Google Security Advisories · September 2023 — Google Security Advisories
451 advisories 246 CVEs 48 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2023-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 48 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

openSUSE-SU-2023:0247-1

Open SourceExploitedCISA KEV listed2023-09-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

openSUSE-SU-2023:0246-1

Open SourceExploitedCISA KEV listedCRITICAL2023-09-13

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

GHSA-j7hp-h8jx-5ppr

Open SourceExploitedCISA KEV listedCRITICAL2023-09-12

libwebp: OOB write in BuildHuffmanTable

Affected products

ProductStatusVendorPackageEcosystem
chai2010/webp affected github.com github.com/chai2010/webp
chai2010/webp affected github.com github.com/chai2010/webp
electron affected npm electron
firefox-esr affected chainguard firefox-esr
github.com/chai2010/webp affected Go github.com/chai2010/webp
libwebp affected wolfi libwebp
libwebp affected chainguard libwebp
libwebp affected webmproject
libwebp-sys affected crates.io libwebp-sys
libwebp-sys2 affected crates.io libwebp-sys2
magick.net-q16-anycpu affected NuGet magick.net-q16-anycpu
magick.net-q16-anycpu affected NuGet magick.net-q16-anycpu
magick.net-q16-hdri-anycpu affected NuGet magick.net-q16-hdri-anycpu
magick.net-q16-hdri-anycpu affected NuGet magick.net-q16-hdri-anycpu
magick.net-q16-x64 affected NuGet magick.net-q16-x64
magick.net-q16-x64 affected NuGet magick.net-q16-x64
magick.net-q8-anycpu affected NuGet magick.net-q8-anycpu
magick.net-q8-anycpu affected NuGet magick.net-q8-anycpu
magick.net-q8-openmp-x64 affected NuGet magick.net-q8-openmp-x64
magick.net-q8-openmp-x64 affected NuGet magick.net-q8-openmp-x64
magick.net-q8-x64 affected NuGet magick.net-q8-x64
magick.net-q8-x64 affected NuGet magick.net-q8-x64
pillow affected PyPI pillow
Pillow affected PyPI Pillow
Pillow affected PyPI Pillow
SkiaSharp affected NuGet SkiaSharp
SkiaSharp affected NuGet SkiaSharp
webp affected crates.io webp
Upstream advisory

GHSA-j7hp-h8jx-5ppr

Open SourceExploitedCISA KEV listedCRITICAL2023-09-12

libwebp: OOB write in BuildHuffmanTable

Affected products

ProductStatusVendorPackageEcosystem
chai2010/webp affected github.com github.com/chai2010/webp
electron affected npm electron
libwebp-sys affected crates.io libwebp-sys
libwebp-sys2 affected crates.io libwebp-sys2
magick.net-q16-anycpu affected NuGet magick.net-q16-anycpu
magick.net-q16-anycpu affected NuGet magick.net-q16-anycpu
magick.net-q16-hdri-anycpu affected NuGet magick.net-q16-hdri-anycpu
magick.net-q16-hdri-anycpu affected NuGet magick.net-q16-hdri-anycpu
magick.net-q16-x64 affected NuGet magick.net-q16-x64
magick.net-q16-x64 affected NuGet magick.net-q16-x64
magick.net-q8-anycpu affected NuGet magick.net-q8-anycpu
magick.net-q8-anycpu affected NuGet magick.net-q8-anycpu
magick.net-q8-openmp-x64 affected NuGet magick.net-q8-openmp-x64
magick.net-q8-openmp-x64 affected NuGet magick.net-q8-openmp-x64
magick.net-q8-x64 affected NuGet magick.net-q8-x64
magick.net-q8-x64 affected NuGet magick.net-q8-x64
pillow affected PyPI pillow
SkiaSharp affected NuGet SkiaSharp
SkiaSharp affected NuGet SkiaSharp
webp affected crates.io webp
Upstream advisory

DEBIAN-CVE-2023-4863

Open SourceExploitedCISA KEV listedCRITICAL2023-09-12

DEBIAN-CVE-2023-4863

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
firefox-esr affected Debian:11 firefox-esr
firefox-esr affected Debian:12 firefox-esr
firefox-esr affected Debian:13 firefox-esr
firefox-esr affected Debian:14 firefox-esr
libwebp affected Debian:11 libwebp
libwebp affected Debian:12 libwebp
libwebp affected Debian:13 libwebp
libwebp affected Debian:14 libwebp
thunderbird affected Debian:11 thunderbird
thunderbird affected Debian:12 thunderbird
thunderbird affected Debian:13 thunderbird
thunderbird affected Debian:14 thunderbird
Upstream advisory

CVE-2023-4863

Open SourceExploitedCISA KEV listedCRITICAL2023-09-11

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2023-4863

Affected products

ProductStatusVendorPackageEcosystem
active_iq_unified_manager affected netapp
chrome affected google
debian_linux affected debian
edge_chromium affected microsoft
fedora affected fedoraproject
firefox affected mozilla
honeyview affected bandisoft
libwebp affected webmproject
seequent_leapfrog affected bentley
teams affected microsoft
thunderbird affected mozilla
webp_image_extension affected microsoft
Upstream advisory

