Advisories
Project ZeroExploitedCISA KEV listed2023-08-17
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.
CVEs:CVE-2023-38831
GoogleExploitedCISA KEV listedCRITICAL2023-08-17
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder tha...
CVEs:CVE-2023-38831
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| winrar |
affected |
rarlab |
— |
— |
GoogleExploitedCISA KEV listedHIGH2023-08-17
CVEs:CVE-2023-38831
Open SourceWeaponized exploitCRITICAL2023-08-21
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourceWeaponized exploit2023-08-17
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
GoogleWeaponized exploitHIGH2023-08-15
CVEs:CVE-2023-4352
GoogleWeaponized exploit2023-08-15
Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4352
GoogleWeaponized exploitHIGH2023-08-15
Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4352
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceWeaponized exploitHIGH2023-08-15
DEBIAN-CVE-2023-4352
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2023-08-23
A security issue was discovered in Kubernetes where a user that can
create pods on Windows nodes running kubernetes-csi-proxy may be able to
escalate to admin privileges on those nodes. Kubernetes clusters are
only affected if they include Windows nodes running
kubernetes-csi-proxy.
CVEs:CVE-2023-3893
Open SourceActive exploitation (sightings)HIGH2023-08-23
Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation
CVEs:CVE-2023-3893
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes-csi/csi-proxy |
affected |
github.com |
github.com/kubernetes-csi/csi-proxy |
— |
| kubernetes-csi/csi-proxy/v2 |
affected |
github.com |
github.com/kubernetes-csi/csi-proxy/v2 |
— |
GoogleActive exploitation (sightings)HIGH2023-08-23
A security issue was discovered in Kubernetes where a user that can
create pods on Windows nodes running kubernetes-csi-proxy may be able to
escalate to admin privileges on those nodes. Kubernetes clusters are
only affected if they include Windows n...
CVEs:CVE-2023-3893
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| csi_proxy |
affected |
kubernetes |
— |
— |
Open SourceActive exploitation (sightings)2023-08-31
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2023-08-29
CVEs:CVE-2023-4572
Open SourceActive exploitation (sightings)CRITICAL2023-08-29
DEBIAN-CVE-2023-4572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2023-08-29
Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4572
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-08-02
Golang TIFF decoder does not place a limit on the size of compressed tile data
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/image |
affected |
golang.org |
golang.org/x/image |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-08-02
Golang TIFF decoder does not place a limit on the size of compressed tile data
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/image |
affected |
golang.org |
golang.org/x/image |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-08-02
DEBIAN-CVE-2023-29408
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-golang-x-image |
affected |
Debian:11 |
golang-golang-x-image |
— |
| golang-golang-x-image |
affected |
Debian:12 |
golang-golang-x-image |
— |
| golang-golang-x-image |
affected |
Debian:13 |
golang-golang-x-image |
— |
| golang-golang-x-image |
affected |
Debian:14 |
golang-golang-x-image |
— |
Open SourceActive exploitation (sightings)CRITICAL2023-08-02
Excessive resource consumption in golang.org/x/image/tiff
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/image |
affected |
golang.org |
golang.org/x/image |
— |
GoogleActive exploitation (sightings)MEDIUM2023-08-01
The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compres...
CVEs:CVE-2023-29408
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| image |
affected |
golang |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-08-01
Golang TIFF decoder does not place a limit on the size of compressed tile data
CVEs:CVE-2023-29408
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/image |
affected |
golang.org |
golang.org/x/image |
— |
GoogleActive exploitation (sightings)2023-08-01
The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compressed data, consuming excessive memory and CPU.
CVEs:CVE-2023-29408
GoogleActive exploitation (sightings)CRITICAL2023-08-07
CVEs:CVE-2023-30699
Open SourceActive exploitation (sightings)CRITICAL2023-08-07
Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.
CVEs:CVE-2023-30699
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-33913
Open SourceActive exploitation (sightings)CRITICAL2023-08-07
In DRM/oemcrypto, there is a possible out of bounds write due to an incorrect calculation of buffer size.This could lead to remote escalation of privilege with System execution privileges needed
CVEs:CVE-2023-33913
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-17
CVEs:CVE-2023-30877
GoogleActive exploitation (sightings)CRITICAL2023-08-17
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov XML for Google Merchant Center plugin <= 3.0.1 versions.
CVEs:CVE-2023-30877
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| xml_for_google_merchant_center |
affected |
icopydoc |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-30
CVEs:CVE-2023-34180
GoogleActive exploitation (sightings)CRITICAL2023-08-30
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in KAPlugins Google Fonts For WordPress plugin <= 3.0.0 versions.
CVEs:CVE-2023-34180
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| free-google-fonts |
affected |
kaplugins |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-15
Insufficient data validation in Systems Extensions in Google Chrome on ChromeOS prior to 116.0.5845.120 allowed an attacker who convinced a user to install a malicious extension to bypass file restrictions via a crafted HTML page. (Chromium security se...
CVEs:CVE-2023-4369
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-15
CVEs:CVE-2023-4369
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30693
Open SourceActive exploitation (sightings)HIGH2023-08-07
Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2023-30693
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30686
Open SourceActive exploitation (sightings)HIGH2023-08-07
Out-of-bounds Write in ReqDataRaw of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2023-30686
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-08-07
Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2023-30687
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30687
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30688
Open SourceActive exploitation (sightings)HIGH2023-08-07
Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2023-30688
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-08-07
Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2023-30689
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30689
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30694
Open SourceActive exploitation (sightings)HIGH2023-08-07
Out-of-bounds Write in IpcTxPcscTransmitApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2023-30694
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2023-08-07
An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
CVEs:CVE-2023-30681
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30681
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30696
Open SourceActive exploitation (sightings)CRITICAL2023-08-07
An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
CVEs:CVE-2023-30696
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30697
Open SourceActive exploitation (sightings)CRITICAL2023-08-07
An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
CVEs:CVE-2023-30697
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30680
Open SourceActive exploitation (sightings)CRITICAL2023-08-07
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.
CVEs:CVE-2023-30680
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30691
Open SourceActive exploitation (sightings)HIGH2023-08-07
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.
CVEs:CVE-2023-30691
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-08-07
CVEs:CVE-2023-30654
Open SourceActive exploitation (sightings)MEDIUM2023-08-07
Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to update fake location.
CVEs:CVE-2023-30654
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-08-07
Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
CVEs:CVE-2023-30685
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)LOW2023-08-07
CVEs:CVE-2023-30685
Open SourceActive exploitation (sightings)MEDIUM2023-08-07
Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.
CVEs:CVE-2023-30698
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-08-07
CVEs:CVE-2023-30698
GoogleActive exploitation (sightings)LOW2023-08-07
CVEs:CVE-2023-30700
Open SourceActive exploitation (sightings)MEDIUM2023-08-07
PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.
CVEs:CVE-2023-30700
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-08-07
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.
CVEs:CVE-2023-30682
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)LOW2023-08-07
CVEs:CVE-2023-30682
GoogleActive exploitation (sightings)LOW2023-08-07
CVEs:CVE-2023-30683
Open SourceActive exploitation (sightings)MEDIUM2023-08-07
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.
CVEs:CVE-2023-30683
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)LOW2023-08-07
CVEs:CVE-2023-30684
Open SourceActive exploitation (sightings)MEDIUM2023-08-07
Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.
CVEs:CVE-2023-30684
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-30679
Open SourceActive exploitation (sightings)HIGH2023-08-07
Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.
CVEs:CVE-2023-30679
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-08-07
PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.
CVEs:CVE-2023-30701
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-08-07
CVEs:CVE-2023-30701
GoogleActive exploitation (sightings)HIGH2023-08-07
CVEs:CVE-2023-21231
Open SourceActive exploitation (sightings)HIGH2023-08-07
In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-exported or permission-protected activity due to a missing permission check. This could lead to local escalation of privilege with no ad...
CVEs:CVE-2023-21231
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-08-07
CVEs:CVE-2023-33908
GoogleActive exploitation (sightings)MEDIUM2023-08-07
CVEs:CVE-2023-33909
Open SourceActive exploitation (sightings)HIGH2023-08-07
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-33908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-08-07
In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-33909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-08-15
Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4357
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GooglePoC exploitHIGH2023-08-15
CVEs:CVE-2023-4357
Open SourcePoC exploitHIGH2023-08-15
DEBIAN-CVE-2023-4357
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploitCRITICAL2023-08-28
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourcePoC exploit2023-08-25
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourcePoC exploitHIGH2023-08-23
DEBIAN-CVE-2023-4427
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitHIGH2023-08-22
CVEs:CVE-2023-4427
GooglePoC exploitHIGH2023-08-22
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4427
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourcePoC exploitCRITICAL2023-08-07
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourcePoC exploit2023-08-04
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourcePoC exploitHIGH2023-08-03
DEBIAN-CVE-2023-4069
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitHIGH2023-08-02
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4069
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-08-02
CVEs:CVE-2023-4069
Open SourcePoC exploitHIGH2023-08-03
DEBIAN-CVE-2023-4068
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitHIGH2023-08-02
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4068
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-08-02
CVEs:CVE-2023-4068
Open SourcePoC exploitHIGH2023-08-23
A security issue was discovered in Kubernetes where a user
that can create pods on Windows nodes may be able to escalate to admin
privileges on those nodes. Kubernetes clusters are only affected if they
include Windows nodes.
CVEs:CVE-2023-3676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
GooglePoC exploit2023-08-23
A security issue was discovered in Kubernetes where a user
that can create pods on Windows nodes may be able to escalate to admin
privileges on those nodes. Kubernetes clusters are only affected if they
include Windows nodes.
CVEs:CVE-2023-3676
Open SourcePoC exploitHIGH2023-08-23
Kubernetes privilege escalation vulnerability
CVEs:CVE-2023-3676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitHIGH2023-08-23
A security issue was discovered in Kubernetes where a user
that can create pods on Windows nodes may be able to escalate to admin
privileges on those nodes. Kubernetes clusters are only affected if they
include Windows nodes.
CVEs:CVE-2023-3955
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
GooglePoC exploit2023-08-23
A security issue was discovered in Kubernetes where a user
that can create pods on Windows nodes may be able to escalate to admin
privileges on those nodes. Kubernetes clusters are only affected if they
include Windows nodes.
