Google Security Advisories · August 2023 — Google Security Advisories
473 advisories 275 CVEs 3 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2023-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2023-38831

Project ZeroExploitedCISA KEV listed2023-08-17

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

CVEs:CVE-2023-38831

Upstream advisory

CVE-2023-38831

GoogleExploitedCISA KEV listedCRITICAL2023-08-17

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder tha...

CVEs:CVE-2023-38831

Affected products

ProductStatusVendorPackageEcosystem
winrar affected rarlab
Upstream advisory

openSUSE-SU-2023:0234-1

Open SourceWeaponized exploitCRITICAL2023-08-21

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DSA-5479-1

Open SourceWeaponized exploit2023-08-17

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2023-4352

GoogleWeaponized exploit2023-08-15

Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4352

Upstream advisory

CVE-2023-4352

GoogleWeaponized exploitHIGH2023-08-15

Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4352

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4352

Open SourceWeaponized exploitHIGH2023-08-15

DEBIAN-CVE-2023-4352

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-3893

GoogleActive exploitation (sightings)2023-08-23

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.

CVEs:CVE-2023-3893

Upstream advisory

CVE-2023-3893

Open SourceActive exploitation (sightings)HIGH2023-08-23

Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation

CVEs:CVE-2023-3893

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-csi/csi-proxy affected github.com github.com/kubernetes-csi/csi-proxy
kubernetes-csi/csi-proxy/v2 affected github.com github.com/kubernetes-csi/csi-proxy/v2
Upstream advisory

CVE-2023-3893

GoogleActive exploitation (sightings)HIGH2023-08-23

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows n...

CVEs:CVE-2023-3893

Affected products

ProductStatusVendorPackageEcosystem
csi_proxy affected kubernetes
Upstream advisory

DSA-5487-1

Open SourceActive exploitation (sightings)2023-08-31

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2023-4572

Open SourceActive exploitation (sightings)CRITICAL2023-08-29

DEBIAN-CVE-2023-4572

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4572

GoogleActive exploitation (sightings)CRITICAL2023-08-29

Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4572

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

GHSA-x92r-3vfx-4cv3

Open SourceActive exploitation (sightings)MEDIUM2023-08-02

Golang TIFF decoder does not place a limit on the size of compressed tile data

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

GHSA-x92r-3vfx-4cv3

Open SourceActive exploitation (sightings)MEDIUM2023-08-02

Golang TIFF decoder does not place a limit on the size of compressed tile data

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

DEBIAN-CVE-2023-29408

Open SourceActive exploitation (sightings)MEDIUM2023-08-02

DEBIAN-CVE-2023-29408

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-image affected Debian:11 golang-golang-x-image
golang-golang-x-image affected Debian:12 golang-golang-x-image
golang-golang-x-image affected Debian:13 golang-golang-x-image
golang-golang-x-image affected Debian:14 golang-golang-x-image
Upstream advisory

GO-2023-1989

Open SourceActive exploitation (sightings)CRITICAL2023-08-02

Excessive resource consumption in golang.org/x/image/tiff

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

CVE-2023-29408

GoogleActive exploitation (sightings)MEDIUM2023-08-01

The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compres...

CVEs:CVE-2023-29408

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
image affected golang
Upstream advisory

CVE-2023-29408

Open SourceActive exploitation (sightings)MEDIUM2023-08-01

Golang TIFF decoder does not place a limit on the size of compressed tile data

CVEs:CVE-2023-29408

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

CVE-2023-29408

GoogleActive exploitation (sightings)2023-08-01

The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compressed data, consuming excessive memory and CPU.

CVEs:CVE-2023-29408

Upstream advisory

CVE-2023-30699

Open SourceActive exploitation (sightings)CRITICAL2023-08-07

Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

CVEs:CVE-2023-30699

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-33913

Open SourceActive exploitation (sightings)CRITICAL2023-08-07

In DRM/oemcrypto, there is a possible out of bounds write due to an incorrect calculation of buffer size.This could lead to remote escalation of privilege with System execution privileges needed

CVEs:CVE-2023-33913

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30877

GoogleActive exploitation (sightings)CRITICAL2023-08-17

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov XML for Google Merchant Center plugin <= 3.0.1 versions.

CVEs:CVE-2023-30877

Affected products

ProductStatusVendorPackageEcosystem
xml_for_google_merchant_center affected icopydoc
Upstream advisory

CVE-2023-34180

GoogleActive exploitation (sightings)CRITICAL2023-08-30

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in KAPlugins Google Fonts For WordPress plugin <= 3.0.0 versions.

CVEs:CVE-2023-34180

Affected products

ProductStatusVendorPackageEcosystem
free-google-fonts affected kaplugins
Upstream advisory

CVE-2023-4369

GoogleActive exploitation (sightings)HIGH2023-08-15

Insufficient data validation in Systems Extensions in Google Chrome on ChromeOS prior to 116.0.5845.120 allowed an attacker who convinced a user to install a malicious extension to bypass file restrictions via a crafted HTML page. (Chromium security se...

CVEs:CVE-2023-4369

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-30693

Open SourceActive exploitation (sightings)HIGH2023-08-07

Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-30693

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30686

Open SourceActive exploitation (sightings)HIGH2023-08-07

Out-of-bounds Write in ReqDataRaw of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-30686

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30687

Open SourceActive exploitation (sightings)HIGH2023-08-07

Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-30687

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30688

Open SourceActive exploitation (sightings)HIGH2023-08-07

Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-30688

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30689

Open SourceActive exploitation (sightings)HIGH2023-08-07

Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-30689

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30694

Open SourceActive exploitation (sightings)HIGH2023-08-07

Out-of-bounds Write in IpcTxPcscTransmitApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2023-30694

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30681

Open SourceActive exploitation (sightings)CRITICAL2023-08-07

An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

CVEs:CVE-2023-30681

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30696

Open SourceActive exploitation (sightings)CRITICAL2023-08-07

An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

CVEs:CVE-2023-30696

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30697

Open SourceActive exploitation (sightings)CRITICAL2023-08-07

An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

CVEs:CVE-2023-30697

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30680

Open SourceActive exploitation (sightings)CRITICAL2023-08-07

Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

CVEs:CVE-2023-30680

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30691

Open SourceActive exploitation (sightings)HIGH2023-08-07

Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.

CVEs:CVE-2023-30691

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30654

Open SourceActive exploitation (sightings)MEDIUM2023-08-07

Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to update fake location.

CVEs:CVE-2023-30654

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30685

Open SourceActive exploitation (sightings)HIGH2023-08-07

Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.

CVEs:CVE-2023-30685

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30698

Open SourceActive exploitation (sightings)MEDIUM2023-08-07

Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.

CVEs:CVE-2023-30698

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30700

Open SourceActive exploitation (sightings)MEDIUM2023-08-07

PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.

CVEs:CVE-2023-30700

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30682

Open SourceActive exploitation (sightings)MEDIUM2023-08-07

Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.

CVEs:CVE-2023-30682

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30683

Open SourceActive exploitation (sightings)MEDIUM2023-08-07

Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.

CVEs:CVE-2023-30683

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30684

Open SourceActive exploitation (sightings)MEDIUM2023-08-07

Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.

CVEs:CVE-2023-30684

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30679

Open SourceActive exploitation (sightings)HIGH2023-08-07

Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.

CVEs:CVE-2023-30679

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30701

Open SourceActive exploitation (sightings)MEDIUM2023-08-07

PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.

CVEs:CVE-2023-30701

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-21231

Open SourceActive exploitation (sightings)HIGH2023-08-07

In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-exported or permission-protected activity due to a missing permission check. This could lead to local escalation of privilege with no ad...

