by Google plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 1.8.0 This is due to the lack of capability checks on the admin_enqueue_scripts action which displays the connection key. Th...
CVEs:CVE-2020-8934
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| site_kit | affected | — | — |
CVEs:CVE-2023-21255
In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21255
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| debian_linux | affected | debian | — | — |
In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21255
ASB-A-275041864
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of service via physical access to the device. (Chromium security severity: Medium)
CVEs:CVE-2023-3497
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-3497
CVEs:CVE-2023-33882
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33882
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In apu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629578; Issue ID: ...
CVEs:CVE-2023-20760
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20760
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628604; Issue ID: ...
CVEs:CVE-2023-20761
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20761
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573237; Issue ID: ...
CVEs:CVE-2023-20766
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20766
In pqframework, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629585; Is...
CVEs:CVE-2023-20767
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20767
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292228; Issue I...
CVEs:CVE-2023-20774
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20774
CVEs:CVE-2023-20775
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07978760; Issue ...
CVEs:CVE-2023-20775
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| openwrt | affected | openwrt | — | — |
CVEs:CVE-2023-33904
CVEs:CVE-2023-33903
In hci_server, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2023-33904
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In FM service, there is a possible missing params check. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2023-33903
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20757
In cmdq, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07636133; Issue ID:...
CVEs:CVE-2023-20757
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20772
In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441...
CVEs:CVE-2023-20772
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-33896
CVEs:CVE-2023-33897
In libimpl-ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2023-33897
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In libimpl-ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2023-33896
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07611...
CVEs:CVE-2023-20773
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20773
CVEs:CVE-2023-20758
In cmdq, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07636133; Issue ID: ALPS076...
CVEs:CVE-2023-20758
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In cmdq, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07636133; Issue ID: ALPS076...
CVEs:CVE-2023-20759
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20759
CVEs:CVE-2023-33894
CVEs:CVE-2023-33895
CVEs:CVE-2023-33887
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33895
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33894
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33887
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20753
In rpmb, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07460390; Issue ID: ALPS0758...
CVEs:CVE-2023-20753
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead to local escalation of privilege with no additional e...
CVEs:CVE-2023-21245
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21245
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07536951; Issue ID...
CVEs:CVE-2023-20748
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20748
CVEs:CVE-2023-20756
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ...
CVEs:CVE-2023-20756
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-33901
CVEs:CVE-2022-48450
In bluetooth service, there is a possible missing params check. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2022-48450
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-33901
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-32789
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-32789
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-20771
In display, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07671046; Issue ID: ALPS...
CVEs:CVE-2023-20771
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21260
In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation.
CVEs:CVE-2023-21260
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-48451
In bluetooth service, there is a possible out of bounds write due to race condition. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2022-48451
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-3732
Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3732
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
ASB-A-268589017
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting whic...
CVEs:CVE-2023-2333
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ninja_forms_google_sheet_connector | affected | gsheetconnector | — | — |
CVEs:CVE-2023-2333
CVEs:CVE-2023-3728
Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3728
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3728
Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-3727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-3727
Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High)
CVEs:CVE-2023-2313
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-2313
DEBIAN-CVE-2023-2313
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-3736
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 115.0.5790.98 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-3736
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 115.0.5790.98 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-3736
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-2311
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-2311
DEBIAN-CVE-2023-2311
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-3735
Inappropriate implementation in Web API Permission Prompts in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-3735
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-2320
The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could...
CVEs:CVE-2023-2320
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cf7_google_sheets_connector | affected | gsheetconnector | — | — |
The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could ...
CVEs:CVE-2023-2321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| wpforms_google_sheet_connector | affected | gsheetconnector | — | — |
CVEs:CVE-2023-2321
The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site ...
CVEs:CVE-2023-2324
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| elementor_forms_google_sheet_connector | affected | gsheetconnector | — | — |
CVEs:CVE-2023-2324
CVEs:CVE-2023-2329
The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
CVEs:CVE-2023-2329
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| woocommerce_google_sheet_connector | affected | gsheetconnector | — | — |
CVEs:CVE-2023-2330
The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
CVEs:CVE-2023-2330
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| caldera_forms_google_sheets_connector | affected | gsheetconnector | — | — |
DEBIAN-CVE-2023-2314
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-23869
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions.
CVEs:CVE-2023-23869
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_xml_sitemap_for_mobile | affected | digitalinspiration | — | — |
Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
CVEs:CVE-2023-30646
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30646
CVEs:CVE-2023-30647
Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
CVEs:CVE-2023-30647
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30649
Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
CVEs:CVE-2023-30649
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
CVEs:CVE-2023-30650
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30650
Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
CVEs:CVE-2023-30653
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30653
CVEs:CVE-2023-30668
Out-of-bounds Write in BuildOemSecureSimLockResponse of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2023-30668
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30656
Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.
CVEs:CVE-2023-30656
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30657
Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
CVEs:CVE-2023-30657
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
CVEs:CVE-2023-30655
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30655
Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
CVEs:CVE-2023-30664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30664
Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
CVEs:CVE-2023-30661
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30661
Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.
CVEs:CVE-2023-30648
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30648
CVEs:CVE-2023-30671
Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.
CVEs:CVE-2023-30671
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-30643
Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications.
CVEs:CVE-2023-30643
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
ASB-A-276751076
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
| vendor/qcom-opensource/wlan/platform | affected | platform | platform/vendor/qcom-opensource/wlan/platform | — |
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypas...
CVEs:CVE-2023-2626
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nest_hub_firmware | affected | — | — | |
| nest_hub_max_firmware | affected | — | — | |
| nest_wifi_6e_firmware | affected | — | — | |
| nest_wifi_point_firmware | affected | — | — | |
| wifi_firmware | affected | — | — |
CVEs:CVE-2023-30916
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
CVEs:CVE-2023-30916
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-30919
CVEs:CVE-2023-30920
CVEs:CVE-2023-30923
CVEs:CVE-2023-30924
CVEs:CVE-2023-30925
CVEs:CVE-2023-30930
CVEs:CVE-2023-30931
CVEs:CVE-2023-30933
CVEs:CVE-2023-30934
CVEs:CVE-2023-30939
CVEs:CVE-2023-30941
CVEs:CVE-2023-30913
CVEs:CVE-2023-30918
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30913
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30939
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30934
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30933
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30931
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30930
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In opm service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30925
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30924
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30923
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30920
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30919
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30918
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-30936
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVEs:CVE-2023-30936
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Security update for kubernetes1.18
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.18 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS | kubernetes1.18 | — |
| kubernetes1.18 | affected | openSUSE:Leap 15.4 | kubernetes1.18 | — |
| kubernetes1.18 | affected | openSUSE:Leap 15.5 | kubernetes1.18 | — |
| kubernetes1.18 | affected | SUSE:Linux Enterprise Module for Containers 15 SP4 | kubernetes1.18 | — |
| kubernetes1.18 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS | kubernetes1.18 | — |
| kubernetes1.18 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS | kubernetes1.18 | — |
| kubernetes1.18 | affected | SUSE:Linux Enterprise Server 15 SP2-LTSS | kubernetes1.18 | — |
| kubernetes1.18 | affected | SUSE:Linux Enterprise Server 15 SP3-LTSS | kubernetes1.18 | — |
| kubernetes1.18 | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP2 | kubernetes1.18 | — |
| kubernetes1.18 | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP3 | kubernetes1.18 | — |
| kubernetes1.18 | affected | SUSE:Enterprise Storage 7 | kubernetes1.18 | — |
| kubernetes1.18 | affected | SUSE:Enterprise Storage 7.1 | kubernetes1.18 | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.