CVE-2023-4863

Project ZeroExploitedCISA KEV listed2023-09-11

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2023-4863

Upstream advisory

CVE-2023-4863

Open SourceExploitedCISA KEV listedCRITICAL2023-09-11

libwebp: OOB write in BuildHuffmanTable

CVEs:CVE-2023-4863

Affected products

ProductStatusVendorPackageEcosystem
chai2010/webp affected github.com github.com/chai2010/webp
electron affected npm electron
libwebp-sys affected crates.io libwebp-sys
libwebp-sys2 affected crates.io libwebp-sys2
magick.net-q16-anycpu affected NuGet magick.net-q16-anycpu
magick.net-q16-hdri-anycpu affected NuGet magick.net-q16-hdri-anycpu
magick.net-q16-x64 affected NuGet magick.net-q16-x64
magick.net-q8-anycpu affected NuGet magick.net-q8-anycpu
magick.net-q8-openmp-x64 affected NuGet magick.net-q8-openmp-x64
magick.net-q8-x64 affected NuGet magick.net-q8-x64
pillow affected PyPI pillow
SkiaSharp affected NuGet SkiaSharp
webp affected crates.io webp
Upstream advisory

CVE-2023-4863

Open SourceExploitedCISA KEV listedHIGH2023-09-11

libwebp: OOB write in BuildHuffmanTable

CVEs:CVE-2023-4863

Affected products

ProductStatusVendorPackageEcosystem
chai2010/webp affected github.com github.com/chai2010/webp
electron affected npm electron
libwebp-sys affected crates.io libwebp-sys
libwebp-sys2 affected crates.io libwebp-sys2
magick.net-q16-anycpu affected NuGet magick.net-q16-anycpu
magick.net-q16-hdri-anycpu affected NuGet magick.net-q16-hdri-anycpu
magick.net-q16-x64 affected NuGet magick.net-q16-x64
magick.net-q8-anycpu affected NuGet magick.net-q8-anycpu
magick.net-q8-openmp-x64 affected NuGet magick.net-q8-openmp-x64
magick.net-q8-x64 affected NuGet magick.net-q8-x64
pillow affected PyPI pillow
SkiaSharp affected NuGet SkiaSharp
webp affected crates.io webp
Upstream advisory

openSUSE-SU-2023:0277-1

Open SourceExploitedCISA KEV listedCRITICAL2023-09-29

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.5 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5508-1

Open SourceExploitedCISA KEV listed2023-09-29

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2023-5217

Open SourceExploitedCISA KEV listedCRITICAL2023-09-28

DEBIAN-CVE-2023-5217

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
firefox-esr affected Debian:14 firefox-esr
firefox-esr affected Debian:11 firefox-esr
firefox-esr affected Debian:12 firefox-esr
firefox-esr affected Debian:13 firefox-esr
libvpx affected Debian:11 libvpx
libvpx affected Debian:12 libvpx
libvpx affected Debian:13 libvpx
libvpx affected Debian:14 libvpx
thunderbird affected Debian:11 thunderbird
thunderbird affected Debian:12 thunderbird
thunderbird affected Debian:13 thunderbird
thunderbird affected Debian:14 thunderbird
Upstream advisory

CVE-2023-5217

GoogleExploitedCISA KEV listedHIGH2023-09-27

Electron affected by libvpx's heap buffer overflow in vp8 encoding

CVEs:CVE-2023-5217

Affected products

ProductStatusVendorPackageEcosystem
electron affected npm electron
Upstream advisory

CVE-2023-5217

GoogleExploitedCISA KEV listedHIGH2023-09-27

Electron affected by libvpx's heap buffer overflow in vp8 encoding

CVEs:CVE-2023-5217

Affected products

ProductStatusVendorPackageEcosystem
electron affected npm electron
Upstream advisory

CVE-2023-5217

Project ZeroExploitedCISA KEV listed2023-09-27

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5217

Upstream advisory

CVE-2023-5217

Open SourceExploitedCISA KEV listedCRITICAL2023-09-27

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5217

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
edge affected microsoft
edge_chromium affected microsoft
enterprise_linux affected redhat
fedora affected fedoraproject
firefox affected mozilla
ipados affected apple
iphone_os affected apple
libvpx affected webmproject
thunderbird affected mozilla
Upstream advisory

CVE-2023-41064

GoogleExploitedCISA KEV listedCRITICAL2023-09-07

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted...