CVEs:CVE-2023-21231

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33908

Open SourceActive exploitation (sightings)HIGH2023-08-07

In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-33908

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33909

Open SourceActive exploitation (sightings)HIGH2023-08-07

In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-33909

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-4357

GooglePoC exploitHIGH2023-08-15

Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4357

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4357

Open SourcePoC exploitHIGH2023-08-15

DEBIAN-CVE-2023-4357

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2023:0237-1

Open SourcePoC exploitCRITICAL2023-08-28

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DSA-5483-1

Open SourcePoC exploit2023-08-25

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-4427

Open SourcePoC exploitHIGH2023-08-23

DEBIAN-CVE-2023-4427

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4427

GooglePoC exploitHIGH2023-08-22

Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4427

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

openSUSE-SU-2023:0216-1

Open SourcePoC exploitCRITICAL2023-08-07

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DSA-5467-1

Open SourcePoC exploit2023-08-04

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-4069

Open SourcePoC exploitHIGH2023-08-03

DEBIAN-CVE-2023-4069

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4069

GooglePoC exploitHIGH2023-08-02

Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4069

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-4068

Open SourcePoC exploitHIGH2023-08-03

DEBIAN-CVE-2023-4068

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4068

GooglePoC exploitHIGH2023-08-02

Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4068

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-3676

Open SourcePoC exploitHIGH2023-08-23

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

CVEs:CVE-2023-3676

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2023-3676

GooglePoC exploit2023-08-23

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

CVEs:CVE-2023-3676

Upstream advisory

CVE-2023-3676

Open SourcePoC exploitHIGH2023-08-23

Kubernetes privilege escalation vulnerability

CVEs:CVE-2023-3676

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2023-3955

Open SourcePoC exploitHIGH2023-08-23

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

CVEs:CVE-2023-3955

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2023-3955

GooglePoC exploit2023-08-23

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

CVEs:CVE-2023-3955

Upstream advisory

CVE-2023-3955

Open SourcePoC exploitHIGH2023-08-23

Kubernetes privilege escalation vulnerability

CVEs:CVE-2023-3955

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

SUSE-SU-2023:3260-1

Open SourcePoC exploitCRITICAL2023-08-10

Security update for kubernetes1.24

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.24 affected SUSE:Linux Enterprise Module for Containers 15 SP4 kubernetes1.24
kubernetes1.24 affected openSUSE:Leap 15.4 kubernetes1.24
Upstream advisory

OESA-2023-1499

Open SourcePoC exploitCRITICAL2023-08-12

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS-SP2 golang
Upstream advisory

OESA-2023-1530

Open SourcePoC exploitNONE2023-08-26

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS golang
Upstream advisory

OESA-2023-1531

Open SourcePoC exploitNONE2023-08-26

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS-SP2 golang
Upstream advisory

OESA-2023-1532

Open SourcePoC exploitNONE2023-08-26

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
Upstream advisory

OESA-2023-1533

Open SourcePoC exploitNONE2023-08-26

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP3 golang
Upstream advisory

SUSE-SU-2023:3263-1

GooglePoC exploit2023-08-10

Security update for go1.19

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
go1.19 affected SUSE:Linux Enterprise Module for Development Tools 15 SP5 go1.19
go1.19 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS go1.19
go1.19 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS go1.19
go1.19 affected SUSE:Linux Enterprise Server 15 SP3-LTSS go1.19
go1.19 affected SUSE:Linux Enterprise Module for Development Tools 15 SP4 go1.19
go1.19 affected SUSE:Enterprise Storage 7.1 go1.19
go1.19 affected openSUSE:Leap 15.4 go1.19
go1.19 affected openSUSE:Leap 15.5 go1.19
go1.19 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 go1.19
Upstream advisory

AZL-27812

Open SourcePoC exploitMEDIUM2023-08-02

CVE-2023-29409 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-27814

Open SourcePoC exploitMEDIUM2023-08-02

CVE-2023-29409 affecting package msft-golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37302

Open SourcePoC exploitMEDIUM2023-08-02

CVE-2023-29409 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37344

Open SourcePoC exploitMEDIUM2023-08-02

CVE-2023-29409 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-52881

Open SourcePoC exploitMEDIUM2023-08-02

CVE-2023-29409 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-79008

Open SourcePoC exploitMEDIUM2023-08-02

CVE-2023-29409 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-29409

Open SourcePoC exploitMEDIUM2023-08-02

DEBIAN-CVE-2023-29409

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2023-29409

GooglePoC exploit2023-08-02

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.

CVEs:CVE-2023-29409

Upstream advisory

CVE-2023-29409

GooglePoC exploitMEDIUM2023-08-02

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trus...

CVEs:CVE-2023-29409

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2023-1987

Open SourcePoC exploitNONE2023-08-02

Large RSA keys can cause high CPU usage in crypto/tls

Affected products

ProductStatusVendorPackageEcosystem
go-1.20 affected wolfi go-1.20
go-1.20 affected chainguard go-1.20
go-1.21 affected wolfi go-1.21
go-1.21 affected chainguard go-1.21
kind affected wolfi kind
kind affected chainguard kind
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

OESA-2023-1500

Open SourcePoC exploit2023-08-12

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
Upstream advisory

OESA-2023-1501

Open SourcePoC exploit2023-08-12

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP3 golang
Upstream advisory

OESA-2023-1502

Open SourcePoC exploit2023-08-12

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS golang
Upstream advisory

OESA-2023-1498

Open SourcePoC exploit2023-08-12

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS-SP1 golang
Upstream advisory

DEBIAN-CVE-2023-4070

Open SourcePoC exploitHIGH2023-08-03

DEBIAN-CVE-2023-4070

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4070

GooglePoC exploitHIGH2023-08-02

Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4070

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-21282

Open SourcePoC exploitHIGH2023-08-07

In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2023-21282

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-j3p8-6mrq-6g7h

Open SourcePoC exploitMEDIUM2023-08-02

Golang TIFF decoder vulnerable to excessive CPU consumption

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

GHSA-j3p8-6mrq-6g7h

Open SourcePoC exploitMEDIUM2023-08-02

Golang TIFF decoder vulnerable to excessive CPU consumption

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

DEBIAN-CVE-2023-29407

Open SourcePoC exploitMEDIUM2023-08-02

DEBIAN-CVE-2023-29407

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-image affected Debian:11 golang-golang-x-image
golang-golang-x-image affected Debian:12 golang-golang-x-image
golang-golang-x-image affected Debian:13 golang-golang-x-image
golang-golang-x-image affected Debian:14 golang-golang-x-image
Upstream advisory

GO-2023-1990

Open SourcePoC exploit2023-08-02

Excessive CPU consumption when decoding 0-height images in golang.org/x/image/tiff

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

CVE-2023-29407

Open SourcePoC exploitMEDIUM2023-08-01

Golang TIFF decoder vulnerable to excessive CPU consumption

CVEs:CVE-2023-29407

Affected products

ProductStatusVendorPackageEcosystem
x/image affected golang.org golang.org/x/image
Upstream advisory

CVE-2023-29407

GooglePoC exploitMEDIUM2023-08-01

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

CVEs:CVE-2023-29407

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
image affected golang
Upstream advisory