CVEs:CVE-2023-3955
Open SourcePoC exploitHIGH2023-08-23
Kubernetes privilege escalation vulnerability
CVEs:CVE-2023-3955
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitCRITICAL2023-08-10
Security update for kubernetes1.24
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes1.24 |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP4 |
kubernetes1.24 |
— |
| kubernetes1.24 |
affected |
openSUSE:Leap 15.4 |
kubernetes1.24 |
— |
Open SourcePoC exploitCRITICAL2023-08-12
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:22.03-LTS-SP2 |
golang |
— |
Open SourcePoC exploitNONE2023-08-26
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:22.03-LTS |
golang |
— |
Open SourcePoC exploitNONE2023-08-26
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:22.03-LTS-SP2 |
golang |
— |
Open SourcePoC exploitNONE2023-08-26
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:20.03-LTS-SP1 |
golang |
— |
Open SourcePoC exploitNONE2023-08-26
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:20.03-LTS-SP3 |
golang |
— |
GooglePoC exploit2023-08-10
Security update for go1.19
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
| go1.19 |
affected |
SUSE:Linux Enterprise Module for Development Tools 15 SP5 |
go1.19 |
— |
| go1.19 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS |
go1.19 |
— |
| go1.19 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS |
go1.19 |
— |
| go1.19 |
affected |
SUSE:Linux Enterprise Server 15 SP3-LTSS |
go1.19 |
— |
| go1.19 |
affected |
SUSE:Linux Enterprise Module for Development Tools 15 SP4 |
go1.19 |
— |
| go1.19 |
affected |
SUSE:Enterprise Storage 7.1 |
go1.19 |
— |
| go1.19 |
affected |
openSUSE:Leap 15.4 |
go1.19 |
— |
| go1.19 |
affected |
openSUSE:Leap 15.5 |
go1.19 |
— |
| go1.19 |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 |
go1.19 |
— |
Open SourcePoC exploitMEDIUM2023-08-02
CVE-2023-29409 affecting package golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitMEDIUM2023-08-02
CVE-2023-29409 affecting package msft-golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| msft-golang |
affected |
Azure Linux:2 |
msft-golang |
— |
Open SourcePoC exploitMEDIUM2023-08-02
CVE-2023-29409 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitMEDIUM2023-08-02
CVE-2023-29409 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitMEDIUM2023-08-02
CVE-2023-29409 affecting package golang for versions less than 1.20.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitMEDIUM2023-08-02
CVE-2023-29409 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
GooglePoC exploitMEDIUM2023-08-02
CVEs:CVE-2023-29409
Open SourcePoC exploitMEDIUM2023-08-02
DEBIAN-CVE-2023-29409
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
GooglePoC exploit2023-08-02
Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.
CVEs:CVE-2023-29409
GooglePoC exploitMEDIUM2023-08-02
Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trus...
CVEs:CVE-2023-29409
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploitNONE2023-08-02
Large RSA keys can cause high CPU usage in crypto/tls
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go-1.20 |
affected |
wolfi |
go-1.20 |
— |
| go-1.20 |
affected |
chainguard |
go-1.20 |
— |
| go-1.21 |
affected |
wolfi |
go-1.21 |
— |
| go-1.21 |
affected |
chainguard |
go-1.21 |
— |
| kind |
affected |
wolfi |
kind |
— |
| kind |
affected |
chainguard |
kind |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| stdlib |
affected |
Go |
stdlib |
— |
Open SourcePoC exploit2023-08-12
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:20.03-LTS-SP1 |
golang |
— |
Open SourcePoC exploit2023-08-12
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:20.03-LTS-SP3 |
golang |
— |
Open SourcePoC exploit2023-08-12
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:22.03-LTS |
golang |
— |
Open SourcePoC exploit2023-08-12
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:22.03-LTS-SP1 |
golang |
— |
Open SourcePoC exploitHIGH2023-08-03
DEBIAN-CVE-2023-4070
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitHIGH2023-08-02
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4070
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-08-02
CVEs:CVE-2023-4070
GooglePoC exploitHIGH2023-08-07
CVEs:CVE-2023-21282
Open SourcePoC exploitHIGH2023-08-07
In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
CVEs:CVE-2023-21282
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitMEDIUM2023-08-02
Golang TIFF decoder vulnerable to excessive CPU consumption
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/image |
affected |
golang.org |
golang.org/x/image |
— |
Open SourcePoC exploitMEDIUM2023-08-02
Golang TIFF decoder vulnerable to excessive CPU consumption
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/image |
affected |
golang.org |
golang.org/x/image |
— |
Open SourcePoC exploitMEDIUM2023-08-02
DEBIAN-CVE-2023-29407
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-golang-x-image |
affected |
Debian:11 |
golang-golang-x-image |
— |
| golang-golang-x-image |
affected |
Debian:12 |
golang-golang-x-image |
— |
| golang-golang-x-image |
affected |
Debian:13 |
golang-golang-x-image |
— |
| golang-golang-x-image |
affected |
Debian:14 |
golang-golang-x-image |
— |
Open SourcePoC exploit2023-08-02
Excessive CPU consumption when decoding 0-height images in golang.org/x/image/tiff
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/image |
affected |
golang.org |
golang.org/x/image |
— |
Open SourcePoC exploitMEDIUM2023-08-01
Golang TIFF decoder vulnerable to excessive CPU consumption
CVEs:CVE-2023-29407
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/image |
affected |
golang.org |
golang.org/x/image |
— |
GooglePoC exploitMEDIUM2023-08-01
A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.
CVEs:CVE-2023-29407
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| image |
affected |
golang |
— |
— |
GooglePoC exploit2023-08-01
A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.
CVEs:CVE-2023-29407
Open SourcePoC exploitCRITICAL2023-08-02
Improper rendering of text nodes in golang.org/x/net/html
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourcePoC exploitCRITICAL2023-08-02
Improper rendering of text nodes in golang.org/x/net/html
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aactl |
affected |
chainguard |
aactl |
— |
| aactl |
affected |
wolfi |
aactl |
— |
| apko |
affected |
chainguard |
apko |
— |
| apko |
affected |
wolfi |
apko |
— |
| argo-cd-2.7 |
affected |
wolfi |
argo-cd-2.7 |
— |
| argo-cd-2.7 |
affected |
chainguard |
argo-cd-2.7 |
— |
| argo-cd-2.8 |
affected |
chainguard |
argo-cd-2.8 |
— |
| argo-cd-2.8 |
affected |
wolfi |
argo-cd-2.8 |
— |
| aws-ebs-csi-driver |
affected |
wolfi |
aws-ebs-csi-driver |
— |
| aws-ebs-csi-driver |
affected |
chainguard |
aws-ebs-csi-driver |
— |
| aws-ebs-csi-driver-1.18 |
affected |
chainguard |
aws-ebs-csi-driver-1.18 |
— |
| aws-ebs-csi-driver-1.19 |
affected |
chainguard |
aws-ebs-csi-driver-1.19 |
— |
| aws-efs-csi-driver |
affected |
wolfi |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver |
affected |
chainguard |
aws-efs-csi-driver |
— |
| aws-load-balancer-controller |
affected |
chainguard |
aws-load-balancer-controller |
— |
| aws-load-balancer-controller |
affected |
wolfi |
aws-load-balancer-controller |
— |
| aws-load-balancer-controller-2.4.5 |
affected |
chainguard |
aws-load-balancer-controller-2.4.5 |
— |
| aws-load-balancer-controller-fips |
affected |
chainguard |
aws-load-balancer-controller-fips |
— |
| azure-aad-pod-identity-mic |
affected |
chainguard |
azure-aad-pod-identity-mic |
— |
| bank-vaults |
affected |
wolfi |
bank-vaults |
— |
| bank-vaults |
affected |
chainguard |
bank-vaults |
— |
| bank-vaults-fips |
affected |
chainguard |
bank-vaults-fips |
— |
| bom |
affected |
wolfi |
bom |
— |
| bom |
affected |
chainguard |
bom |
— |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| cert-manager-fips-1.13 |
affected |
chainguard |
cert-manager-fips-1.13 |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| cloud-sql-proxy |
affected |
wolfi |
cloud-sql-proxy |
— |
| cloud-sql-proxy |
affected |
chainguard |
cloud-sql-proxy |
— |
| cluster-autoscaler-1.25 |
affected |
chainguard |
cluster-autoscaler-1.25 |
— |
| cluster-autoscaler-1.25 |
affected |
wolfi |
cluster-autoscaler-1.25 |
— |
| cluster-autoscaler-fips-1.25 |
affected |
chainguard |
cluster-autoscaler-fips-1.25 |
— |
| cluster-autoscaler-fips-1.26 |
affected |
chainguard |
cluster-autoscaler-fips-1.26 |
— |
| cluster-autoscaler-fips-1.27 |
affected |
chainguard |
cluster-autoscaler-fips-1.27 |
— |
| cluster-autoscaler-fips-1.28 |
affected |
chainguard |
cluster-autoscaler-fips-1.28 |
— |
| consul-1.15 |
affected |
wolfi |
consul-1.15 |
— |
| consul-1.15 |
affected |
chainguard |
consul-1.15 |
— |
| consul-1.16 |
affected |
wolfi |
consul-1.16 |
— |
| consul-1.16 |
affected |
chainguard |
consul-1.16 |
— |
| containerd |
affected |
chainguard |
containerd |
— |
| containerd |
affected |
wolfi |
containerd |
— |
| coredns |
affected |
chainguard |
coredns |
— |
| coredns |
affected |
wolfi |
coredns |
— |
| cosign |
affected |
chainguard |
cosign |
— |
| cosign |
affected |
wolfi |
cosign |
— |
| crossplane-provider-aws |
affected |
wolfi |
crossplane-provider-aws |
— |
| crossplane-provider-aws |
affected |
chainguard |
crossplane-provider-aws |
— |
| crossplane-provider-azure |
affected |
chainguard |
crossplane-provider-azure |
— |
| crossplane-provider-azure |
affected |
wolfi |
crossplane-provider-azure |
— |
| cue |
affected |
chainguard |
cue |
— |
| cue |
affected |
wolfi |
cue |
— |
| dex |