CVEs:CVE-2023-41064

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-41064

Project ZeroExploitedCISA KEV listed2023-09-07

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2023-41064

Upstream advisory

openSUSE-SU-2023:0245-1

Open SourceExploitedCISA KEV listedCRITICAL2023-09-12

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
Upstream advisory

DSA-5491-1

Open SourceExploitedCISA KEV listed2023-09-07

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-4762

Open SourceExploitedCISA KEV listedCRITICAL2023-09-05

DEBIAN-CVE-2023-4762

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4762

Open SourceExploitedCISA KEV listedCRITICAL2023-09-05

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4762

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2023-4762

GoogleExploitedCISA KEV listed2023-09-05

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4762

Upstream advisory

CVE-2023-4762

Project ZeroExploitedCISA KEV listed2023-09-05

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4762

Upstream advisory

CVE-2023-36802

GoogleExploitedCISA KEV listedCRITICAL2023-09-12

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVEs:CVE-2023-36802

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
Upstream advisory

CVE-2023-36761

GoogleExploitedCISA KEV listedHIGH2023-09-12

Microsoft Word Information Disclosure Vulnerability

CVEs:CVE-2023-36761

Affected products

ProductStatusVendorPackageEcosystem
365_apps affected microsoft
office affected microsoft
office_long_term_servicing_channel affected microsoft
word affected microsoft
Upstream advisory

CVE-2023-26369

GoogleExploitedCISA KEV listedHIGH2023-09-12

Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploit...

CVEs:CVE-2023-26369

Affected products

ProductStatusVendorPackageEcosystem
acrobat affected adobe
acrobat_dc affected adobe
acrobat_reader affected adobe
acrobat_reader_dc affected adobe
Upstream advisory

CVE-2023-41991

GoogleExploitedCISA KEV listedMEDIUM2023-09-21

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited a...

CVEs:CVE-2023-41991

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-41991

Project ZeroExploitedCISA KEV listed2023-09-21

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVEs:CVE-2023-41991

Upstream advisory

CVE-2023-41061

GoogleExploitedCISA KEV listedCRITICAL2023-09-07

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been ...

CVEs:CVE-2023-41061

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2023-41061

Project ZeroExploitedCISA KEV listed2023-09-07

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVEs:CVE-2023-41061

Upstream advisory

CVE-2023-41992

GoogleExploitedCISA KEV listedHIGH2023-09-21

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been a...

CVEs:CVE-2023-41992

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-41992

Project ZeroExploitedCISA KEV listed2023-09-21

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVEs:CVE-2023-41992

Upstream advisory

CVE-2023-35674

Open SourceExploitedCISA KEV listedHIGH2023-09-05

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2023-35674

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35674

Project ZeroExploitedCISA KEV listed2023-09-05

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35674

Upstream advisory

PUB-A-294605494

GoogleExploitedCISA KEV listed2023-09-01

PUB-A-294605494

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

MGASA-2023-0256

Open SourceActive exploitation (sightings)CRITICAL2023-09-11

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

DEBIAN-CVE-2023-4761

Open SourceActive exploitation (sightings)HIGH2023-09-05

DEBIAN-CVE-2023-4761

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4761

GoogleActive exploitation (sightings)2023-09-05

Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4761

Upstream advisory

CVE-2023-4761

GoogleActive exploitation (sightings)HIGH2023-09-05

Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4761

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4763

Open SourceActive exploitation (sightings)CRITICAL2023-09-05

DEBIAN-CVE-2023-4763

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4763

GoogleActive exploitation (sightings)2023-09-05

Use after free in Networks in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4763

Upstream advisory

CVE-2023-4763

GoogleActive exploitation (sightings)CRITICAL2023-09-05

Use after free in Networks in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4763

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

openSUSE-SU-2023:0244-1

Open SourceActive exploitation (sightings)CRITICAL2023-09-06

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DSA-5499-1

Open SourceActive exploitation (sightings)2023-09-18

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2023-30708

Open SourceActive exploitation (sightings)HIGH2023-09-05

Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.

CVEs:CVE-2023-30708

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-33914

Open SourceActive exploitation (sightings)HIGH2023-09-04

In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to remote information disclosure no additional execution privileges needed

CVEs:CVE-2023-33914

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33915

Open SourceActive exploitation (sightings)HIGH2023-09-04

In LTE protocol stack, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed

CVEs:CVE-2023-33915

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-31416

Open SourceActive exploitation (sightings)MEDIUM2023-09-26

Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.

CVEs:CVE-2023-31416

Affected products

ProductStatusVendorPackageEcosystem
elastic_cloud_on_kubernetes affected elastic
Upstream advisory

CVE-2023-30712

Open SourceActive exploitation (sightings)HIGH2023-09-05

Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.

CVEs:CVE-2023-30712

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30710

Open SourceActive exploitation (sightings)HIGH2023-09-05

Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.

CVEs:CVE-2023-30710

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30709

Open SourceActive exploitation (sightings)HIGH2023-09-05

Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.

CVEs:CVE-2023-30709

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30711

Open SourceActive exploitation (sightings)MEDIUM2023-09-05

Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.

CVEs:CVE-2023-30711

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30715

Open SourceActive exploitation (sightings)MEDIUM2023-09-05

Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.

CVEs:CVE-2023-30715

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30717

Open SourceActive exploitation (sightings)HIGH2023-09-05

Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to get unresettable identifiers.

CVEs:CVE-2023-30717

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30713

Open SourceActive exploitation (sightings)MEDIUM2023-09-05

Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.

CVEs:CVE-2023-30713

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30720

Open SourceActive exploitation (sightings)MEDIUM2023-09-05

PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.

CVEs:CVE-2023-30720

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-44121

Open SourceActive exploitation (sightings)CRITICAL2023-09-27

The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a...