CVE-2023-29407

GooglePoC exploit2023-08-01

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

CVEs:CVE-2023-29407

Upstream advisory

GHSA-2wrh-6pvc-2jm9

Open SourcePoC exploitCRITICAL2023-08-02

Improper rendering of text nodes in golang.org/x/net/html

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-2wrh-6pvc-2jm9

Open SourcePoC exploitCRITICAL2023-08-02

Improper rendering of text nodes in golang.org/x/net/html

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
apko affected chainguard apko
apko affected wolfi apko
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.8 affected wolfi argo-cd-2.8
aws-ebs-csi-driver affected wolfi aws-ebs-csi-driver
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller-2.4.5 affected chainguard aws-load-balancer-controller-2.4.5
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bom affected wolfi bom
bom affected chainguard bom
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
cloud-sql-proxy affected wolfi cloud-sql-proxy
cloud-sql-proxy affected chainguard cloud-sql-proxy
cluster-autoscaler-1.25 affected chainguard cluster-autoscaler-1.25
cluster-autoscaler-1.25 affected wolfi cluster-autoscaler-1.25
cluster-autoscaler-fips-1.25 affected chainguard cluster-autoscaler-fips-1.25
cluster-autoscaler-fips-1.26 affected chainguard cluster-autoscaler-fips-1.26
cluster-autoscaler-fips-1.27 affected chainguard cluster-autoscaler-fips-1.27
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
consul-1.15 affected wolfi consul-1.15
consul-1.15 affected chainguard consul-1.15
consul-1.16 affected wolfi consul-1.16
consul-1.16 affected chainguard consul-1.16
containerd affected chainguard containerd
containerd affected wolfi containerd
coredns affected chainguard coredns
coredns affected wolfi coredns
cosign affected chainguard cosign
cosign affected wolfi cosign
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure affected wolfi crossplane-provider-azure
cue affected chainguard cue
cue affected wolfi cue
dex affected wolfi dex
dex affected chainguard dex
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
dive affected wolfi dive
dive affected chainguard dive
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
external-dns affected chainguard external-dns
external-dns affected wolfi external-dns
external-dns-fips affected chainguard external-dns-fips
external-secrets-0.7 affected chainguard external-secrets-0.7
external-secrets-operator affected wolfi external-secrets-operator
external-secrets-operator affected chainguard external-secrets-operator
falcoctl affected wolfi falcoctl
falcoctl affected chainguard falcoctl
flux affected wolfi flux
flux affected chainguard flux
flux-0 affected chainguard flux-0
flux-0.37 affected chainguard flux-0.37
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller-0 affected chainguard flux-helm-controller-0
flux-helm-controller-0.37 affected chainguard flux-helm-controller-0.37
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-image-reflector-controller-0 affected chainguard flux-image-reflector-controller-0
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller-0 affected chainguard flux-kustomize-controller-0
flux-kustomize-controller-0.37 affected chainguard flux-kustomize-controller-0.37
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller-0 affected chainguard flux-notification-controller-0
flux-notification-controller-0.37 affected chainguard flux-notification-controller-0.37
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller-0 affected chainguard flux-source-controller-0
flux-source-controller-0.37 affected chainguard flux-source-controller-0.37
frp affected wolfi frp
frp affected chainguard frp
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
gatekeeper-3.12 affected wolfi gatekeeper-3.12
gatekeeper-3.12 affected chainguard gatekeeper-3.12
gitlab-pages affected wolfi gitlab-pages
gitlab-pages affected chainguard gitlab-pages
gitlab-runner affected chainguard gitlab-runner
gitlab-runner affected wolfi gitlab-runner
git-lfs affected chainguard git-lfs
git-lfs affected wolfi git-lfs
gitness affected chainguard gitness
gitness affected wolfi gitness
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
gobuster affected wolfi gobuster
gobuster affected chainguard gobuster
gomplate affected chainguard gomplate
gomplate affected wolfi gomplate
goreleaser-1.18 affected wolfi goreleaser-1.18
goreleaser-1.18 affected chainguard goreleaser-1.18
grafana-9.3 affected chainguard grafana-9.3
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
haproxy-ingress affected wolfi haproxy-ingress
haproxy-ingress affected chainguard haproxy-ingress
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected wolfi helm-3
helm-3 affected chainguard helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
hey affected wolfi hey
hey affected chainguard hey
hugo affected chainguard hugo
hugo affected wolfi hugo
influxd affected wolfi influxd
influxd affected chainguard influxd
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected wolfi k3s
k3s affected chainguard k3s
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
k8sgpt-operator affected chainguard k8sgpt-operator
k8sgpt-operator affected wolfi k8sgpt-operator
kaf affected chainguard kaf
kaf affected wolfi kaf
karpenter affected chainguard karpenter
karpenter affected wolfi karpenter
karpenter-0.23 affected chainguard karpenter-0.23
keda-2.10 affected chainguard keda-2.10
keda-2.10 affected wolfi keda-2.10
keda-2.11 affected wolfi keda-2.11
keda-2.11 affected chainguard keda-2.11
keda-2.8 affected chainguard keda-2.8
keda-2.9 affected chainguard keda-2.9
kiam affected chainguard kiam
kots affected chainguard kots
kots affected wolfi kots
kpt affected chainguard kpt
kpt affected wolfi kpt
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kube-logging-operator affected chainguard kube-logging-operator
kube-logging-operator affected wolfi kube-logging-operator
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-csi-external-attacher-4.3 affected chainguard kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.3 affected wolfi kubernetes-csi-external-attacher-4.3
kubernetes-csi-external-attacher-4.4 affected wolfi kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-attacher-4.4 affected chainguard kubernetes-csi-external-attacher-4.4
kubernetes-csi-external-attacher-fips-4.3 affected chainguard kubernetes-csi-external-attacher-fips-4.3
kubernetes-csi-external-attacher-fips-4.4 affected chainguard kubernetes-csi-external-attacher-fips-4.4
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-external-resizer-1.8 affected chainguard kubernetes-csi-external-resizer-1.8
kubernetes-csi-external-resizer-fips-1.8 affected chainguard kubernetes-csi-external-resizer-fips-1.8
kubernetes-csi-external-snapshotter affected chainguard kubernetes-csi-external-snapshotter
kubernetes-csi-external-snapshotter affected wolfi kubernetes-csi-external-snapshotter
kubernetes-csi-external-snapshotter-6.0 affected chainguard kubernetes-csi-external-snapshotter-6.0
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-node-driver-registrar-2.9 affected chainguard kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-2.9 affected wolfi kubernetes-csi-node-driver-registrar-2.9
kubernetes-csi-node-driver-registrar-fips-2.8 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.8
kubernetes-csi-node-driver-registrar-fips-2.9 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.9
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kube-state-metrics-2.2.0 affected chainguard kube-state-metrics-2.2.0
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
kubewatch affected chainguard kubewatch
kubewatch affected wolfi kubewatch
kyverno affected chainguard kyverno
kyverno affected wolfi kyverno
kyverno-1.8 affected chainguard kyverno-1.8
kyverno-policy-reporter-2.11 affected chainguard kyverno-policy-reporter-2.11
kyverno-policy-reporter-kyverno-plugin-1.5 affected chainguard kyverno-policy-reporter-kyverno-plugin-1.5
mc affected wolfi mc
mc affected chainguard mc
memcached-exporter affected chainguard memcached-exporter
memcached-exporter affected wolfi memcached-exporter
metacontroller affected chainguard metacontroller
metacontroller affected wolfi metacontroller
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
minio affected chainguard minio
minio affected wolfi minio
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
node-problem-detector-0.8 affected wolfi node-problem-detector-0.8
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nri-prometheus affected wolfi nri-prometheus
nri-prometheus affected chainguard nri-prometheus
oauth2-proxy affected wolfi oauth2-proxy
oauth2-proxy affected chainguard oauth2-proxy
ollama affected chainguard ollama
ollama affected wolfi ollama
opentofu affected chainguard opentofu
opentofu affected wolfi opentofu
prometheus affected chainguard prometheus
prometheus affected wolfi prometheus
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-blackbox-exporter affected wolfi prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected wolfi prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter-fips affected chainguard prometheus-elasticsearch-exporter-fips
prometheus-fips affected chainguard prometheus-fips
prometheus-fips-2.38 affected chainguard prometheus-fips-2.38
prometheus-mongodb-exporter affected wolfi prometheus-mongodb-exporter
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter-fips affected chainguard prometheus-mongodb-exporter-fips
prometheus-mongodb-exporter-fips-0.37 affected chainguard prometheus-mongodb-exporter-fips-0.37
prometheus-mysqld-exporter affected wolfi prometheus-mysqld-exporter
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter affected wolfi prometheus-node-exporter
prometheus-node-exporter-1.5 affected chainguard prometheus-node-exporter-1.5
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-operator affected wolfi prometheus-operator
prometheus-operator affected chainguard prometheus-operator
prometheus-postgres-exporter affected wolfi prometheus-postgres-exporter
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-postgres-exporter-fips affected chainguard prometheus-postgres-exporter-fips
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
prometheus-pushgateway-fips-1.4 affected chainguard prometheus-pushgateway-fips-1.4
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected wolfi prometheus-statsd-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter-fips affected chainguard prometheus-statsd-exporter-fips
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-yaml affected chainguard pulumi-language-yaml
pulumi-language-yaml affected wolfi pulumi-language-yaml
rqlite affected wolfi rqlite
rqlite affected chainguard rqlite
runc affected wolfi runc
runc affected chainguard runc
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
sigstore-scaffolding affected wolfi sigstore-scaffolding
sigstore-scaffolding affected chainguard sigstore-scaffolding
skaffold affected wolfi skaffold
skaffold affected chainguard skaffold
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
src affected wolfi src
src affected chainguard src
stakater-reloader affected chainguard stakater-reloader
stakater-reloader affected wolfi stakater-reloader
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
tctl affected wolfi tctl
tctl affected chainguard tctl
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.26 affected wolfi telegraf-1.26
terraform affected chainguard terraform
terraform affected wolfi terraform
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
thanos-0.31 affected chainguard thanos-0.31
thanos-0.31 affected wolfi thanos-0.31
thanos-0.32 affected wolfi thanos-0.32
thanos-0.32 affected chainguard thanos-0.32
thanos-operator affected wolfi thanos-operator
thanos-operator affected chainguard thanos-operator
timoni affected chainguard timoni
timoni affected wolfi timoni
tkn affected chainguard tkn
tkn affected wolfi tkn
trillian affected chainguard trillian
trillian affected wolfi trillian
trust-manager affected chainguard trust-manager
trust-manager affected wolfi trust-manager
vault-1.13 affected wolfi vault-1.13
vault-1.13 affected chainguard vault-1.13
vault-csi-provider affected chainguard vault-csi-provider
vault-csi-provider affected wolfi vault-csi-provider
vault-k8s affected wolfi vault-k8s
vault-k8s affected chainguard vault-k8s
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
weaviate affected wolfi weaviate
weaviate affected chainguard weaviate
wireguard-go affected wolfi wireguard-go
wireguard-go affected chainguard wireguard-go
x/net affected golang.org golang.org/x/net
x/net affected golang.org
yq affected chainguard yq
yq affected wolfi yq
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