affected |
wolfi |
dex |
— |
| dex |
affected |
chainguard |
dex |
— |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| dgraph |
affected |
wolfi |
dgraph |
— |
| dgraph |
affected |
chainguard |
dgraph |
— |
| dive |
affected |
wolfi |
dive |
— |
| dive |
affected |
chainguard |
dive |
— |
| dynamic-localpv-provisioner |
affected |
wolfi |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner |
affected |
chainguard |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| external-dns |
affected |
chainguard |
external-dns |
— |
| external-dns |
affected |
wolfi |
external-dns |
— |
| external-dns-fips |
affected |
chainguard |
external-dns-fips |
— |
| external-secrets-0.7 |
affected |
chainguard |
external-secrets-0.7 |
— |
| external-secrets-operator |
affected |
wolfi |
external-secrets-operator |
— |
| external-secrets-operator |
affected |
chainguard |
external-secrets-operator |
— |
| falcoctl |
affected |
wolfi |
falcoctl |
— |
| falcoctl |
affected |
chainguard |
falcoctl |
— |
| flux |
affected |
wolfi |
flux |
— |
| flux |
affected |
chainguard |
flux |
— |
| flux-0 |
affected |
chainguard |
flux-0 |
— |
| flux-0.37 |
affected |
chainguard |
flux-0.37 |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-helm-controller-0 |
affected |
chainguard |
flux-helm-controller-0 |
— |
| flux-helm-controller-0.37 |
affected |
chainguard |
flux-helm-controller-0.37 |
— |
| flux-image-automation-controller |
affected |
wolfi |
flux-image-automation-controller |
— |
| flux-image-automation-controller |
affected |
chainguard |
flux-image-automation-controller |
— |
| flux-image-reflector-controller |
affected |
chainguard |
flux-image-reflector-controller |
— |
| flux-image-reflector-controller |
affected |
wolfi |
flux-image-reflector-controller |
— |
| flux-image-reflector-controller-0 |
affected |
chainguard |
flux-image-reflector-controller-0 |
— |
| flux-kustomize-controller |
affected |
wolfi |
flux-kustomize-controller |
— |
| flux-kustomize-controller |
affected |
chainguard |
flux-kustomize-controller |
— |
| flux-kustomize-controller-0 |
affected |
chainguard |
flux-kustomize-controller-0 |
— |
| flux-kustomize-controller-0.37 |
affected |
chainguard |
flux-kustomize-controller-0.37 |
— |
| flux-notification-controller |
affected |
wolfi |
flux-notification-controller |
— |
| flux-notification-controller |
affected |
chainguard |
flux-notification-controller |
— |
| flux-notification-controller-0 |
affected |
chainguard |
flux-notification-controller-0 |
— |
| flux-notification-controller-0.37 |
affected |
chainguard |
flux-notification-controller-0.37 |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| flux-source-controller-0 |
affected |
chainguard |
flux-source-controller-0 |
— |
| flux-source-controller-0.37 |
affected |
chainguard |
flux-source-controller-0.37 |
— |
| frp |
affected |
wolfi |
frp |
— |
| frp |
affected |
chainguard |
frp |
— |
| fuse-overlayfs-snapshotter |
affected |
wolfi |
fuse-overlayfs-snapshotter |
— |
| fuse-overlayfs-snapshotter |
affected |
chainguard |
fuse-overlayfs-snapshotter |
— |
| gatekeeper-3.12 |
affected |
wolfi |
gatekeeper-3.12 |
— |
| gatekeeper-3.12 |
affected |
chainguard |
gatekeeper-3.12 |
— |
| gitlab-pages |
affected |
wolfi |
gitlab-pages |
— |
| gitlab-pages |
affected |
chainguard |
gitlab-pages |
— |
| gitlab-runner |
affected |
chainguard |
gitlab-runner |
— |
| gitlab-runner |
affected |
wolfi |
gitlab-runner |
— |
| git-lfs |
affected |
chainguard |
git-lfs |
— |
| git-lfs |
affected |
wolfi |
git-lfs |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gke-gcloud-auth-plugin |
affected |
wolfi |
gke-gcloud-auth-plugin |
— |
| gke-gcloud-auth-plugin |
affected |
chainguard |
gke-gcloud-auth-plugin |
— |
| gobuster |
affected |
wolfi |
gobuster |
— |
| gobuster |
affected |
chainguard |
gobuster |
— |
| gomplate |
affected |
chainguard |
gomplate |
— |
| gomplate |
affected |
wolfi |
gomplate |
— |
| goreleaser-1.18 |
affected |
wolfi |
goreleaser-1.18 |
— |
| goreleaser-1.18 |
affected |
chainguard |
goreleaser-1.18 |
— |
| grafana-9.3 |
affected |
chainguard |
grafana-9.3 |
— |
| grpcurl |
affected |
wolfi |
grpcurl |
— |
| grpcurl |
affected |
chainguard |
grpcurl |
— |
| haproxy-ingress |
affected |
wolfi |
haproxy-ingress |
— |
| haproxy-ingress |
affected |
chainguard |
haproxy-ingress |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm-3 |
affected |
wolfi |
helm-3 |
— |
| helm-3 |
affected |
chainguard |
helm-3 |
— |
| helm-4 |
affected |
wolfi |
helm-4 |
— |
| helm-4 |
affected |
chainguard |
helm-4 |
— |
| hey |
affected |
wolfi |
hey |
— |
| hey |
affected |
chainguard |
hey |
— |
| hugo |
affected |
chainguard |
hugo |
— |
| hugo |
affected |
wolfi |
hugo |
— |
| influxd |
affected |
wolfi |
influxd |
— |
| influxd |
affected |
chainguard |
influxd |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt-operator |
affected |
chainguard |
k8sgpt-operator |
— |
| k8sgpt-operator |
affected |
wolfi |
k8sgpt-operator |
— |
| kaf |
affected |
chainguard |
kaf |
— |
| kaf |
affected |
wolfi |
kaf |
— |
| karpenter |
affected |
chainguard |
karpenter |
— |
| karpenter |
affected |
wolfi |
karpenter |
— |
| karpenter-0.23 |
affected |
chainguard |
karpenter-0.23 |
— |
| keda-2.10 |
affected |
chainguard |
keda-2.10 |
— |
| keda-2.10 |
affected |
wolfi |
keda-2.10 |
— |
| keda-2.11 |
affected |
wolfi |
keda-2.11 |
— |
| keda-2.11 |
affected |
chainguard |
keda-2.11 |
— |
| keda-2.8 |
affected |
chainguard |
keda-2.8 |
— |
| keda-2.9 |
affected |
chainguard |
keda-2.9 |
— |
| kiam |
affected |
chainguard |
kiam |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kpt |
affected |
chainguard |
kpt |
— |
| kpt |
affected |
wolfi |
kpt |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| kube-fluentd-operator |
affected |
chainguard |
kube-fluentd-operator |
— |
| kube-fluentd-operator |
affected |
wolfi |
kube-fluentd-operator |
— |
| kube-logging-logging-operator-3.17 |
affected |
chainguard |
kube-logging-logging-operator-3.17 |
— |
| kube-logging-logging-operator-4.1 |
affected |
chainguard |
kube-logging-logging-operator-4.1 |
— |
| kube-logging-operator |
affected |
chainguard |
kube-logging-operator |
— |
| kube-logging-operator |
affected |
wolfi |
kube-logging-operator |
— |
| kube-oidc-proxy |
affected |
chainguard |
kube-oidc-proxy |
— |
| kubernetes-csi-external-attacher-4.3 |
affected |
chainguard |
kubernetes-csi-external-attacher-4.3 |
— |
| kubernetes-csi-external-attacher-4.3 |
affected |
wolfi |
kubernetes-csi-external-attacher-4.3 |
— |
| kubernetes-csi-external-attacher-4.4 |
affected |
wolfi |
kubernetes-csi-external-attacher-4.4 |
— |
| kubernetes-csi-external-attacher-4.4 |
affected |
chainguard |
kubernetes-csi-external-attacher-4.4 |
— |
| kubernetes-csi-external-attacher-fips-4.3 |
affected |
chainguard |
kubernetes-csi-external-attacher-fips-4.3 |
— |
| kubernetes-csi-external-attacher-fips-4.4 |
affected |
chainguard |
kubernetes-csi-external-attacher-fips-4.4 |
— |
| kubernetes-csi-external-provisioner |
affected |
chainguard |
kubernetes-csi-external-provisioner |
— |
| kubernetes-csi-external-provisioner |
affected |
wolfi |
kubernetes-csi-external-provisioner |
— |
| kubernetes-csi-external-resizer |
affected |
wolfi |
kubernetes-csi-external-resizer |
— |
| kubernetes-csi-external-resizer |
affected |
chainguard |
kubernetes-csi-external-resizer |
— |
| kubernetes-csi-external-resizer-1.8 |
affected |
chainguard |
kubernetes-csi-external-resizer-1.8 |
— |
| kubernetes-csi-external-resizer-fips-1.8 |
affected |
chainguard |
kubernetes-csi-external-resizer-fips-1.8 |
— |
| kubernetes-csi-external-snapshotter |
affected |
chainguard |
kubernetes-csi-external-snapshotter |
— |
| kubernetes-csi-external-snapshotter |
affected |
wolfi |
kubernetes-csi-external-snapshotter |
— |
| kubernetes-csi-external-snapshotter-6.0 |
affected |
chainguard |
kubernetes-csi-external-snapshotter-6.0 |
— |
| kubernetes-csi-livenessprobe |
affected |
chainguard |
kubernetes-csi-livenessprobe |
— |
| kubernetes-csi-livenessprobe |
affected |
wolfi |
kubernetes-csi-livenessprobe |
— |
| kubernetes-csi-livenessprobe-2.10 |
affected |
chainguard |
kubernetes-csi-livenessprobe-2.10 |
— |
| kubernetes-csi-livenessprobe-fips |
affected |
chainguard |
kubernetes-csi-livenessprobe-fips |
— |
| kubernetes-csi-node-driver-registrar-2.9 |
affected |
chainguard |
kubernetes-csi-node-driver-registrar-2.9 |
— |
| kubernetes-csi-node-driver-registrar-2.9 |
affected |
wolfi |
kubernetes-csi-node-driver-registrar-2.9 |
— |
| kubernetes-csi-node-driver-registrar-fips-2.8 |
affected |
chainguard |
kubernetes-csi-node-driver-registrar-fips-2.8 |
— |
| kubernetes-csi-node-driver-registrar-fips-2.9 |
affected |
chainguard |
kubernetes-csi-node-driver-registrar-fips-2.9 |
— |
| kubernetes-dashboard |
affected |
chainguard |
kubernetes-dashboard |
— |
| kubernetes-dashboard |
affected |
wolfi |
kubernetes-dashboard |
— |
| kubernetes-dashboard-metrics-scraper |
affected |
wolfi |
kubernetes-dashboard-metrics-scraper |
— |
| kubernetes-dashboard-metrics-scraper |
affected |
chainguard |
kubernetes-dashboard-metrics-scraper |
— |
| kubernetes-dns-node-cache-1.17 |
affected |
chainguard |
kubernetes-dns-node-cache-1.17 |
— |
| kube-state-metrics |
affected |
chainguard |
kube-state-metrics |
— |
| kube-state-metrics |
affected |
wolfi |
kube-state-metrics |
— |
| kube-state-metrics-2.2.0 |
affected |
chainguard |
kube-state-metrics-2.2.0 |
— |
| kube-state-metrics-2.6 |
affected |
chainguard |
kube-state-metrics-2.6 |
— |
| kube-state-metrics-fips |
affected |
chainguard |