CVEs:CVE-2023-44121

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32810

Open SourceActive exploitation (sightings)MEDIUM2023-09-04

In bluetooth driver, there is a possible out of bounds read due to improper input validation. This could lead to local information leak with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07867212; Is...

CVEs:CVE-2023-32810

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-32810

GoogleActive exploitation (sightings)2023-09-04

In bluetooth driver, there is a possible out of bounds read due to improper input validation. This could lead to local information leak with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07867212; Issue ID: ALPS07867212.

CVEs:CVE-2023-32810

Upstream advisory

CVE-2023-32811

Open SourceActive exploitation (sightings)HIGH2023-09-04

In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID...

CVEs:CVE-2023-32811

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
yocto affected linuxfoundation
Upstream advisory

CVE-2023-32806

Open SourceActive exploitation (sightings)HIGH2023-09-04

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441589;...

CVEs:CVE-2023-32806

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
openwrt affected openwrt
yocto affected linuxfoundation
Upstream advisory

CVE-2023-32816

Open SourceActive exploitation (sightings)MEDIUM2023-09-04

In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; ...

CVEs:CVE-2023-32816

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32814

Open SourceActive exploitation (sightings)MEDIUM2023-09-04

In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08031947; ...

CVEs:CVE-2023-32814

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32813

Open SourceActive exploitation (sightings)HIGH2023-09-04

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017370;...

CVEs:CVE-2023-32813

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
yocto affected linuxfoundation
Upstream advisory

CVE-2023-32807

Open SourceActive exploitation (sightings)MEDIUM2023-09-04

In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588360; ...

CVEs:CVE-2023-32807

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
yocto affected linuxfoundation
Upstream advisory

AZL-38341

Open SourcePoC exploitHIGH2023-09-15

CVE-2023-38039 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

SUSE-SU-2023:2783-2

Open SourcePoC exploitCRITICAL2023-09-19

Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS protobuf
python-cryptography affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS python-cryptography
python-psutil affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS python-psutil
python-requests affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS python-requests
python-websocket-client affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS python-websocket-client
Upstream advisory

CLSA-2023-1694538837

Open SourcePoC exploitHIGH2023-09-12

Fix CVE(s): CVE-2022-48565

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.6 affected TuxCare:Ubuntu:18.04 idle-python3.6
libpython3.6 affected TuxCare:Ubuntu:18.04 libpython3.6
libpython3.6-dev affected TuxCare:Ubuntu:18.04 libpython3.6-dev
libpython3.6-minimal affected TuxCare:Ubuntu:18.04 libpython3.6-minimal
libpython3.6-stdlib affected TuxCare:Ubuntu:18.04 libpython3.6-stdlib
libpython3.6-testsuite affected TuxCare:Ubuntu:18.04 libpython3.6-testsuite
python3.6 affected TuxCare:Ubuntu:18.04 python3.6
python3.6-dev affected TuxCare:Ubuntu:18.04 python3.6-dev
python3.6-doc affected TuxCare:Ubuntu:18.04 python3.6-doc
python3.6-examples affected TuxCare:Ubuntu:18.04 python3.6-examples
python3.6-minimal affected TuxCare:Ubuntu:18.04 python3.6-minimal
python3.6-venv affected TuxCare:Ubuntu:18.04 python3.6-venv
Upstream advisory

CLSA-2023-1694538765

Open SourcePoC exploit2023-09-12

Fix CVE(s): CVE-2022-48565

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:18.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:18.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:18.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:18.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:18.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:18.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:18.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:18.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:18.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:18.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:18.04 python2.7-minimal
Upstream advisory

CLSA-2023-1694538434

Open SourcePoC exploitHIGH2023-09-12

Fix CVE(s): CVE-2022-48565

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

CLSA-2023-1694538236

Open SourcePoC exploit2023-09-12

Fix CVE(s): CVE-2022-48565

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

SUSE-EL-9-CLIENT-TOOLS-2023-3875

Open SourcePoC exploitCRITICAL2023-09-28

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS golang-github-lusitaniae-apache_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS golang-github-prometheus-node_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS golang-github-QubitProducts-exporter_exporter
prometheus-postgres_exporter affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS prometheus-postgres_exporter
scap-security-guide affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS scap-security-guide
spacecmd affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS spacecmd
Upstream advisory

SUSE-SU-2023:3875-1

Open SourcePoC exploitCRITICAL2023-09-28

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lusitaniae-apache_exporter affected SUSE:EL-9:Update:Products:ManagerTools:Update golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS golang-github-lusitaniae-apache_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:EL-9:Update:Products:ManagerTools:Update golang-github-prometheus-node_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:EL-9:Update:Products:ManagerTools:Update golang-github-QubitProducts-exporter_exporter
prometheus-postgres_exporter affected SUSE:EL-9:Update:Products:ManagerTools:Update prometheus-postgres_exporter
prometheus-postgres_exporter affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS prometheus-postgres_exporter
scap-security-guide affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS scap-security-guide
scap-security-guide affected SUSE:EL-9:Update:Products:ManagerTools:Update scap-security-guide
spacecmd affected SUSE:EL-9:Update:Products:ManagerTools:Update spacecmd
spacecmd affected SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS spacecmd
Upstream advisory