AZL-34542

Open SourcePoC exploitCRITICAL2023-08-02

CVE-2023-3978 affecting package application-gateway-kubernetes-ingress for versions less than 1.7.7-1

Affected products

ProductStatusVendorPackageEcosystem
application-gateway-kubernetes-ingress affected Azure Linux:3 application-gateway-kubernetes-ingress
Upstream advisory

DEBIAN-CVE-2023-3978

Open SourcePoC exploitCRITICAL2023-08-02

DEBIAN-CVE-2023-3978

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-net affected Debian:11 golang-golang-x-net
golang-golang-x-net affected Debian:12 golang-golang-x-net
golang-golang-x-net affected Debian:13 golang-golang-x-net
golang-golang-x-net affected Debian:14 golang-golang-x-net
Upstream advisory

GO-2023-1988

Open SourcePoC exploitCRITICAL2023-08-02

Improper rendering of text nodes in golang.org/x/net/html

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
apko affected chainguard apko
apko affected wolfi apko
aws-ebs-csi-driver affected chainguard aws-ebs-csi-driver
aws-efs-csi-driver affected chainguard aws-efs-csi-driver
aws-efs-csi-driver affected wolfi aws-efs-csi-driver
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bom affected wolfi bom
bom affected chainguard bom
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
cosign affected chainguard cosign
cosign affected wolfi cosign
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure affected wolfi crossplane-provider-azure
cue affected chainguard cue
cue affected wolfi cue
dex affected chainguard dex
dex affected wolfi dex
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
dive affected chainguard dive
dive affected wolfi dive
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
falcoctl affected wolfi falcoctl
falcoctl affected chainguard falcoctl
flux affected wolfi flux
flux affected chainguard flux
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
frp affected chainguard frp
frp affected wolfi frp
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
git-lfs affected chainguard git-lfs
git-lfs affected wolfi git-lfs
gitness affected chainguard gitness
gitness affected wolfi gitness
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gobuster affected wolfi gobuster
gobuster affected chainguard gobuster
gomplate affected wolfi gomplate
gomplate affected chainguard gomplate
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
haproxy-ingress affected wolfi haproxy-ingress
haproxy-ingress affected chainguard haproxy-ingress
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
hey affected chainguard hey
hey affected wolfi hey
hugo affected wolfi hugo
hugo affected chainguard hugo
k3d affected wolfi k3d
k3d affected chainguard k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
k8sgpt-operator affected wolfi k8sgpt-operator
k8sgpt-operator affected chainguard k8sgpt-operator
kaf affected wolfi kaf
kaf affected chainguard kaf
kiam affected chainguard kiam
kots affected chainguard kots
kots affected wolfi kots
kpt affected wolfi kpt
kpt affected chainguard kpt
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kube-logging-operator affected chainguard kube-logging-operator
kube-logging-operator affected wolfi kube-logging-operator
kube-oidc-proxy affected chainguard kube-oidc-proxy
kubernetes-csi-external-provisioner affected chainguard kubernetes-csi-external-provisioner
kubernetes-csi-external-provisioner affected wolfi kubernetes-csi-external-provisioner
kubernetes-csi-external-resizer affected wolfi kubernetes-csi-external-resizer
kubernetes-csi-external-resizer affected chainguard kubernetes-csi-external-resizer
kubernetes-csi-livenessprobe affected chainguard kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe affected wolfi kubernetes-csi-livenessprobe
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kubewatch affected wolfi kubewatch
kubewatch affected chainguard kubewatch
mc affected wolfi mc
mc affected chainguard mc
memcached-exporter affected chainguard memcached-exporter
memcached-exporter affected wolfi memcached-exporter
metacontroller affected chainguard metacontroller
metacontroller affected wolfi metacontroller
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
minio affected wolfi minio
minio affected chainguard minio
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
nri-prometheus affected wolfi nri-prometheus
nri-prometheus affected chainguard nri-prometheus
oauth2-proxy affected wolfi oauth2-proxy
oauth2-proxy affected chainguard oauth2-proxy
ollama affected chainguard ollama
ollama affected wolfi ollama
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter affected chainguard prometheus-elasticsearch-exporter
prometheus-elasticsearch-exporter-fips affected chainguard prometheus-elasticsearch-exporter-fips
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter-fips affected chainguard prometheus-mongodb-exporter-fips
prometheus-mongodb-exporter-fips-0.37 affected chainguard prometheus-mongodb-exporter-fips-0.37
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter-1.5 affected chainguard prometheus-node-exporter-1.5
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-operator affected chainguard prometheus-operator
prometheus-operator affected wolfi prometheus-operator
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-postgres-exporter-fips affected chainguard prometheus-postgres-exporter-fips
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
prometheus-pushgateway-fips-1.4 affected chainguard prometheus-pushgateway-fips-1.4
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter-fips affected chainguard prometheus-statsd-exporter-fips
pulumi affected chainguard pulumi
pulumi affected wolfi pulumi
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-yaml affected wolfi pulumi-language-yaml
pulumi-language-yaml affected chainguard pulumi-language-yaml
rqlite affected wolfi rqlite
rqlite affected chainguard rqlite
runc affected wolfi runc
runc affected chainguard runc
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver-provider-gcp affected chainguard secrets-store-csi-driver-provider-gcp
secrets-store-csi-driver-provider-gcp affected wolfi secrets-store-csi-driver-provider-gcp
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
src affected wolfi src
src affected chainguard src
stakater-reloader affected chainguard stakater-reloader
stakater-reloader affected wolfi stakater-reloader
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
terraform affected chainguard terraform
terraform affected wolfi terraform
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
thanos-operator affected wolfi thanos-operator
thanos-operator affected chainguard thanos-operator
timoni affected wolfi timoni
timoni affected chainguard timoni
tkn affected wolfi tkn
tkn affected chainguard tkn
trillian affected wolfi trillian
trillian affected chainguard trillian
trust-manager affected wolfi trust-manager
trust-manager affected chainguard trust-manager
vault-csi-provider affected chainguard vault-csi-provider
vault-k8s affected chainguard vault-k8s
vault-k8s affected wolfi vault-k8s
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
volume-modifier-for-k8s-fips affected chainguard volume-modifier-for-k8s-fips
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
weaviate affected chainguard weaviate
weaviate affected wolfi weaviate
wireguard-go affected chainguard wireguard-go
wireguard-go affected wolfi wireguard-go
x/net affected golang.org golang.org/x/net
yq affected wolfi yq
yq affected chainguard yq
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