kube-state-metrics-fips |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubewatch |
affected |
chainguard |
kubewatch |
— |
| kubewatch |
affected |
wolfi |
kubewatch |
— |
| kyverno |
affected |
chainguard |
kyverno |
— |
| kyverno |
affected |
wolfi |
kyverno |
— |
| kyverno-1.8 |
affected |
chainguard |
kyverno-1.8 |
— |
| kyverno-policy-reporter-2.11 |
affected |
chainguard |
kyverno-policy-reporter-2.11 |
— |
| kyverno-policy-reporter-kyverno-plugin-1.5 |
affected |
chainguard |
kyverno-policy-reporter-kyverno-plugin-1.5 |
— |
| mc |
affected |
wolfi |
mc |
— |
| mc |
affected |
chainguard |
mc |
— |
| memcached-exporter |
affected |
chainguard |
memcached-exporter |
— |
| memcached-exporter |
affected |
wolfi |
memcached-exporter |
— |
| metacontroller |
affected |
chainguard |
metacontroller |
— |
| metacontroller |
affected |
wolfi |
metacontroller |
— |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| metrics-server-fips |
affected |
chainguard |
metrics-server-fips |
— |
| minio |
affected |
chainguard |
minio |
— |
| minio |
affected |
wolfi |
minio |
— |
| newrelic-infrastructure-agent |
affected |
wolfi |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent |
affected |
chainguard |
newrelic-infrastructure-agent |
— |
| nfs-subdir-external-provisioner |
affected |
wolfi |
nfs-subdir-external-provisioner |
— |
| nfs-subdir-external-provisioner |
affected |
chainguard |
nfs-subdir-external-provisioner |
— |
| nfs-subdir-external-provisioner-fips |
affected |
chainguard |
nfs-subdir-external-provisioner-fips |
— |
| node-problem-detector-0.8 |
affected |
wolfi |
node-problem-detector-0.8 |
— |
| node-problem-detector-0.8 |
affected |
chainguard |
node-problem-detector-0.8 |
— |
| nodetaint |
affected |
wolfi |
nodetaint |
— |
| nodetaint |
affected |
chainguard |
nodetaint |
— |
| nri-prometheus |
affected |
wolfi |
nri-prometheus |
— |
| nri-prometheus |
affected |
chainguard |
nri-prometheus |
— |
| oauth2-proxy |
affected |
wolfi |
oauth2-proxy |
— |
| oauth2-proxy |
affected |
chainguard |
oauth2-proxy |
— |
| ollama |
affected |
chainguard |
ollama |
— |
| ollama |
affected |
wolfi |
ollama |
— |
| opentofu |
affected |
chainguard |
opentofu |
— |
| opentofu |
affected |
wolfi |
opentofu |
— |
| prometheus |
affected |
chainguard |
prometheus |
— |
| prometheus |
affected |
wolfi |
prometheus |
— |
| prometheus-adapter |
affected |
chainguard |
prometheus-adapter |
— |
| prometheus-adapter |
affected |
wolfi |
prometheus-adapter |
— |
| prometheus-adapter-0.10 |
affected |
chainguard |
prometheus-adapter-0.10 |
— |
| prometheus-adapter-fips |
affected |
chainguard |
prometheus-adapter-fips |
— |
| prometheus-adapter-fips-0.10 |
affected |
chainguard |
prometheus-adapter-fips-0.10 |
— |
| prometheus-alertmanager |
affected |
chainguard |
prometheus-alertmanager |
— |
| prometheus-alertmanager |
affected |
wolfi |
prometheus-alertmanager |
— |
| prometheus-bind-exporter |
affected |
chainguard |
prometheus-bind-exporter |
— |
| prometheus-bind-exporter |
affected |
wolfi |
prometheus-bind-exporter |
— |
| prometheus-blackbox-exporter |
affected |
chainguard |
prometheus-blackbox-exporter |
— |
| prometheus-blackbox-exporter |
affected |
wolfi |
prometheus-blackbox-exporter |
— |
| prometheus-elasticsearch-exporter |
affected |
wolfi |
prometheus-elasticsearch-exporter |
— |
| prometheus-elasticsearch-exporter |
affected |
chainguard |
prometheus-elasticsearch-exporter |
— |
| prometheus-elasticsearch-exporter-fips |
affected |
chainguard |
prometheus-elasticsearch-exporter-fips |
— |
| prometheus-fips |
affected |
chainguard |
prometheus-fips |
— |
| prometheus-fips-2.38 |
affected |
chainguard |
prometheus-fips-2.38 |
— |
| prometheus-mongodb-exporter |
affected |
wolfi |
prometheus-mongodb-exporter |
— |
| prometheus-mongodb-exporter |
affected |
chainguard |
prometheus-mongodb-exporter |
— |
| prometheus-mongodb-exporter-fips |
affected |
chainguard |
prometheus-mongodb-exporter-fips |
— |
| prometheus-mongodb-exporter-fips-0.37 |
affected |
chainguard |
prometheus-mongodb-exporter-fips-0.37 |
— |
| prometheus-mysqld-exporter |
affected |
wolfi |
prometheus-mysqld-exporter |
— |
| prometheus-mysqld-exporter |
affected |
chainguard |
prometheus-mysqld-exporter |
— |
| prometheus-node-exporter |
affected |
chainguard |
prometheus-node-exporter |
— |
| prometheus-node-exporter |
affected |
wolfi |
prometheus-node-exporter |
— |
| prometheus-node-exporter-1.5 |
affected |
chainguard |
prometheus-node-exporter-1.5 |
— |
| prometheus-node-exporter-fips |
affected |
chainguard |
prometheus-node-exporter-fips |
— |
| prometheus-operator |
affected |
wolfi |
prometheus-operator |
— |
| prometheus-operator |
affected |
chainguard |
prometheus-operator |
— |
| prometheus-postgres-exporter |
affected |
wolfi |
prometheus-postgres-exporter |
— |
| prometheus-postgres-exporter |
affected |
chainguard |
prometheus-postgres-exporter |
— |
| prometheus-postgres-exporter-0.10 |
affected |
chainguard |
prometheus-postgres-exporter-0.10 |
— |
| prometheus-postgres-exporter-fips |
affected |
chainguard |
prometheus-postgres-exporter-fips |
— |
| prometheus-pushgateway |
affected |
chainguard |
prometheus-pushgateway |
— |
| prometheus-pushgateway |
affected |
wolfi |
prometheus-pushgateway |
— |
| prometheus-pushgateway-fips |
affected |
chainguard |
prometheus-pushgateway-fips |
— |
| prometheus-pushgateway-fips-1.4 |
affected |
chainguard |
prometheus-pushgateway-fips-1.4 |
— |
| prometheus-stackdriver-exporter |
affected |
wolfi |
prometheus-stackdriver-exporter |
— |
| prometheus-stackdriver-exporter |
affected |
chainguard |
prometheus-stackdriver-exporter |
— |
| prometheus-statsd-exporter |
affected |
wolfi |
prometheus-statsd-exporter |
— |
| prometheus-statsd-exporter |
affected |
chainguard |
prometheus-statsd-exporter |
— |
| prometheus-statsd-exporter-fips |
affected |
chainguard |
prometheus-statsd-exporter-fips |
— |
| pulumi |
affected |
wolfi |
pulumi |
— |
| pulumi |
affected |
chainguard |
pulumi |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| pulumi-language-dotnet |
affected |
chainguard |
pulumi-language-dotnet |
— |
| pulumi-language-dotnet |
affected |
wolfi |
pulumi-language-dotnet |
— |
| pulumi-language-java |
affected |
chainguard |
pulumi-language-java |
— |
| pulumi-language-java |
affected |
wolfi |
pulumi-language-java |
— |
| pulumi-language-yaml |
affected |
chainguard |
pulumi-language-yaml |
— |
| pulumi-language-yaml |
affected |
wolfi |
pulumi-language-yaml |
— |
| rqlite |
affected |
wolfi |
rqlite |
— |
| rqlite |
affected |
chainguard |
rqlite |
— |
| runc |
affected |
wolfi |
runc |
— |
| runc |
affected |
chainguard |
runc |
— |
| secrets-store-csi-driver |
affected |
chainguard |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver |
affected |
wolfi |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver-provider-gcp |
affected |
wolfi |
secrets-store-csi-driver-provider-gcp |
— |
| secrets-store-csi-driver-provider-gcp |
affected |
chainguard |
secrets-store-csi-driver-provider-gcp |
— |
| sigstore-scaffolding |
affected |
wolfi |
sigstore-scaffolding |
— |
| sigstore-scaffolding |
affected |
chainguard |
sigstore-scaffolding |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
| src |
affected |
wolfi |
src |
— |
| src |
affected |
chainguard |
src |
— |
| stakater-reloader |
affected |
chainguard |
stakater-reloader |
— |
| stakater-reloader |
affected |
wolfi |
stakater-reloader |
— |
| stakater-reloader-0.0.119 |
affected |
chainguard |
stakater-reloader-0.0.119 |
— |
| stakater-reloader-0.0.128 |
affected |
chainguard |
stakater-reloader-0.0.128 |
— |
| tctl |
affected |
wolfi |
tctl |
— |
| tctl |
affected |
chainguard |
tctl |
— |
| telegraf-1.26 |
affected |
chainguard |
telegraf-1.26 |
— |
| telegraf-1.26 |
affected |
wolfi |
telegraf-1.26 |
— |
| terraform |
affected |
chainguard |
terraform |
— |
| terraform |
affected |
wolfi |
terraform |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| thanos-0.31 |
affected |
chainguard |
thanos-0.31 |
— |
| thanos-0.31 |
affected |
wolfi |
thanos-0.31 |
— |
| thanos-0.32 |
affected |
wolfi |
thanos-0.32 |
— |
| thanos-0.32 |
affected |
chainguard |
thanos-0.32 |
— |
| thanos-operator |
affected |
wolfi |
thanos-operator |
— |
| thanos-operator |
affected |
chainguard |
thanos-operator |
— |
| timoni |
affected |
chainguard |
timoni |
— |
| timoni |
affected |
wolfi |
timoni |
— |
| tkn |
affected |
chainguard |
tkn |
— |
| tkn |
affected |
wolfi |
tkn |
— |
| trillian |
affected |
chainguard |
trillian |
— |
| trillian |
affected |
wolfi |
trillian |
— |
| trust-manager |
affected |
chainguard |
trust-manager |
— |
| trust-manager |
affected |
wolfi |
trust-manager |
— |
| vault-1.13 |
affected |
wolfi |
vault-1.13 |
— |
| vault-1.13 |
affected |
chainguard |
vault-1.13 |
— |
| vault-csi-provider |
affected |
chainguard |
vault-csi-provider |
— |
| vault-csi-provider |
affected |
wolfi |
vault-csi-provider |
— |
| vault-k8s |
affected |
wolfi |
vault-k8s |
— |
| vault-k8s |
affected |
chainguard |
vault-k8s |
— |
| vertical-pod-autoscaler |
affected |
chainguard |
vertical-pod-autoscaler |
— |
| vertical-pod-autoscaler |
affected |
wolfi |
vertical-pod-autoscaler |
— |
| volume-modifier-for-k8s-fips |
affected |
chainguard |
volume-modifier-for-k8s-fips |
— |
| wavefront-collector-for-kubernetes-1.12 |
affected |
chainguard |
wavefront-collector-for-kubernetes-1.12 |
— |
| wavefront-collector-for-kubernetes-1.13 |
affected |
chainguard |
wavefront-collector-for-kubernetes-1.13 |
— |
| weaviate |
affected |
wolfi |
weaviate |
— |
| weaviate |