SUSE-SU-2023:3868-1

Open SourcePoC exploitHIGH2023-09-28

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Proxy Module 4.3 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected openSUSE:Leap 15.5 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Client Tools 15 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected openSUSE:Leap 15.4 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Server Module 4.3 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Server Module 4.2 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Proxy Module 4.2 golang-github-lusitaniae-apache_exporter
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 15 golang-github-prometheus-prometheus
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Client Tools 15 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Server Module 4.2 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected openSUSE:Leap 15.4 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Server Module 4.3 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Proxy Module 4.2 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected openSUSE:Leap 15.5 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Client Tools for SLE Micro 5 golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Proxy Module 4.3 golang-github-QubitProducts-exporter_exporter
grafana affected SUSE:Manager Client Tools 15 grafana
prometheus-blackbox_exporter affected openSUSE:Leap 15.5 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected SUSE:Manager Client Tools for SLE Micro 5 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected SUSE:Manager Proxy Module 4.2 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected SUSE:Manager Proxy Module 4.3 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected SUSE:Manager Client Tools 15 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected openSUSE:Leap 15.4 prometheus-blackbox_exporter
prometheus-postgres_exporter affected openSUSE:Leap 15.5 prometheus-postgres_exporter
prometheus-postgres_exporter affected SUSE:Manager Server Module 4.2 prometheus-postgres_exporter
prometheus-postgres_exporter affected SUSE:Manager Client Tools 15 prometheus-postgres_exporter
prometheus-postgres_exporter affected openSUSE:Leap 15.4 prometheus-postgres_exporter
python-pyvmomi affected SUSE:Manager Client Tools 15 python-pyvmomi
spacecmd affected SUSE:Manager Client Tools 15 spacecmd
spacecmd affected openSUSE:Leap 15.4 spacecmd
spacecmd affected openSUSE:Leap 15.5 spacecmd
supportutils-plugin-susemanager-client affected openSUSE:Leap 15.5 supportutils-plugin-susemanager-client
supportutils-plugin-susemanager-client affected openSUSE:Leap 15.4 supportutils-plugin-susemanager-client
supportutils-plugin-susemanager-client affected SUSE:Manager Client Tools 15 supportutils-plugin-susemanager-client
uyuni-common-libs affected SUSE:Manager Client Tools 15 uyuni-common-libs
Upstream advisory

SUSE-SU-2023:3867-1

Open SourcePoC exploitHIGH2023-09-28

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Client Tools 12 golang-github-lusitaniae-apache_exporter
golang-github-prometheus-alertmanager affected SUSE:Manager Client Tools 12 golang-github-prometheus-alertmanager
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 12 SP5 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Client Tools 12 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 12 SP5 golang-github-prometheus-node_exporter
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 12 golang-github-prometheus-prometheus
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Client Tools 12 golang-github-QubitProducts-exporter_exporter
grafana affected SUSE:Manager Client Tools 12 grafana
prometheus-blackbox_exporter affected SUSE:Manager Client Tools 12 prometheus-blackbox_exporter
prometheus-postgres_exporter affected SUSE:Manager Client Tools 12 prometheus-postgres_exporter
spacecmd affected SUSE:Manager Client Tools 12 spacecmd
supportutils-plugin-susemanager-client affected SUSE:Manager Client Tools 12 supportutils-plugin-susemanager-client
uyuni-common-libs affected SUSE:Manager Client Tools 12 uyuni-common-libs
Upstream advisory

CVE-2023-39320

GooglePoC exploitCRITICAL2023-09-06

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command f...

CVEs:CVE-2023-39320

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2023-39320

GooglePoC exploit2023-09-06

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.

CVEs:CVE-2023-39320

Upstream advisory

SUSE-SU-2023:3888-1

Open SourcePoC exploitCRITICAL2023-09-28

Security update for Golang Prometheus

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-alertmanager affected SUSE:Manager Proxy Module 4.3 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected SUSE:Manager Client Tools 15 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected SUSE:Linux Enterprise Module for Package Hub 15 SP5 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected SUSE:Manager Proxy Module 4.2 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected openSUSE:Leap 15.4 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected openSUSE:Leap 15.5 golang-github-prometheus-alertmanager
golang-github-prometheus-node_exporter affected SUSE:Manager Client Tools for SLE Micro 5 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP1-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP2-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server 15 SP3-LTSS golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 15 SP1 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Proxy 4.2 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Manager Server 4.2 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Enterprise Storage 7.1 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Module for Basesystem 15 SP4 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected SUSE:Linux Enterprise Module for Basesystem 15 SP5 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected openSUSE:Leap 15.5 golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter affected openSUSE:Leap 15.4 golang-github-prometheus-node_exporter
Upstream advisory

OESA-2023-1591

Open SourcePoC exploitNONE2023-09-02

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS-SP1 golang
Upstream advisory