CVE-2023-3978

GooglePoC exploitCRITICAL2023-08-01

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

CVEs:CVE-2023-3978

Affected products

ProductStatusVendorPackageEcosystem
networking affected golang
Upstream advisory

CVE-2023-3978

Open SourcePoC exploitMEDIUM2023-08-01

Improper rendering of text nodes in golang.org/x/net/html

CVEs:CVE-2023-3978

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2023-3978

Open SourcePoC exploitMEDIUM2023-08-01

Improper rendering of text nodes in golang.org/x/net/html

CVEs:CVE-2023-3978

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2023-4785

Open SourcePoC exploitHIGH2023-08-09

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

CVEs:CVE-2023-4785

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
Upstream advisory

CVE-2023-4785

Open SourcePoC exploitHIGH2023-08-09

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC ...

CVEs:CVE-2023-4785

Affected products

ProductStatusVendorPackageEcosystem
grpc affected grpc
Upstream advisory

CVE-2023-4785

Open SourcePoC exploitHIGH2023-08-09

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

CVEs:CVE-2023-4785

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
Upstream advisory

GHSA-496j-2rq6-j6cc

Open SourcePoC exploitHIGH2023-08-09

Excessive Iteration in gRPC

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
grpcio affected PyPI grpcio
Upstream advisory

GHSA-496j-2rq6-j6cc

Open SourcePoC exploitHIGH2023-08-09

Excessive Iteration in gRPC

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
Upstream advisory

AZL-27911

Open SourcePoC exploitHIGH2023-08-09

CVE-2023-33953 affecting package grpc 1.42.0-11

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Azure Linux:2 grpc
Upstream advisory

AZL-34770

Open SourcePoC exploitHIGH2023-08-09

CVE-2023-33953 affecting package grpc for versions less than 1.62.0-2

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Azure Linux:3 grpc
Upstream advisory

DEBIAN-CVE-2023-33953

Open SourcePoC exploitHIGH2023-08-09

DEBIAN-CVE-2023-33953

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Debian:13 grpc
grpc affected Debian:11 grpc
grpc affected Debian:12 grpc
grpc affected Debian:14 grpc
Upstream advisory

CVE-2023-33953

Open SourcePoC exploitHIGH2023-08-09

Excessive Iteration in gRPC

CVEs:CVE-2023-33953

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
Upstream advisory

CVE-2023-33953

Open SourcePoC exploitHIGH2023-08-09

Excessive Iteration in gRPC

CVEs:CVE-2023-33953

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
Upstream advisory

CVE-2023-33953

Open SourcePoC exploitHIGH2023-08-09

gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks: - Unbounded memory buffering i...

CVEs:CVE-2023-33953

Affected products

ProductStatusVendorPackageEcosystem
grpc affected grpc
Upstream advisory

CVE-2023-3739

GooglePoC exploit2023-08-01

Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low)

CVEs:CVE-2023-3739

Upstream advisory

CVE-2023-3739

GooglePoC exploitCRITICAL2023-08-01

Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low)

CVEs:CVE-2023-3739

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-3739

Open SourcePoC exploitCRITICAL2023-08-01

DEBIAN-CVE-2023-3739

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-21275

Open SourcePoC exploitHIGH2023-08-07

In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr...

CVEs:CVE-2023-21275

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21281

Open SourcePoC exploitHIGH2023-08-07

In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a logic error in the code. This could lead to local escalation of privilege across users with no additional execution privileges needed....

CVEs:CVE-2023-21281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21286

Open SourcePoC exploitHIGH2023-08-07

In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2023-21286

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21285

Open SourcePoC exploitMEDIUM2023-08-07

In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2023-21285

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21272

Open SourcePoC exploitHIGH2023-08-07

In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21272

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21284

Open SourcePoC exploitMEDIUM2023-08-07

In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interacti...

CVEs:CVE-2023-21284

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21288

Open SourcePoC exploitMEDIUM2023-08-07

In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2023-21288

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-4355

GoogleCoalition ESS < 30%HIGH2023-08-15

Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4355

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4355

Open SourceCoalition ESS < 30%HIGH2023-08-15

DEBIAN-CVE-2023-4355

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4362

GoogleCoalition ESS < 30%CRITICAL2023-08-15

Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. (Chromium...

CVEs:CVE-2023-4362

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2023-4362

GoogleCoalition ESS < 30%2023-08-15

Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4362

Upstream advisory

DEBIAN-CVE-2023-4362

Open SourceCoalition ESS < 30%CRITICAL2023-08-15

DEBIAN-CVE-2023-4362

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-4428

Open SourceCoalition ESS < 30%HIGH2023-08-23

DEBIAN-CVE-2023-4428

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4428

GoogleCoalition ESS < 30%HIGH2023-08-22

Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4428

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4430

Open SourceCoalition ESS < 30%CRITICAL2023-08-23

DEBIAN-CVE-2023-4430

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4430

GoogleCoalition ESS < 30%CRITICAL2023-08-22

Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4430

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-38157

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVEs:CVE-2023-38157

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-36741

Open SourceCoalition ESS < 30%CRITICAL2023-08-08

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2023-36741

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GO-2023-1992

Open SourceCoalition ESS < 30%NONE2023-08-23

Misleading message verification in golang.org/x/crypto/openpgp/clearsign

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
k3d affected chainguard k3d
k3d affected wolfi k3d
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CVE-2023-36787