affected |
chainguard |
weaviate |
— |
| wireguard-go |
affected |
wolfi |
wireguard-go |
— |
| wireguard-go |
affected |
chainguard |
wireguard-go |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
| x/net |
affected |
golang.org |
— |
— |
| yq |
affected |
chainguard |
yq |
— |
| yq |
affected |
wolfi |
yq |
— |
| zot |
affected |
chainguard |
zot |
— |
| zot |
affected |
wolfi |
zot |
— |
Open SourcePoC exploitCRITICAL2023-08-02
CVE-2023-3978 affecting package application-gateway-kubernetes-ingress for versions less than 1.7.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| application-gateway-kubernetes-ingress |
affected |
Azure Linux:3 |
application-gateway-kubernetes-ingress |
— |
Open SourcePoC exploitCRITICAL2023-08-02
DEBIAN-CVE-2023-3978
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-golang-x-net |
affected |
Debian:11 |
golang-golang-x-net |
— |
| golang-golang-x-net |
affected |
Debian:12 |
golang-golang-x-net |
— |
| golang-golang-x-net |
affected |
Debian:13 |
golang-golang-x-net |
— |
| golang-golang-x-net |
affected |
Debian:14 |
golang-golang-x-net |
— |
Open SourcePoC exploitCRITICAL2023-08-02
Improper rendering of text nodes in golang.org/x/net/html
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aactl |
affected |
wolfi |
aactl |
— |
| aactl |
affected |
chainguard |
aactl |
— |
| apko |
affected |
chainguard |
apko |
— |
| apko |
affected |
wolfi |
apko |
— |
| aws-ebs-csi-driver |
affected |
chainguard |
aws-ebs-csi-driver |
— |
| aws-efs-csi-driver |
affected |
chainguard |
aws-efs-csi-driver |
— |
| aws-efs-csi-driver |
affected |
wolfi |
aws-efs-csi-driver |
— |
| aws-load-balancer-controller |
affected |
chainguard |
aws-load-balancer-controller |
— |
| aws-load-balancer-controller |
affected |
wolfi |
aws-load-balancer-controller |
— |
| aws-load-balancer-controller-fips |
affected |
chainguard |
aws-load-balancer-controller-fips |
— |
| azure-aad-pod-identity-mic |
affected |
chainguard |
azure-aad-pod-identity-mic |
— |
| bank-vaults |
affected |
wolfi |
bank-vaults |
— |
| bank-vaults |
affected |
chainguard |
bank-vaults |
— |
| bank-vaults-fips |
affected |
chainguard |
bank-vaults-fips |
— |
| bom |
affected |
wolfi |
bom |
— |
| bom |
affected |
chainguard |
bom |
— |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| cosign |
affected |
chainguard |
cosign |
— |
| cosign |
affected |
wolfi |
cosign |
— |
| crossplane-provider-aws |
affected |
chainguard |
crossplane-provider-aws |
— |
| crossplane-provider-aws |
affected |
wolfi |
crossplane-provider-aws |
— |
| crossplane-provider-azure |
affected |
chainguard |
crossplane-provider-azure |
— |
| crossplane-provider-azure |
affected |
wolfi |
crossplane-provider-azure |
— |
| cue |
affected |
chainguard |
cue |
— |
| cue |
affected |
wolfi |
cue |
— |
| dex |
affected |
chainguard |
dex |
— |
| dex |
affected |
wolfi |
dex |
— |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| dgraph |
affected |
wolfi |
dgraph |
— |
| dgraph |
affected |
chainguard |
dgraph |
— |
| dive |
affected |
chainguard |
dive |
— |
| dive |
affected |
wolfi |
dive |
— |
| dynamic-localpv-provisioner |
affected |
chainguard |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner |
affected |
wolfi |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| falcoctl |
affected |
wolfi |
falcoctl |
— |
| falcoctl |
affected |
chainguard |
falcoctl |
— |
| flux |
affected |
wolfi |
flux |
— |
| flux |
affected |
chainguard |
flux |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-image-automation-controller |
affected |
chainguard |
flux-image-automation-controller |
— |
| flux-image-automation-controller |
affected |
wolfi |
flux-image-automation-controller |
— |
| flux-image-reflector-controller |
affected |
chainguard |
flux-image-reflector-controller |
— |
| flux-image-reflector-controller |
affected |
wolfi |
flux-image-reflector-controller |
— |
| flux-kustomize-controller |
affected |
chainguard |
flux-kustomize-controller |
— |
| flux-kustomize-controller |
affected |
wolfi |
flux-kustomize-controller |
— |
| flux-notification-controller |
affected |
chainguard |
flux-notification-controller |
— |
| flux-notification-controller |
affected |
wolfi |
flux-notification-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| frp |
affected |
chainguard |
frp |
— |
| frp |
affected |
wolfi |
frp |
— |
| fuse-overlayfs-snapshotter |
affected |
chainguard |
fuse-overlayfs-snapshotter |
— |
| fuse-overlayfs-snapshotter |
affected |
wolfi |
fuse-overlayfs-snapshotter |
— |
| git-lfs |
affected |
chainguard |
git-lfs |
— |
| git-lfs |
affected |
wolfi |
git-lfs |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gke-gcloud-auth-plugin |
affected |
chainguard |
gke-gcloud-auth-plugin |
— |
| gke-gcloud-auth-plugin |
affected |
wolfi |
gke-gcloud-auth-plugin |
— |
| gobuster |
affected |
wolfi |
gobuster |
— |
| gobuster |
affected |
chainguard |
gobuster |
— |
| gomplate |
affected |
wolfi |
gomplate |
— |
| gomplate |
affected |
chainguard |
gomplate |
— |
| grpcurl |
affected |
chainguard |
grpcurl |
— |
| grpcurl |
affected |
wolfi |
grpcurl |
— |
| haproxy-ingress |
affected |
wolfi |
haproxy-ingress |
— |
| haproxy-ingress |
affected |
chainguard |
haproxy-ingress |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm-3 |
affected |
chainguard |
helm-3 |
— |
| helm-3 |
affected |
wolfi |
helm-3 |
— |
| helm-4 |
affected |
wolfi |
helm-4 |
— |
| helm-4 |
affected |
chainguard |
helm-4 |
— |
| hey |
affected |
chainguard |
hey |
— |
| hey |
affected |
wolfi |
hey |
— |
| hugo |
affected |
wolfi |
hugo |
— |
| hugo |
affected |
chainguard |
hugo |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt-operator |
affected |
wolfi |
k8sgpt-operator |
— |
| k8sgpt-operator |
affected |
chainguard |
k8sgpt-operator |
— |
| kaf |
affected |
wolfi |
kaf |
— |
| kaf |
affected |
chainguard |
kaf |
— |
| kiam |
affected |
chainguard |
kiam |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kpt |
affected |
wolfi |
kpt |
— |
| kpt |
affected |
chainguard |
kpt |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| kube-fluentd-operator |
affected |
wolfi |
kube-fluentd-operator |
— |
| kube-fluentd-operator |
affected |
chainguard |
kube-fluentd-operator |
— |
| kube-logging-logging-operator-3.17 |
affected |
chainguard |
kube-logging-logging-operator-3.17 |
— |
| kube-logging-logging-operator-4.1 |
affected |
chainguard |
kube-logging-logging-operator-4.1 |
— |
| kube-logging-operator |
affected |
chainguard |
kube-logging-operator |
— |
| kube-logging-operator |
affected |
wolfi |
kube-logging-operator |
— |
| kube-oidc-proxy |
affected |
chainguard |
kube-oidc-proxy |
— |
| kubernetes-csi-external-provisioner |
affected |
chainguard |
kubernetes-csi-external-provisioner |
— |
| kubernetes-csi-external-provisioner |
affected |
wolfi |
kubernetes-csi-external-provisioner |
— |
| kubernetes-csi-external-resizer |
affected |
wolfi |
kubernetes-csi-external-resizer |
— |
| kubernetes-csi-external-resizer |
affected |
chainguard |
kubernetes-csi-external-resizer |
— |
| kubernetes-csi-livenessprobe |
affected |
chainguard |
kubernetes-csi-livenessprobe |
— |
| kubernetes-csi-livenessprobe |
affected |
wolfi |
kubernetes-csi-livenessprobe |
— |
| kubernetes-csi-livenessprobe-2.10 |
affected |
chainguard |
kubernetes-csi-livenessprobe-2.10 |
— |
| kubernetes-csi-livenessprobe-fips |
affected |
chainguard |
kubernetes-csi-livenessprobe-fips |
— |
| kubernetes-dashboard |
affected |
wolfi |
kubernetes-dashboard |
— |
| kubernetes-dashboard |
affected |
chainguard |
kubernetes-dashboard |
— |
| kubernetes-dashboard-metrics-scraper |
affected |
wolfi |
kubernetes-dashboard-metrics-scraper |
— |
| kubernetes-dashboard-metrics-scraper |
affected |
chainguard |
kubernetes-dashboard-metrics-scraper |
— |
| kube-state-metrics |
affected |
chainguard |
kube-state-metrics |
— |
| kube-state-metrics |
affected |
wolfi |
kube-state-metrics |
— |
| kube-state-metrics-2.6 |
affected |
chainguard |
kube-state-metrics-2.6 |
— |
| kube-state-metrics-fips |
affected |
chainguard |
kube-state-metrics-fips |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubewatch |
affected |
wolfi |
kubewatch |
— |
| kubewatch |
affected |
chainguard |
kubewatch |
— |
| mc |
affected |
wolfi |
mc |
— |
| mc |
affected |
chainguard |
mc |
— |
| memcached-exporter |
affected |
chainguard |
memcached-exporter |
— |
| memcached-exporter |
affected |
wolfi |
memcached-exporter |
— |
| metacontroller |
affected |
chainguard |
metacontroller |
— |
| metacontroller |
affected |
wolfi |
metacontroller |
— |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| metrics-server-fips |
affected |
chainguard |
metrics-server-fips |
— |
| minio |
affected |
wolfi |
minio |
— |
| minio |
affected |
chainguard |
minio |
— |
| newrelic-infrastructure-agent |
affected |
wolfi |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent |
affected |
chainguard |
newrelic-infrastructure-agent |
— |
| nfs-subdir-external-provisioner |
affected |
chainguard |
nfs-subdir-external-provisioner |
— |
| nfs-subdir-external-provisioner |
affected |
wolfi |
nfs-subdir-external-provisioner |
— |
| nfs-subdir-external-provisioner-fips |
affected |
chainguard |
nfs-subdir-external-provisioner-fips |
— |
| node-problem-detector-0.8 |
affected |
chainguard |
node-problem-detector-0.8 |
— |
| nodetaint |
affected |
chainguard |
nodetaint |
— |
| nodetaint |
affected |
wolfi |
nodetaint |
— |
| nri-prometheus |
affected |
wolfi |
nri-prometheus |
— |
| nri-prometheus |
affected |
chainguard |
nri-prometheus |
— |
| oauth2-proxy |
affected |