DEBIAN-CVE-2023-5186

Open SourcePoC exploitCRITICAL2023-09-28

DEBIAN-CVE-2023-5186

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5186

GooglePoC exploit2023-09-27

Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)

CVEs:CVE-2023-5186

Upstream advisory

CVE-2023-5186

GooglePoC exploitCRITICAL2023-09-27

Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)

CVEs:CVE-2023-5186

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

AZL-28694

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39318 affecting package golang for versions less than 1.20.10-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-28832

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39318 affecting package msft-golang for versions less than 1.20.10-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37386

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39318 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37494

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39318 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-52735

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39318 affecting package golang for versions less than 1.20.10-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-78980

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39318 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-39318

Open SourcePoC exploitCRITICAL2023-09-08

DEBIAN-CVE-2023-39318

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GO-2023-2041

Open SourcePoC exploitCRITICAL2023-09-07

Improper handling of HTML-like comments in script contexts in html/template

Affected products

ProductStatusVendorPackageEcosystem
kind affected chainguard kind
kind affected wolfi kind
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
metrics-server affected chainguard metrics-server
metrics-server affected wolfi metrics-server
stdlib affected Go stdlib
stdlib affected Go
Upstream advisory

CVE-2023-39318

GooglePoC exploit2023-09-06

The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack.

CVEs:CVE-2023-39318

Upstream advisory

CVE-2023-39318

GooglePoC exploitCRITICAL2023-09-06

The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be ...

CVEs:CVE-2023-39318

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

AZL-28695

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39319 affecting package golang for versions less than 1.20.10-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-28830

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39319 affecting package msft-golang for versions less than 1.20.10-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-34745

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39319 affecting package golang for versions less than 1.20.10-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-37293

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39319 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37403

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39319 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-78956

Open SourcePoC exploitCRITICAL2023-09-08

CVE-2023-39319 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-39319

Open SourcePoC exploitCRITICAL2023-09-08

DEBIAN-CVE-2023-39319

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GO-2023-2043

Open SourcePoC exploitCRITICAL2023-09-07

Improper handling of special tags within script contexts in html/template

Affected products

ProductStatusVendorPackageEcosystem
kind affected chainguard kind
kind affected wolfi kind
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
metrics-server affected chainguard metrics-server
metrics-server affected wolfi metrics-server
stdlib affected Go stdlib
Upstream advisory

CVE-2023-39319

GooglePoC exploit2023-09-06

The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack.

CVEs:CVE-2023-39319

Upstream advisory

CVE-2023-39319

GooglePoC exploitCRITICAL2023-09-06

The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated ...

CVEs:CVE-2023-39319

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

DEBIAN-CVE-2023-5187

Open SourcePoC exploitCRITICAL2023-09-28

DEBIAN-CVE-2023-5187

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-5187

GooglePoC exploitCRITICAL2023-09-27

Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5187

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-5187

GooglePoC exploit2023-09-27

Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5187

Upstream advisory

OESA-2023-1682

Open SourcePoC exploitCRITICAL2023-09-22

grpc security update

Affected products

ProductStatusVendorPackageEcosystem
grpc affected openEuler:20.03-LTS-SP3 grpc
grpc affected openEuler:22.03-LTS grpc
grpc affected openEuler:22.03-LTS-SP1 grpc
grpc affected openEuler:22.03-LTS-SP2 grpc
Upstream advisory

GHSA-p25m-jpj4-qcrr

Open SourcePoC exploitHIGH2023-09-13

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
Upstream advisory

GHSA-p25m-jpj4-qcrr

Open SourcePoC exploitHIGH2023-09-13

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Affected products

ProductStatusVendorPackageEcosystem
grpc affected RubyGems grpc
grpcio affected PyPI grpcio
grpcio affected PyPI grpcio
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-fluentd-operator affected wolfi kube-fluentd-operator
Upstream advisory

AZL-34772

Open SourcePoC exploitHIGH2023-09-13

CVE-2023-4785 affecting package grpc for versions less than 1.62.0-2

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Azure Linux:3 grpc
Upstream advisory

DEBIAN-CVE-2023-4785

Open SourcePoC exploitHIGH2023-09-13

DEBIAN-CVE-2023-4785

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Debian:11 grpc
grpc affected Debian:12 grpc
grpc affected Debian:13 grpc
grpc affected Debian:14 grpc
Upstream advisory

BELL-CVE-2023-4785

Open SourcePoC exploitHIGH2023-09-13

BELL-CVE-2023-4785

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Alpaquita:stream grpc
grpc affected Alpaquita:23 grpc
Upstream advisory

openSUSE-SU-2023:0249-1

Open SourcePoC exploitCRITICAL2023-09-19

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.4 chromium
chromium affected openSUSE:Leap 15.5 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
Upstream advisory