Open SourceCoalition ESS < 30%CRITICAL2023-08-08

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2023-36787

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-4354

GoogleCoalition ESS < 30%CRITICAL2023-08-15

Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4354

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4354

Open SourceCoalition ESS < 30%CRITICAL2023-08-15

DEBIAN-CVE-2023-4354

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

AZL-27872

Open SourceCoalition ESS < 30%CRITICAL2023-08-08

CVE-2023-39533 affecting package golang for versions less than 1.19.12-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-27875

Open SourceCoalition ESS < 30%CRITICAL2023-08-08

CVE-2023-39533 affecting package msft-golang for versions less than 1.19.12-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37359

Open SourceCoalition ESS < 30%CRITICAL2023-08-08

CVE-2023-39533 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37422

Open SourceCoalition ESS < 30%CRITICAL2023-08-08

CVE-2023-39533 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-52773

Open SourceCoalition ESS < 30%CRITICAL2023-08-08

CVE-2023-39533 affecting package golang for versions less than 1.19.12-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-79074

Open SourceCoalition ESS < 30%CRITICAL2023-08-08

CVE-2023-39533 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2023-38158

Open SourceCoalition ESS < 30%HIGH2023-08-08

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVEs:CVE-2023-38158

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2023-4071

Open SourceCoalition ESS < 30%CRITICAL2023-08-03

DEBIAN-CVE-2023-4071

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4071

GoogleCoalition ESS < 30%CRITICAL2023-08-02

Heap buffer overflow in Visuals in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4071

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-4072

Open SourceCoalition ESS < 30%HIGH2023-08-03

DEBIAN-CVE-2023-4072

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-4073

Open SourceCoalition ESS < 30%HIGH2023-08-03

DEBIAN-CVE-2023-4073

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4072

GoogleCoalition ESS < 30%HIGH2023-08-02

Out of bounds read and write in WebGL in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4072

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-4073

GoogleCoalition ESS < 30%HIGH2023-08-02

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4073

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4075

Open SourceCoalition ESS < 30%CRITICAL2023-08-03

DEBIAN-CVE-2023-4075

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4075

GoogleCoalition ESS < 30%CRITICAL2023-08-02

Use after free in Cast in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4075

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-6q5m-22mq-q2xv

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

Istio Authorization Bypass Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
Upstream advisory

GHSA-6q5m-22mq-q2xv

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

Istio Authorization Bypass Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio.io istio.io/istio
istio affected istio.io istio.io/istio
Upstream advisory

DEBIAN-CVE-2023-4074

Open SourceCoalition ESS < 30%CRITICAL2023-08-03

DEBIAN-CVE-2023-4074

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4074

GoogleCoalition ESS < 30%CRITICAL2023-08-02

Use after free in Blink Task Scheduling in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4074

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MGASA-2023-0245

Open SourceCoalition ESS < 30%HIGH2023-08-23

Updated docker-containerd packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
docker-containerd affected Mageia:8 docker-containerd
golang-github-mrunalp-fileutils affected Mageia:8 golang-github-mrunalp-fileutils
Upstream advisory

CVE-2023-4353

GoogleCoalition ESS < 30%CRITICAL2023-08-15

Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4353

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4353

Open SourceCoalition ESS < 30%CRITICAL2023-08-15

DEBIAN-CVE-2023-4353

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-4431

Open SourceCoalition ESS < 30%HIGH2023-08-23

DEBIAN-CVE-2023-4431

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4431

GoogleCoalition ESS < 30%HIGH2023-08-22

Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4431

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-4431

GoogleCoalition ESS < 30%2023-08-22

Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4431

Upstream advisory

DEBIAN-CVE-2023-4076

Open SourceCoalition ESS < 30%CRITICAL2023-08-03

DEBIAN-CVE-2023-4076

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4076

GoogleCoalition ESS < 30%CRITICAL2023-08-02

Use after free in WebRTC in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC session. (Chromium security severity: High)

CVEs:CVE-2023-4076

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-4429

Open SourceCoalition ESS < 30%CRITICAL2023-08-23

DEBIAN-CVE-2023-4429

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4429

GoogleCoalition ESS < 30%CRITICAL2023-08-22

Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4429

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4077

Open SourceCoalition ESS < 30%HIGH2023-08-03

DEBIAN-CVE-2023-4077

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-4078

Open SourceCoalition ESS < 30%HIGH2023-08-03

DEBIAN-CVE-2023-4078

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4077

GoogleCoalition ESS < 30%HIGH2023-08-02

Insufficient data validation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium sec...

CVEs:CVE-2023-4077

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-4078

GoogleCoalition ESS < 30%HIGH2023-08-02

Inappropriate implementation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium sec...

CVEs:CVE-2023-4078

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-4350

GoogleCoalition ESS < 30%MEDIUM2023-08-15

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4350

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-4350

GoogleCoalition ESS < 30%2023-08-15

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4350

Upstream advisory

DEBIAN-CVE-2023-4350

Open SourceCoalition ESS < 30%MEDIUM2023-08-15

DEBIAN-CVE-2023-4350

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4356

GoogleCoalition ESS < 30%CRITICAL2023-08-15

Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4356

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-4358

GoogleCoalition ESS < 30%CRITICAL2023-08-15

Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4358

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4356

Open SourceCoalition ESS < 30%CRITICAL2023-08-15

DEBIAN-CVE-2023-4356

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-4358

Open SourceCoalition ESS < 30%CRITICAL2023-08-15

DEBIAN-CVE-2023-4358

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4351

GoogleCoalition ESS < 30%CRITICAL2023-08-15

Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4351

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-4351

GoogleCoalition ESS < 30%2023-08-15

Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4351

Upstream advisory

DEBIAN-CVE-2023-4351

Open SourceCoalition ESS < 30%CRITICAL2023-08-15

DEBIAN-CVE-2023-4351

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4349

GoogleCoalition ESS < 30%CRITICAL2023-08-15

Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4349

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4349

Open SourceCoalition ESS < 30%CRITICAL2023-08-15

DEBIAN-CVE-2023-4349

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4361

GoogleCoalition ESS < 30%MEDIUM2023-08-15

Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4361

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4361

Open SourceCoalition ESS < 30%MEDIUM2023-08-15

DEBIAN-CVE-2023-4361

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4359

GoogleCoalition ESS < 30%MEDIUM2023-08-15

Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed a remote attacker to potentially spoof elements of the security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4359

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4359

Open SourceCoalition ESS < 30%MEDIUM2023-08-15

DEBIAN-CVE-2023-4359

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-3730

Open SourceCoalition ESS < 30%CRITICAL2023-08-01

DEBIAN-CVE-2023-3730

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4368

GoogleCoalition ESS < 30%CRITICAL2023-08-15

Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Med...

CVEs:CVE-2023-4368

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2023-4368

Open SourceCoalition ESS < 30%CRITICAL2023-08-15

DEBIAN-CVE-2023-4368

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4363

GoogleCoalition ESS < 30%2023-08-15

Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4363

Upstream advisory

CVE-2023-4363

GoogleCoalition ESS < 30%MEDIUM2023-08-15

Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4363

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-4364

GoogleCoalition ESS < 30%2023-08-15

Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4364

Upstream advisory

CVE-2023-4364

GoogleCoalition ESS < 30%MEDIUM2023-08-15

Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4364

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-4365

GoogleCoalition ESS < 30%MEDIUM2023-08-15

Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4365

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4363

Open SourceCoalition ESS < 30%MEDIUM2023-08-15

DEBIAN-CVE-2023-4363

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-4364

Open SourceCoalition ESS < 30%MEDIUM2023-08-15

DEBIAN-CVE-2023-4364

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-4365

Open SourceCoalition ESS < 30%MEDIUM2023-08-15

DEBIAN-CVE-2023-4365

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4360

GoogleCoalition ESS < 30%2023-08-15

Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4360

Upstream advisory

CVE-2023-4360

GoogleCoalition ESS < 30%MEDIUM2023-08-15

Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4360

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4360

Open SourceCoalition ESS < 30%MEDIUM2023-08-15

DEBIAN-CVE-2023-4360

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4366

GoogleCoalition ESS < 30%CRITICAL2023-08-15

Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4366

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-4366

GoogleCoalition ESS < 30%2023-08-15

Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4366

Upstream advisory

DEBIAN-CVE-2023-4366

Open SourceCoalition ESS < 30%CRITICAL2023-08-15

DEBIAN-CVE-2023-4366

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4367

GoogleCoalition ESS < 30%CRITICAL2023-08-15

Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Med...