wolfi |
oauth2-proxy |
— |
| oauth2-proxy |
affected |
chainguard |
oauth2-proxy |
— |
| ollama |
affected |
chainguard |
ollama |
— |
| ollama |
affected |
wolfi |
ollama |
— |
| prometheus-adapter |
affected |
chainguard |
prometheus-adapter |
— |
| prometheus-adapter |
affected |
wolfi |
prometheus-adapter |
— |
| prometheus-adapter-0.10 |
affected |
chainguard |
prometheus-adapter-0.10 |
— |
| prometheus-adapter-fips |
affected |
chainguard |
prometheus-adapter-fips |
— |
| prometheus-adapter-fips-0.10 |
affected |
chainguard |
prometheus-adapter-fips-0.10 |
— |
| prometheus-alertmanager |
affected |
wolfi |
prometheus-alertmanager |
— |
| prometheus-alertmanager |
affected |
chainguard |
prometheus-alertmanager |
— |
| prometheus-bind-exporter |
affected |
chainguard |
prometheus-bind-exporter |
— |
| prometheus-blackbox-exporter |
affected |
chainguard |
prometheus-blackbox-exporter |
— |
| prometheus-elasticsearch-exporter |
affected |
chainguard |
prometheus-elasticsearch-exporter |
— |
| prometheus-elasticsearch-exporter-fips |
affected |
chainguard |
prometheus-elasticsearch-exporter-fips |
— |
| prometheus-mongodb-exporter |
affected |
chainguard |
prometheus-mongodb-exporter |
— |
| prometheus-mongodb-exporter-fips |
affected |
chainguard |
prometheus-mongodb-exporter-fips |
— |
| prometheus-mongodb-exporter-fips-0.37 |
affected |
chainguard |
prometheus-mongodb-exporter-fips-0.37 |
— |
| prometheus-mysqld-exporter |
affected |
chainguard |
prometheus-mysqld-exporter |
— |
| prometheus-node-exporter |
affected |
chainguard |
prometheus-node-exporter |
— |
| prometheus-node-exporter-1.5 |
affected |
chainguard |
prometheus-node-exporter-1.5 |
— |
| prometheus-node-exporter-fips |
affected |
chainguard |
prometheus-node-exporter-fips |
— |
| prometheus-operator |
affected |
chainguard |
prometheus-operator |
— |
| prometheus-operator |
affected |
wolfi |
prometheus-operator |
— |
| prometheus-postgres-exporter |
affected |
chainguard |
prometheus-postgres-exporter |
— |
| prometheus-postgres-exporter-0.10 |
affected |
chainguard |
prometheus-postgres-exporter-0.10 |
— |
| prometheus-postgres-exporter-fips |
affected |
chainguard |
prometheus-postgres-exporter-fips |
— |
| prometheus-pushgateway |
affected |
chainguard |
prometheus-pushgateway |
— |
| prometheus-pushgateway |
affected |
wolfi |
prometheus-pushgateway |
— |
| prometheus-pushgateway-fips |
affected |
chainguard |
prometheus-pushgateway-fips |
— |
| prometheus-pushgateway-fips-1.4 |
affected |
chainguard |
prometheus-pushgateway-fips-1.4 |
— |
| prometheus-stackdriver-exporter |
affected |
chainguard |
prometheus-stackdriver-exporter |
— |
| prometheus-statsd-exporter |
affected |
chainguard |
prometheus-statsd-exporter |
— |
| prometheus-statsd-exporter-fips |
affected |
chainguard |
prometheus-statsd-exporter-fips |
— |
| pulumi |
affected |
chainguard |
pulumi |
— |
| pulumi |
affected |
wolfi |
pulumi |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| pulumi-language-dotnet |
affected |
chainguard |
pulumi-language-dotnet |
— |
| pulumi-language-dotnet |
affected |
wolfi |
pulumi-language-dotnet |
— |
| pulumi-language-java |
affected |
wolfi |
pulumi-language-java |
— |
| pulumi-language-java |
affected |
chainguard |
pulumi-language-java |
— |
| pulumi-language-yaml |
affected |
wolfi |
pulumi-language-yaml |
— |
| pulumi-language-yaml |
affected |
chainguard |
pulumi-language-yaml |
— |
| rqlite |
affected |
wolfi |
rqlite |
— |
| rqlite |
affected |
chainguard |
rqlite |
— |
| runc |
affected |
wolfi |
runc |
— |
| runc |
affected |
chainguard |
runc |
— |
| secrets-store-csi-driver |
affected |
wolfi |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver |
affected |
chainguard |
secrets-store-csi-driver |
— |
| secrets-store-csi-driver-provider-gcp |
affected |
chainguard |
secrets-store-csi-driver-provider-gcp |
— |
| secrets-store-csi-driver-provider-gcp |
affected |
wolfi |
secrets-store-csi-driver-provider-gcp |
— |
| sigstore-scaffolding |
affected |
chainguard |
sigstore-scaffolding |
— |
| sigstore-scaffolding |
affected |
wolfi |
sigstore-scaffolding |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| spark-operator |
affected |
chainguard |
spark-operator |
— |
| spark-operator |
affected |
wolfi |
spark-operator |
— |
| src |
affected |
wolfi |
src |
— |
| src |
affected |
chainguard |
src |
— |
| stakater-reloader |
affected |
chainguard |
stakater-reloader |
— |
| stakater-reloader |
affected |
wolfi |
stakater-reloader |
— |
| stakater-reloader-0.0.119 |
affected |
chainguard |
stakater-reloader-0.0.119 |
— |
| stakater-reloader-0.0.128 |
affected |
chainguard |
stakater-reloader-0.0.128 |
— |
| terraform |
affected |
chainguard |
terraform |
— |
| terraform |
affected |
wolfi |
terraform |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| thanos-operator |
affected |
wolfi |
thanos-operator |
— |
| thanos-operator |
affected |
chainguard |
thanos-operator |
— |
| timoni |
affected |
wolfi |
timoni |
— |
| timoni |
affected |
chainguard |
timoni |
— |
| tkn |
affected |
wolfi |
tkn |
— |
| tkn |
affected |
chainguard |
tkn |
— |
| trillian |
affected |
wolfi |
trillian |
— |
| trillian |
affected |
chainguard |
trillian |
— |
| trust-manager |
affected |
wolfi |
trust-manager |
— |
| trust-manager |
affected |
chainguard |
trust-manager |
— |
| vault-csi-provider |
affected |
chainguard |
vault-csi-provider |
— |
| vault-k8s |
affected |
chainguard |
vault-k8s |
— |
| vault-k8s |
affected |
wolfi |
vault-k8s |
— |
| vertical-pod-autoscaler |
affected |
chainguard |
vertical-pod-autoscaler |
— |
| vertical-pod-autoscaler |
affected |
wolfi |
vertical-pod-autoscaler |
— |
| volume-modifier-for-k8s-fips |
affected |
chainguard |
volume-modifier-for-k8s-fips |
— |
| wavefront-collector-for-kubernetes-1.12 |
affected |
chainguard |
wavefront-collector-for-kubernetes-1.12 |
— |
| wavefront-collector-for-kubernetes-1.13 |
affected |
chainguard |
wavefront-collector-for-kubernetes-1.13 |
— |
| weaviate |
affected |
chainguard |
weaviate |
— |
| weaviate |
affected |
wolfi |
weaviate |
— |
| wireguard-go |
affected |
chainguard |
wireguard-go |
— |
| wireguard-go |
affected |
wolfi |
wireguard-go |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
| yq |
affected |
wolfi |
yq |
— |
| yq |
affected |
chainguard |
yq |
— |
| zot |
affected |
wolfi |
zot |
— |
| zot |
affected |
chainguard |
zot |
— |
GooglePoC exploitCRITICAL2023-08-01
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
CVEs:CVE-2023-3978
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| networking |
affected |
golang |
— |
— |
Open SourcePoC exploitMEDIUM2023-08-01
Improper rendering of text nodes in golang.org/x/net/html
CVEs:CVE-2023-3978
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourcePoC exploitMEDIUM2023-08-01
Improper rendering of text nodes in golang.org/x/net/html
CVEs:CVE-2023-3978
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourcePoC exploitHIGH2023-08-09
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
CVEs:CVE-2023-4785
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
Open SourcePoC exploitHIGH2023-08-09
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC ...
CVEs:CVE-2023-4785
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
grpc |
— |
— |
Open SourcePoC exploitHIGH2023-08-09
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
CVEs:CVE-2023-4785
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
Open SourcePoC exploitHIGH2023-08-09
Excessive Iteration in gRPC
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
Open SourcePoC exploitHIGH2023-08-09
Excessive Iteration in gRPC
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
Open SourcePoC exploitHIGH2023-08-09
CVE-2023-33953 affecting package grpc 1.42.0-11
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Azure Linux:2 |
grpc |
— |
Open SourcePoC exploitHIGH2023-08-09
CVE-2023-33953 affecting package grpc for versions less than 1.62.0-2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Azure Linux:3 |
grpc |
— |
Open SourcePoC exploitHIGH2023-08-09
DEBIAN-CVE-2023-33953
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Debian:13 |
grpc |
— |
| grpc |
affected |
Debian:11 |
grpc |
— |
| grpc |
affected |
Debian:12 |
grpc |
— |
| grpc |
affected |
Debian:14 |
grpc |
— |
Open SourcePoC exploitHIGH2023-08-09
Excessive Iteration in gRPC
CVEs:CVE-2023-33953
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
Open SourcePoC exploitHIGH2023-08-09
Excessive Iteration in gRPC
CVEs:CVE-2023-33953
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
Open SourcePoC exploitHIGH2023-08-09
gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks:
- Unbounded memory buffering i...
CVEs:CVE-2023-33953
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
grpc |
— |
— |
GooglePoC exploit2023-08-01
Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low)
CVEs:CVE-2023-3739
GooglePoC exploitMEDIUM2023-08-01
CVEs:CVE-2023-3739
GooglePoC exploitCRITICAL2023-08-01
Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low)
CVEs:CVE-2023-3739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2023-08-01
DEBIAN-CVE-2023-3739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploitHIGH2023-08-07
In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr...
CVEs:CVE-2023-21275
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-08-07
CVEs:CVE-2023-21275
Open SourcePoC exploitHIGH2023-08-07
In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a logic error in the code. This could lead to local escalation of privilege across users with no additional execution privileges needed....