CVE-2023-4901

GooglePoC exploitMEDIUM2023-09-12

Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4901

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4901

Open SourcePoC exploitMEDIUM2023-09-12

DEBIAN-CVE-2023-4901

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4905

GooglePoC exploitMEDIUM2023-09-12

Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4905

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4905

Open SourcePoC exploitMEDIUM2023-09-12

DEBIAN-CVE-2023-4905

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4907

GooglePoC exploitMEDIUM2023-09-12

Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-4907

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4907

Open SourcePoC exploitMEDIUM2023-09-12

DEBIAN-CVE-2023-4907

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2023-4900

GooglePoC exploitMEDIUM2023-09-12

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4900

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-4902

GooglePoC exploitMEDIUM2023-09-12

Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4902

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-4903

GooglePoC exploitMEDIUM2023-09-12

Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-4903

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4900

Open SourcePoC exploitMEDIUM2023-09-12

DEBIAN-CVE-2023-4900

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

DEBIAN-CVE-2023-4902

Open SourcePoC exploitMEDIUM2023-09-12

DEBIAN-CVE-2023-4902

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-4903

Open SourcePoC exploitMEDIUM2023-09-12

DEBIAN-CVE-2023-4903

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4906

GooglePoC exploitCRITICAL2023-09-12

Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-4906

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4906

Open SourcePoC exploitCRITICAL2023-09-12

DEBIAN-CVE-2023-4906

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4908

GooglePoC exploitMEDIUM2023-09-12

Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-4908

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-4909

GooglePoC exploitMEDIUM2023-09-12

Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-4909

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4908

Open SourcePoC exploitMEDIUM2023-09-12

DEBIAN-CVE-2023-4908

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-4909

Open SourcePoC exploitMEDIUM2023-09-12

DEBIAN-CVE-2023-4909

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4904

GooglePoC exploitCRITICAL2023-09-12

Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)

CVEs:CVE-2023-4904

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-4904

Open SourcePoC exploitCRITICAL2023-09-12

DEBIAN-CVE-2023-4904

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-35681

Open SourcePoC exploitCRITICAL2023-09-05

In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35681

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2023-36308

Open SourcePoC exploitMEDIUM2023-09-05

DEBIAN-CVE-2023-36308

Affected products

ProductStatusVendorPackageEcosystem
golang-github-disintegration-imaging affected Debian:12 golang-github-disintegration-imaging
golang-github-disintegration-imaging affected Debian:11 golang-github-disintegration-imaging
golang-github-disintegration-imaging affected Debian:13 golang-github-disintegration-imaging
golang-github-disintegration-imaging affected Debian:14 golang-github-disintegration-imaging
Upstream advisory

CVE-2023-35671

Open SourcePoC exploitMEDIUM2023-09-05

In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to ...

CVEs:CVE-2023-35671

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35687

Open SourcePoC exploitHIGH2023-09-05

In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35687

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-36735

Open SourceCoalition ESS < 30%CRITICAL2023-09-12

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2023-36735

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-44216

Open SourceCoalition ESS < 30%CRITICAL2023-09-27

PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. ...

CVEs:CVE-2023-44216

Affected products

ProductStatusVendorPackageEcosystem
android affected google
core_i7-10510u affected intel
core_i7-10610u affected intel
core_i7-11800h affected intel
core_i7-12700k affected intel
core_i7-8700 affected intel
geforce_rtx_2080_super affected nvidia
geforce_rtx_3060 affected nvidia
m1_mac_mini affected apple
macos affected apple
pixel_6 affected google
ryzen_5_7600x affected amd
ryzen_7_4800u affected amd
ubuntu_linux affected canonical
windows_10 affected microsoft
windows_11 affected microsoft
Upstream advisory

CVE-2023-39323

GoogleCoalition ESS < 30%CRITICAL2023-09-28

Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". ...

CVEs:CVE-2023-39323

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
Upstream advisory

CVE-2023-39323

GoogleCoalition ESS < 30%2023-09-28

Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.

CVEs:CVE-2023-39323

Upstream advisory

GO-2023-2044

Open SourceCoalition ESS < 30%2023-09-07

Panic when processing post-handshake message on QUIC connections in crypto/tls

Affected products

ProductStatusVendorPackageEcosystem
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
stdlib affected Go stdlib
Upstream advisory

CVE-2023-39321

GoogleCoalition ESS < 30%HIGH2023-09-06

Processing an incomplete post-handshake message for a QUIC connection can cause a panic.

CVEs:CVE-2023-39321

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2023-2045

Open SourceCoalition ESS < 30%HIGH2023-09-07

Memory exhaustion in QUIC connection handling in crypto/tls

Affected products

ProductStatusVendorPackageEcosystem
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
stdlib affected Go stdlib
Upstream advisory

CVE-2023-39322

GoogleCoalition ESS < 30%HIGH2023-09-06

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65...