CVEs:CVE-2023-4367

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4367

Open SourceCoalition ESS < 30%CRITICAL2023-08-15

DEBIAN-CVE-2023-4367

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-3734

Open SourceCoalition ESS < 30%MEDIUM2023-08-01

DEBIAN-CVE-2023-3734

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-3733

Open SourceCoalition ESS < 30%MEDIUM2023-08-01

DEBIAN-CVE-2023-3733

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-3737

Open SourceCoalition ESS < 30%MEDIUM2023-08-01

DEBIAN-CVE-2023-3737

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

ASB-A-227655299

GoogleCoalition ESS < 30%2023-08-01

ASB-A-227655299

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2023-3740

Open SourceCoalition ESS < 30%MEDIUM2023-08-01

DEBIAN-CVE-2023-3740

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-21242

Open SourceCoalition ESS < 30%CRITICAL2023-08-07

In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User in...

CVEs:CVE-2023-21242

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2023-3738

Open SourceCoalition ESS < 30%MEDIUM2023-08-01

DEBIAN-CVE-2023-3738

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-21287

Open SourceCoalition ESS < 30%CRITICAL2023-08-07

In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21287

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-13690

GoogleCoalition ESS < 30%CRITICAL2023-08-25

Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

CVEs:CVE-2019-13690

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-21233

Open SourceCoalition ESS < 30%HIGH2023-08-07

In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21233

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-174737879

GoogleCoalition ESS < 30%HIGH2023-08-01

ASB-A-174737879

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2023-3729

GoogleCoalition ESS < 30%CRITICAL2023-08-01

Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chromium securi...

CVEs:CVE-2023-3729

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-3731

GoogleCoalition ESS < 30%CRITICAL2023-08-01

Use after free in Diagnostics in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security sever...

CVEs:CVE-2023-3731

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-21265

Open SourceCoalition ESS < 30%HIGH2023-08-07

In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21265

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2022-4955

Open SourceCoalition ESS < 30%MEDIUM2023-08-04

DEBIAN-CVE-2022-4955

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2019-13689

GoogleCoalition ESS < 30%HIGH2023-08-25

Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)

CVEs:CVE-2019-13689

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-jw82-xjgr-g6f8

Open SourceCoalition ESS < 30%HIGH2023-08-23

Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management

Affected products

ProductStatusVendorPackageEcosystem
github.com/nmstate/kubernetes-nmstate affected Go github.com/nmstate/kubernetes-nmstate
nmstate/kubernetes-nmstate affected github.com github.com/nmstate/kubernetes-nmstate
nmstate/kubernetes-nmstate affected github.com github.com/nmstate/kubernetes-nmstate
Upstream advisory

GHSA-jw82-xjgr-g6f8

Open SourceCoalition ESS < 30%HIGH2023-08-23

Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management

Affected products

ProductStatusVendorPackageEcosystem
nmstate/kubernetes-nmstate affected github.com github.com/nmstate/kubernetes-nmstate
Upstream advisory

CVE-2023-21273

Open SourceCoalition ESS < 30%HIGH2023-08-07

In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-21273

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-3481

GoogleCoalition ESS < 30%CRITICAL2023-08-21

Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XSS) bug. We recommend upgrading to version 0.0.20 of the extension. 

CVEs:CVE-2023-3481

Affected products

ProductStatusVendorPackageEcosystem
critters affected google
Upstream advisory

CVE-2023-3481

GoogleCoalition ESS < 30%MEDIUM2023-08-11

Critters Cross-site Scripting Vulnerability

CVEs:CVE-2023-3481

Affected products

ProductStatusVendorPackageEcosystem
critters affected npm critters
Upstream advisory

CVE-2023-3481

GoogleCoalition ESS < 30%MEDIUM2023-08-11

Critters Cross-site Scripting Vulnerability

CVEs:CVE-2023-3481

Affected products

ProductStatusVendorPackageEcosystem
critters affected npm critters
Upstream advisory

CVE-2023-21132

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset wi...

CVEs:CVE-2023-21132

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21133

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset wi...

CVEs:CVE-2023-21133

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21134

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset wi...

CVEs:CVE-2023-21134

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21140

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset wi...

CVEs:CVE-2023-21140

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21264

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n...

CVEs:CVE-2023-21264

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21264

GoogleCoalition ESS < 30%2023-08-07

In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21264

Upstream advisory

ASB-A-279739439

GoogleCoalition ESS < 30%NONE2023-08-01

ASB-A-279739439

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2023-20797

Open SourceCoalition ESS < 30%HIGH2023-08-07

In camera middleware, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS076295...

CVEs:CVE-2023-20797

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-268066858

GoogleCoalition ESS < 30%2023-08-01

PUB-A-268066858

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21283

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for ex...

CVEs:CVE-2023-21283

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20780

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; I...

CVEs:CVE-2023-20780

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-285686353

GoogleCoalition ESS < 30%2023-08-01

ASB-A-285686353

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21267

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. Us...

CVEs:CVE-2023-21267

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21274

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2023-21274

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21268

Open SourceCoalition ESS < 30%HIGH2023-08-07

In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2023-21268

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20802

Open SourceCoalition ESS < 30%HIGH2023-08-07

In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ...

CVEs:CVE-2023-20802

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20800

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420955.

CVEs:CVE-2023-20800

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-21229

Open SourceCoalition ESS < 30%HIGH2023-08-07

In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. Use...

CVEs:CVE-2023-21229

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21276

Open SourceCoalition ESS < 30%HIGH2023-08-07

In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21276

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21277

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2023-21277

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21279

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In visitUris of RemoteViews.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21279

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21292

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted files due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User in...

CVEs:CVE-2023-21292

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20806

Open SourceCoalition ESS < 30%HIGH2023-08-07

In hcp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340433; Issue ID: ...

CVEs:CVE-2023-20806

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20807

Open SourceCoalition ESS < 30%HIGH2023-08-07

In dpe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608433; Issue ID: ...

CVEs:CVE-2023-20807

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20814

Open SourceCoalition ESS < 30%HIGH2023-08-07

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453560...

CVEs:CVE-2023-20814

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20815

Open SourceCoalition ESS < 30%HIGH2023-08-07

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453587...

CVEs:CVE-2023-20815

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20816

Open SourceCoalition ESS < 30%HIGH2023-08-07

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453589...

CVEs:CVE-2023-20816

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20817

Open SourceCoalition ESS < 30%HIGH2023-08-07

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453600...

CVEs:CVE-2023-20817

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20795

Open SourceCoalition ESS < 30%HIGH2023-08-07

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07864900; Issue ID: ...

CVEs:CVE-2023-20795

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20804

Open SourceCoalition ESS < 30%HIGH2023-08-07

In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue I...

CVEs:CVE-2023-20804

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20805

Open SourceCoalition ESS < 30%HIGH2023-08-07

In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue I...