CVEs:CVE-2023-21281
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-08-07
CVEs:CVE-2023-21281
GooglePoC exploitHIGH2023-08-07
CVEs:CVE-2023-21286
Open SourcePoC exploitHIGH2023-08-07
In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2023-21286
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-08-07
CVEs:CVE-2023-21285
Open SourcePoC exploitMEDIUM2023-08-07
In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2023-21285
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2023-08-07
CVEs:CVE-2023-21272
Open SourcePoC exploitHIGH2023-08-07
In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21272
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitMEDIUM2023-08-07
In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interacti...
CVEs:CVE-2023-21284
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-08-07
CVEs:CVE-2023-21284
GooglePoC exploitMEDIUM2023-08-07
CVEs:CVE-2023-21288
Open SourcePoC exploitMEDIUM2023-08-07
In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2023-21288
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-15
CVEs:CVE-2023-4355
GoogleCoalition ESS < 30%HIGH2023-08-15
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4355
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-15
DEBIAN-CVE-2023-4355
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-15
Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. (Chromium...
CVEs:CVE-2023-4362
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-15
CVEs:CVE-2023-4362
GoogleCoalition ESS < 30%2023-08-15
Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4362
Open SourceCoalition ESS < 30%CRITICAL2023-08-15
DEBIAN-CVE-2023-4362
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-23
DEBIAN-CVE-2023-4428
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2023-08-22
Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4428
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-22
CVEs:CVE-2023-4428
Open SourceCoalition ESS < 30%CRITICAL2023-08-23
DEBIAN-CVE-2023-4430
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-22
Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4430
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-22
CVEs:CVE-2023-4430
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVEs:CVE-2023-38157
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-38157
GoogleCoalition ESS < 30%HIGH2023-08-26
CVEs:CVE-2023-36741
Open SourceCoalition ESS < 30%CRITICAL2023-08-08
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2023-36741
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%NONE2023-08-23
Misleading message verification in golang.org/x/crypto/openpgp/clearsign
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| x/crypto |
affected |
golang.org |
golang.org/x/crypto |
— |
GoogleCoalition ESS < 30%HIGH2023-08-17
CVEs:CVE-2023-36787
Open SourceCoalition ESS < 30%CRITICAL2023-08-08
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2023-36787
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-15
CVEs:CVE-2023-4354
GoogleCoalition ESS < 30%CRITICAL2023-08-15
Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4354
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-15
DEBIAN-CVE-2023-4354
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-08
CVE-2023-39533 affecting package golang for versions less than 1.19.12-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-08
CVE-2023-39533 affecting package msft-golang for versions less than 1.19.12-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| msft-golang |
affected |
Azure Linux:2 |
msft-golang |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-08
CVE-2023-39533 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-08
CVE-2023-39533 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-08
CVE-2023-39533 affecting package golang for versions less than 1.19.12-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-08
CVE-2023-39533 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
GoogleCoalition ESS < 30%LOW2023-08-17
CVEs:CVE-2023-38158
Open SourceCoalition ESS < 30%HIGH2023-08-08
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVEs:CVE-2023-38158
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-03
DEBIAN-CVE-2023-4071
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2023-08-02
CVEs:CVE-2023-4071
GoogleCoalition ESS < 30%CRITICAL2023-08-02
Heap buffer overflow in Visuals in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4071
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-03
DEBIAN-CVE-2023-4072
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-03
DEBIAN-CVE-2023-4073
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2023-08-02
CVEs:CVE-2023-4072
GoogleCoalition ESS < 30%HIGH2023-08-02
Out of bounds read and write in WebGL in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4072
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-02
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4073
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-02
CVEs:CVE-2023-4073
Open SourceCoalition ESS < 30%CRITICAL2023-08-03
DEBIAN-CVE-2023-4075
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-02
Use after free in Cast in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4075
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-02
CVEs:CVE-2023-4075
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
Istio Authorization Bypass Vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
Istio Authorization Bypass Vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio.io |
istio.io/istio |
— |
| istio |
affected |
istio.io |
istio.io/istio |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-03
DEBIAN-CVE-2023-4074
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2023-08-02
CVEs:CVE-2023-4074
GoogleCoalition ESS < 30%CRITICAL2023-08-02
Use after free in Blink Task Scheduling in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4074
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-23
Updated docker-containerd packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| docker-containerd |
affected |
Mageia:8 |
docker-containerd |
— |
| golang-github-mrunalp-fileutils |
affected |
Mageia:8 |
golang-github-mrunalp-fileutils |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-15
Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-15
CVEs:CVE-2023-4353
Open SourceCoalition ESS < 30%CRITICAL2023-08-15
DEBIAN-CVE-2023-4353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-23
DEBIAN-CVE-2023-4431
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2023-08-22
Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4431
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2023-08-22
Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4431
GoogleCoalition ESS < 30%HIGH2023-08-22
CVEs:CVE-2023-4431
Open SourceCoalition ESS < 30%CRITICAL2023-08-03
DEBIAN-CVE-2023-4076
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-02
Use after free in WebRTC in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC session. (Chromium security severity: High)
CVEs:CVE-2023-4076
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-02
CVEs:CVE-2023-4076
Open SourceCoalition ESS < 30%CRITICAL2023-08-23
DEBIAN-CVE-2023-4429
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-22
Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4429
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-22
CVEs:CVE-2023-4429
Open SourceCoalition ESS < 30%HIGH2023-08-03
DEBIAN-CVE-2023-4077
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-03
DEBIAN-CVE-2023-4078
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2023-08-02
CVEs:CVE-2023-4077
GoogleCoalition ESS < 30%HIGH2023-08-02
Insufficient data validation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium sec...
CVEs:CVE-2023-4077
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-02
CVEs:CVE-2023-4078
GoogleCoalition ESS < 30%HIGH2023-08-02
Inappropriate implementation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium sec...
CVEs:CVE-2023-4078
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-15
CVEs:CVE-2023-4350
GoogleCoalition ESS < 30%MEDIUM2023-08-15
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4350
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2023-08-15
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4350
Open SourceCoalition ESS < 30%MEDIUM2023-08-15
DEBIAN-CVE-2023-4350
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-15
Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4356
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-15
CVEs:CVE-2023-4356
GoogleCoalition ESS < 30%HIGH2023-08-15
CVEs:CVE-2023-4358
GoogleCoalition ESS < 30%CRITICAL2023-08-15
Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4358
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-15
DEBIAN-CVE-2023-4356
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-15
DEBIAN-CVE-2023-4358
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-15
Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4351
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-15
CVEs:CVE-2023-4351
GoogleCoalition ESS < 30%2023-08-15
Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4351
Open SourceCoalition ESS < 30%CRITICAL2023-08-15
DEBIAN-CVE-2023-4351
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2023-08-15
CVEs:CVE-2023-4349
GoogleCoalition ESS < 30%CRITICAL2023-08-15
Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4349
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-15
DEBIAN-CVE-2023-4349
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-15
Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4361
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-15
CVEs:CVE-2023-4361
Open SourceCoalition ESS < 30%MEDIUM2023-08-15
DEBIAN-CVE-2023-4361
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-15
CVEs:CVE-2023-4359
GoogleCoalition ESS < 30%MEDIUM2023-08-15
Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed a remote attacker to potentially spoof elements of the security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-15
DEBIAN-CVE-2023-4359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-01
DEBIAN-CVE-2023-3730
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-15
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Med...
CVEs:CVE-2023-4368
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-15
CVEs:CVE-2023-4368
Open SourceCoalition ESS < 30%CRITICAL2023-08-15
DEBIAN-CVE-2023-4368
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2023-08-15
Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4363
GoogleCoalition ESS < 30%MEDIUM2023-08-15
CVEs:CVE-2023-4363
GoogleCoalition ESS < 30%MEDIUM2023-08-15
Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4363
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2023-08-15
Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4364
GoogleCoalition ESS < 30%MEDIUM2023-08-15
CVEs:CVE-2023-4364
GoogleCoalition ESS < 30%MEDIUM2023-08-15
Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4364
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-15
Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4365
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-15
CVEs:CVE-2023-4365
Open SourceCoalition ESS < 30%MEDIUM2023-08-15
DEBIAN-CVE-2023-4363
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-15
DEBIAN-CVE-2023-4364
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-15
DEBIAN-CVE-2023-4365
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2023-08-15
Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4360
GoogleCoalition ESS < 30%MEDIUM2023-08-15
Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4360
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-15
CVEs:CVE-2023-4360
Open SourceCoalition ESS < 30%MEDIUM2023-08-15
DEBIAN-CVE-2023-4360
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-15
Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4366
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-15
CVEs:CVE-2023-4366
GoogleCoalition ESS < 30%2023-08-15
Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4366
Open SourceCoalition ESS < 30%CRITICAL2023-08-15
DEBIAN-CVE-2023-4366
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-15
CVEs:CVE-2023-4367
GoogleCoalition ESS < 30%CRITICAL2023-08-15
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Med...
CVEs:CVE-2023-4367
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-15
DEBIAN-CVE-2023-4367
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-01
DEBIAN-CVE-2023-3734
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-01
DEBIAN-CVE-2023-3733
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-01
DEBIAN-CVE-2023-3737
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2023-08-01
ASB-A-227655299
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-01
DEBIAN-CVE-2023-3740
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-08-07
In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User in...
CVEs:CVE-2023-21242
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-07
CVEs:CVE-2023-21242
Open SourceCoalition ESS < 30%MEDIUM2023-08-01
DEBIAN-CVE-2023-3738
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-07
CVEs:CVE-2023-21287
Open SourceCoalition ESS < 30%CRITICAL2023-08-07
In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21287
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-25
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
CVEs:CVE-2019-13690
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-25
CVEs:CVE-2019-13690
Open SourceCoalition ESS < 30%HIGH2023-08-07
In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21233
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-07
CVEs:CVE-2023-21233
GoogleCoalition ESS < 30%HIGH2023-08-01
ASB-A-174737879
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-01
Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chromium securi...
CVEs:CVE-2023-3729
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-01
CVEs:CVE-2023-3729
GoogleCoalition ESS < 30%HIGH2023-08-01
CVEs:CVE-2023-3731
GoogleCoalition ESS < 30%CRITICAL2023-08-01
Use after free in Diagnostics in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security sever...
CVEs:CVE-2023-3731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-07
CVEs:CVE-2023-21265
Open SourceCoalition ESS < 30%HIGH2023-08-07
In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21265
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-04
DEBIAN-CVE-2022-4955
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2023-08-25
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)
CVEs:CVE-2019-13689
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-25
CVEs:CVE-2019-13689
Open SourceCoalition ESS < 30%HIGH2023-08-23
Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| github.com/nmstate/kubernetes-nmstate |
affected |
Go |
github.com/nmstate/kubernetes-nmstate |
— |
| nmstate/kubernetes-nmstate |
affected |
github.com |
github.com/nmstate/kubernetes-nmstate |
— |
| nmstate/kubernetes-nmstate |
affected |
github.com |
github.com/nmstate/kubernetes-nmstate |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-23
Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| nmstate/kubernetes-nmstate |
affected |
github.com |
github.com/nmstate/kubernetes-nmstate |
— |
GoogleCoalition ESS < 30%HIGH2023-08-07
CVEs:CVE-2023-21273
Open SourceCoalition ESS < 30%HIGH2023-08-07
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-21273
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-08-21
Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XSS) bug. We recommend upgrading to version 0.0.20 of the extension.
CVEs:CVE-2023-3481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| critters |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-11
Critters Cross-site Scripting Vulnerability
CVEs:CVE-2023-3481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| critters |
affected |
npm |
critters |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-11
Critters Cross-site Scripting Vulnerability
CVEs:CVE-2023-3481
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| critters |
affected |
npm |
critters |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21132
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset wi...
CVEs:CVE-2023-21132
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset wi...
CVEs:CVE-2023-21133
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21133
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21134
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset wi...
CVEs:CVE-2023-21134
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset wi...
CVEs:CVE-2023-21140
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21140
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n...
CVEs:CVE-2023-21264
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2023-08-07
In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21264
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21264
GoogleCoalition ESS < 30%NONE2023-08-01
ASB-A-279739439
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20797
Open SourceCoalition ESS < 30%HIGH2023-08-07
In camera middleware, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS076295...
CVEs:CVE-2023-20797
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2023-08-01
PUB-A-268066858
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for ex...
CVEs:CVE-2023-21283
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21283
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20780
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; I...
CVEs:CVE-2023-20780
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2023-08-01
ASB-A-285686353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. Us...
CVEs:CVE-2023-21267
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21267
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2023-21274
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21274
Open SourceCoalition ESS < 30%HIGH2023-08-07
In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not ...
CVEs:CVE-2023-21268
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21268
Open SourceCoalition ESS < 30%HIGH2023-08-07
In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ...
CVEs:CVE-2023-20802
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20802
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20800
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420955.
CVEs:CVE-2023-20800
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. Use...
CVEs:CVE-2023-21229
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-07
CVEs:CVE-2023-21229
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21276
Open SourceCoalition ESS < 30%HIGH2023-08-07
In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21276
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2023-21277
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21277
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In visitUris of RemoteViews.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21279
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21279
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted files due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User in...
CVEs:CVE-2023-21292
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21292
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20806
Open SourceCoalition ESS < 30%HIGH2023-08-07
In hcp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340433; Issue ID: ...
CVEs:CVE-2023-20806
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20807
Open SourceCoalition ESS < 30%HIGH2023-08-07
In dpe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608433; Issue ID: ...
CVEs:CVE-2023-20807
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453560...
CVEs:CVE-2023-20814
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20814
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20815
Open SourceCoalition ESS < 30%HIGH2023-08-07
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453587...
CVEs:CVE-2023-20815
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20816
Open SourceCoalition ESS < 30%HIGH2023-08-07
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453589...
CVEs:CVE-2023-20816
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20817
Open SourceCoalition ESS < 30%HIGH2023-08-07
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453600...
CVEs:CVE-2023-20817
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20795
Open SourceCoalition ESS < 30%HIGH2023-08-07
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07864900; Issue ID: ...
CVEs:CVE-2023-20795
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20804
Open SourceCoalition ESS < 30%HIGH2023-08-07
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue I...
CVEs:CVE-2023-20804
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue I...
CVEs:CVE-2023-20805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20805
Open SourceCoalition ESS < 30%HIGH2023-08-07
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767811; Issue ID: ...
CVEs:CVE-2023-20786
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20786
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20803
Open SourceCoalition ESS < 30%HIGH2023-08-07
In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ...
CVEs:CVE-2023-20803
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-07
CVEs:CVE-2023-21235
Open SourceCoalition ESS < 30%HIGH2023-08-07
In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without entering the existing PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. U...
CVEs:CVE-2023-21235
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2023-21271
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21271
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2023-21289
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21289
GoogleCoalition ESS < 30%HIGH2023-08-07
CVEs:CVE-2023-35689
Open SourceCoalition ESS < 30%HIGH2023-08-07
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. Us...
CVEs:CVE-2023-35689
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20811
Open SourceCoalition ESS < 30%HIGH2023-08-07
In IOMMU, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issue ID:...
CVEs:CVE-2023-20811
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453549; ...
CVEs:CVE-2023-20813
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20813
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20818
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07460540; ...
CVEs:CVE-2023-20818
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20798
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In pda, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07147...
CVEs:CVE-2023-20798
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07826905; Iss...
CVEs:CVE-2023-20783
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20783
Open SourceCoalition ESS < 30%HIGH2023-08-07
In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07826989; Iss...
CVEs:CVE-2023-20784
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20784
Open SourceCoalition ESS < 30%HIGH2023-08-07
In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2023-21280
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21280
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20810
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In IOMMU, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issu...
CVEs:CVE-2023-20810
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20812
Open SourceCoalition ESS < 30%HIGH2023-08-07
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944987; ...
CVEs:CVE-2023-20812
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In jpeg, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07693193; Issue I...
CVEs:CVE-2023-20789
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20789
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20790
Open SourceCoalition ESS < 30%HIGH2023-08-07
In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07740194; Issue ID:...
CVEs:CVE-2023-20790
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| rdk-b |
affected |
rdkcentral |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20782
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07550104; I...
CVEs:CVE-2023-20782
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2022-47351
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2022-47351
Open SourceCoalition ESS < 30%HIGH2023-08-07
In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2022-47350
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2022-47350
Open SourceCoalition ESS < 30%HIGH2023-08-07
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...
CVEs:CVE-2023-21269
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-08-07
CVEs:CVE-2023-21269
Open SourceCoalition ESS < 30%HIGH2023-08-07
In OPTEE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03645895; Issue ID:...
CVEs:CVE-2023-20808
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20808
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20809
Open SourceCoalition ESS < 30%HIGH2023-08-07
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03751198; Issue ID: ...
CVEs:CVE-2023-20809
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-08-07
CVEs:CVE-2023-21278
Open SourceCoalition ESS < 30%LOW2023-08-07
In multiple locations, there is a possible way to obscure the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2023-21278
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20793
Open SourceCoalition ESS < 30%HIGH2023-08-07
In apu, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767818; Issue ID: ALPS0776...
CVEs:CVE-2023-20793
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20796
Open SourceCoalition ESS < 30%HIGH2023-08-07
In power, there is a possible memory corruption due to an incorrect bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929790; Issue ID: ALP...
CVEs:CVE-2023-20796
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| rdk-b |
affected |
rdkcentral |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In keyinstall, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; Issue ID: A...
CVEs:CVE-2023-20781
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20781
GoogleCoalition ESS < 30%HIGH2023-08-07
CVEs:CVE-2023-21270
Open SourceCoalition ESS < 30%HIGH2023-08-07
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege w...
CVEs:CVE-2023-21270
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition check failure. This could lead to local information d...
CVEs:CVE-2023-21230
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21230
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2023-21232
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-08-07
CVEs:CVE-2023-21232
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-33906
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-33907
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-33910
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-33911
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-33912
Open SourceCoalition ESS < 30%HIGH2023-08-07
In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-33912
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-33910
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-33911
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-33906
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-33907
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21234
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check. This could lead to local escalation of privilege with no additional execut...
CVEs:CVE-2023-21234
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-21290
Open SourceCoalition ESS < 30%MEDIUM2023-08-07
In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21290
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20787
Open SourceCoalition ESS < 30%HIGH2023-08-07
In thermal, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648734; Issue ID: ALPS076...
CVEs:CVE-2023-20787
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-08-07
In thermal, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648734; Issue ID: ALPS076...
CVEs:CVE-2023-20788
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20788
Open SourceCoalition ESS < 30%HIGH2023-08-07
In imgsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS074...
CVEs:CVE-2023-20801
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20801
Open SourceCoalition ESS < 30%HIGH2023-08-07
In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628524; Issue ID...
CVEs:CVE-2023-20785
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-08-07
CVEs:CVE-2023-20785
Open SourceEPSS <= 49%HIGH2023-08-01
DEBIAN-CVE-2023-3732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleEPSS <= 49%CRITICAL2023-08-15
Use after free in Offline in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-2312
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2023-08-15
CVEs:CVE-2023-2312
Open SourceEPSS <= 49%CRITICAL2023-08-15
DEBIAN-CVE-2023-2312
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceEPSS <= 49%CRITICAL2023-08-01
DEBIAN-CVE-2023-3728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceEPSS <= 49%CRITICAL2023-08-01
DEBIAN-CVE-2023-3727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceEPSS <= 49%MEDIUM2023-08-01
DEBIAN-CVE-2023-3736
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceEPSS <= 49%MEDIUM2023-08-01
DEBIAN-CVE-2023-3735
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceEPSS <= 49%HIGH2023-08-11
Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| intel-tensorflow |
affected |
PyPI |
intel-tensorflow |
— |
| intel-tensorflow-avx512 |
affected |
PyPI |
intel-tensorflow-avx512 |
— |
| tensorflow-intel |
affected |
PyPI |
tensorflow-intel |
— |
Open SourceEPSS <= 49%HIGH2023-08-11
Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| intel-tensorflow |
affected |
PyPI |
intel-tensorflow |
— |
| intel-tensorflow |
affected |
PyPI |
intel-tensorflow |
— |
| intel-tensorflow-avx512 |
affected |
PyPI |
intel-tensorflow-avx512 |
— |
| intel-tensorflow-avx512 |
affected |
PyPI |
intel-tensorflow-avx512 |
— |
| tensorflow-intel |
affected |
PyPI |
tensorflow-intel |
— |
| tensorflow-intel |
affected |
PyPI |
tensorflow-intel |
— |
Open SourceEPSS <= 49%HIGH2023-08-11
Improper buffer restrictions in the Intel(R) Optimization for Tensorflow software before version 2.12 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVEs:CVE-2023-27506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| optimization_for_tensorflow |
affected |
intel |
— |
— |
Open SourceEPSS <= 49%HIGH2023-08-11
Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
CVEs:CVE-2023-27506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| intel-tensorflow |
affected |
PyPI |
intel-tensorflow |
— |
| intel-tensorflow-avx512 |
affected |
PyPI |
intel-tensorflow-avx512 |
— |
| tensorflow-intel |
affected |
PyPI |
tensorflow-intel |
— |
Open SourceEPSS <= 49%MEDIUM2023-08-11
Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
CVEs:CVE-2023-27506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| intel-tensorflow |
affected |
PyPI |
intel-tensorflow |
— |
| intel-tensorflow-avx512 |
affected |
PyPI |
intel-tensorflow-avx512 |
— |
| tensorflow-intel |
affected |
PyPI |
tensorflow-intel |
— |