CVEs:CVE-2023-20805

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20786

Open SourceCoalition ESS < 30%HIGH2023-08-07

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767811; Issue ID: ...

CVEs:CVE-2023-20786

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20803

Open SourceCoalition ESS < 30%HIGH2023-08-07

In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ...

CVEs:CVE-2023-20803

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-21235

Open SourceCoalition ESS < 30%HIGH2023-08-07

In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without entering the existing PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. U...

CVEs:CVE-2023-21235

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21271

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2023-21271

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21289

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2023-21289

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35689

Open SourceCoalition ESS < 30%HIGH2023-08-07

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. Us...

CVEs:CVE-2023-35689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20811

Open SourceCoalition ESS < 30%HIGH2023-08-07

In IOMMU, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issue ID:...

CVEs:CVE-2023-20811

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2023-20813

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453549; ...

CVEs:CVE-2023-20813

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20818

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07460540; ...

CVEs:CVE-2023-20818

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20798

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In pda, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07147...

CVEs:CVE-2023-20798

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20783

Open SourceCoalition ESS < 30%HIGH2023-08-07

In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07826905; Iss...

CVEs:CVE-2023-20783

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20784

Open SourceCoalition ESS < 30%HIGH2023-08-07

In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07826989; Iss...

CVEs:CVE-2023-20784

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21280

Open SourceCoalition ESS < 30%HIGH2023-08-07

In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-21280

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20810

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In IOMMU, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issu...

CVEs:CVE-2023-20810

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2023-20812

Open SourceCoalition ESS < 30%HIGH2023-08-07

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944987; ...

CVEs:CVE-2023-20812

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
Upstream advisory

CVE-2023-20789

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In jpeg, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07693193; Issue I...

CVEs:CVE-2023-20789

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20790

Open SourceCoalition ESS < 30%HIGH2023-08-07

In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07740194; Issue ID:...

CVEs:CVE-2023-20790

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20782

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07550104; I...

CVEs:CVE-2023-20782

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47351

Open SourceCoalition ESS < 30%HIGH2023-08-07

In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2022-47351

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47350

Open SourceCoalition ESS < 30%HIGH2023-08-07

In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2022-47350

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21269

Open SourceCoalition ESS < 30%HIGH2023-08-07

In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...

CVEs:CVE-2023-21269

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20808

Open SourceCoalition ESS < 30%HIGH2023-08-07

In OPTEE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03645895; Issue ID:...

CVEs:CVE-2023-20808

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20809

Open SourceCoalition ESS < 30%HIGH2023-08-07

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03751198; Issue ID: ...

CVEs:CVE-2023-20809

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21278

Open SourceCoalition ESS < 30%LOW2023-08-07

In multiple locations, there is a possible way to obscure the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2023-21278

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20793

Open SourceCoalition ESS < 30%HIGH2023-08-07

In apu, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767818; Issue ID: ALPS0776...

CVEs:CVE-2023-20793

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20796

Open SourceCoalition ESS < 30%HIGH2023-08-07

In power, there is a possible memory corruption due to an incorrect bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929790; Issue ID: ALP...

CVEs:CVE-2023-20796

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20781

Open SourceCoalition ESS < 30%HIGH2023-08-07

In keyinstall, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; Issue ID: A...

CVEs:CVE-2023-20781

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21270

Open SourceCoalition ESS < 30%HIGH2023-08-07

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege w...

CVEs:CVE-2023-21270

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21230

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition check failure. This could lead to local information d...

CVEs:CVE-2023-21230

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21232

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-21232

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33912

Open SourceCoalition ESS < 30%HIGH2023-08-07

In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-33912

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33910

Open SourceCoalition ESS < 30%HIGH2023-08-07

In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-33910

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33911

Open SourceCoalition ESS < 30%HIGH2023-08-07

In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-33911

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33906

Open SourceCoalition ESS < 30%HIGH2023-08-07

In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-33906

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33907

Open SourceCoalition ESS < 30%HIGH2023-08-07

In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-33907

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21234

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check. This could lead to local escalation of privilege with no additional execut...

CVEs:CVE-2023-21234

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21290

Open SourceCoalition ESS < 30%MEDIUM2023-08-07

In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21290

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20787

Open SourceCoalition ESS < 30%HIGH2023-08-07

In thermal, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648734; Issue ID: ALPS076...

CVEs:CVE-2023-20787

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20788

Open SourceCoalition ESS < 30%HIGH2023-08-07

In thermal, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648734; Issue ID: ALPS076...

CVEs:CVE-2023-20788

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20801

Open SourceCoalition ESS < 30%HIGH2023-08-07

In imgsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS074...

CVEs:CVE-2023-20801

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20785

Open SourceCoalition ESS < 30%HIGH2023-08-07

In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628524; Issue ID...

CVEs:CVE-2023-20785

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2023-3732

Open SourceEPSS <= 49%HIGH2023-08-01

DEBIAN-CVE-2023-3732

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-2312

GoogleEPSS <= 49%CRITICAL2023-08-15

Use after free in Offline in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-2312

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-2312

Open SourceEPSS <= 49%CRITICAL2023-08-15

DEBIAN-CVE-2023-2312

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-3728

Open SourceEPSS <= 49%CRITICAL2023-08-01

DEBIAN-CVE-2023-3728

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-3727

Open SourceEPSS <= 49%CRITICAL2023-08-01

DEBIAN-CVE-2023-3727

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-3736

Open SourceEPSS <= 49%MEDIUM2023-08-01

DEBIAN-CVE-2023-3736

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-3735

Open SourceEPSS <= 49%MEDIUM2023-08-01

DEBIAN-CVE-2023-3735

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-m2f8-v8q4-3m59

Open SourceEPSS <= 49%HIGH2023-08-11

Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
intel-tensorflow affected PyPI intel-tensorflow
intel-tensorflow-avx512 affected PyPI intel-tensorflow-avx512
tensorflow-intel affected PyPI tensorflow-intel
Upstream advisory

GHSA-m2f8-v8q4-3m59

Open SourceEPSS <= 49%HIGH2023-08-11

Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow

Affected products

ProductStatusVendorPackageEcosystem
intel-tensorflow affected PyPI intel-tensorflow
intel-tensorflow affected PyPI intel-tensorflow
intel-tensorflow-avx512 affected PyPI intel-tensorflow-avx512
intel-tensorflow-avx512 affected PyPI intel-tensorflow-avx512
tensorflow-intel affected PyPI tensorflow-intel
tensorflow-intel affected PyPI tensorflow-intel
Upstream advisory

CVE-2023-27506

Open SourceEPSS <= 49%HIGH2023-08-11

Improper buffer restrictions in the Intel(R) Optimization for Tensorflow software before version 2.12 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVEs:CVE-2023-27506

Affected products

ProductStatusVendorPackageEcosystem
optimization_for_tensorflow affected intel
Upstream advisory

CVE-2023-27506

Open SourceEPSS <= 49%HIGH2023-08-11

Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow

CVEs:CVE-2023-27506

Affected products

ProductStatusVendorPackageEcosystem
intel-tensorflow affected PyPI intel-tensorflow
intel-tensorflow-avx512 affected PyPI intel-tensorflow-avx512
tensorflow-intel affected PyPI tensorflow-intel
Upstream advisory

CVE-2023-27506

Open SourceEPSS <= 49%MEDIUM2023-08-11

Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow

CVEs:CVE-2023-27506

Affected products

ProductStatusVendorPackageEcosystem
intel-tensorflow affected PyPI intel-tensorflow
intel-tensorflow-avx512 affected PyPI intel-tensorflow-avx512
tensorflow-intel affected PyPI tensorflow-intel
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.