CVEs:CVE-2023-39322

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

CVE-2023-39322

GoogleCoalition ESS < 30%2023-09-06

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVEs:CVE-2023-39322

Upstream advisory

DEBIAN-CVE-2023-4764

Open SourceCoalition ESS < 30%MEDIUM2023-09-05

DEBIAN-CVE-2023-4764

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-4764

GoogleCoalition ESS < 30%MEDIUM2023-09-05

Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4764

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2023-4764

GoogleCoalition ESS < 30%2023-09-05

Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-4764

Upstream advisory

DEBIAN-CVE-2023-42821

Open SourceCoalition ESS < 30%HIGH2023-09-22

DEBIAN-CVE-2023-42821

Affected products

ProductStatusVendorPackageEcosystem
golang-github-gomarkdown-markdown affected Debian:12 golang-github-gomarkdown-markdown
golang-github-gomarkdown-markdown affected Debian:13 golang-github-gomarkdown-markdown
golang-github-gomarkdown-markdown affected Debian:14 golang-github-gomarkdown-markdown
Upstream advisory

CVE-2023-36727

Open SourceCoalition ESS < 30%MEDIUM2023-09-12

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2023-36727

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-36562

Open SourceCoalition ESS < 30%CRITICAL2023-09-12

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2023-36562

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-g58x-57fv-86jh

GoogleCoalition ESS < 30%HIGH2023-09-06

Jenkins Google Login Plugin non-constant time token comparison

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

GHSA-g58x-57fv-86jh

GoogleCoalition ESS < 30%HIGH2023-09-06

Jenkins Google Login Plugin non-constant time token comparison

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

CVE-2023-41936

GoogleCoalition ESS < 30%2023-09-06

Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.

CVEs:CVE-2023-41936

Upstream advisory

CVE-2023-41936

GoogleCoalition ESS < 30%HIGH2023-09-06

Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.

CVEs:CVE-2023-41936

Affected products

ProductStatusVendorPackageEcosystem
google_login affected jenkins
Upstream advisory

CVE-2023-41936

GoogleCoalition ESS < 30%HIGH2023-09-06

Jenkins Google Login Plugin non-constant time token comparison

CVEs:CVE-2023-41936

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

CVE-2023-41387

Open SourceCoalition ESS < 30%CRITICAL2023-09-19

A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if ...

CVEs:CVE-2023-41387

Affected products

ProductStatusVendorPackageEcosystem
flutter_downloader affected patreon
Upstream advisory

CVE-2023-4887

GoogleCoalition ESS < 30%HIGH2023-09-12

The Google Maps Plugin by Intergeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes...

CVEs:CVE-2023-4887

Affected products

ProductStatusVendorPackageEcosystem
google_maps_plugin_by_intergeo affected themeisle
Upstream advisory

CVE-2023-35658

Open SourceCoalition ESS < 30%HIGH2023-09-05

In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible privilege escalation due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2023-35658

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35683

Open SourceCoalition ESS < 30%HIGH2023-09-05

In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2023-35683

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35684

Open SourceCoalition ESS < 30%HIGH2023-09-05

In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to an integer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35684

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-44123

Open SourceCoalition ESS < 30%CRITICAL2023-09-27

The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app. The attacker's app, if i...

CVEs:CVE-2023-44123

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-44125

Open SourceCoalition ESS < 30%CRITICAL2023-09-27

The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The attacker's app, ...

CVEs:CVE-2023-44125

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-44127

Open SourceCoalition ESS < 30%CRITICAL2023-09-27

he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as contact detail...

CVEs:CVE-2023-44127

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-44126

Open SourceCoalition ESS < 30%CRITICAL2023-09-27

The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data suc...

CVEs:CVE-2023-44126

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-285903020

GoogleCoalition ESS < 30%2023-09-01

ASB-A-285903020

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom/opensource/graphics-kernel affected platform platform/vendor/qcom/opensource/graphics-kernel
Upstream advisory

CVE-2023-35675

Open SourceCoalition ESS < 30%MEDIUM2023-09-05

In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user on the same device due to a logic error in the code. This could lead to local information disclosure with no addi...

CVEs:CVE-2023-35675

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20849

Open SourceCoalition ESS < 30%HIGH2023-09-04

In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Iss...

CVEs:CVE-2023-20849

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-35669

Open SourceCoalition ESS < 30%HIGH2023-09-05

In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed...

CVEs:CVE-2023-35669

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35679

Open SourceCoalition ESS < 30%MEDIUM2023-09-05

In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2023-35679

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35682

Open SourceCoalition ESS < 30%HIGH2023-09-05

In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary components due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...

CVEs:CVE-2023-35682

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20850

Open SourceCoalition ESS < 30%HIGH2023-09-04

In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433...

CVEs:CVE-2023-20850

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20841

Open SourceCoalition ESS < 30%HIGH2023-09-04

In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Iss...

CVEs:CVE-2023-20841

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20842

Open SourceCoalition ESS < 30%HIGH2023-09-04

In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS0735425...

CVEs:CVE-2023-20842

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20848

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433;...

CVEs:CVE-2023-20848

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20840

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS0732...

CVEs:CVE-2023-20840

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-35665

Open SourceCoalition ESS < 30%HIGH2023-09-05

In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2023-35665

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32812

Open SourceCoalition ESS < 30%HIGH2023-09-04

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017365...

CVEs:CVE-2023-32812

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20843

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340119; ...

CVEs:CVE-2023-20843

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20844

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; ...

CVEs:CVE-2023-20844

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20845

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07197795; Issue...

CVEs:CVE-2023-20845

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20846

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354023; ...

CVEs:CVE-2023-20846

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20839

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue...

CVEs:CVE-2023-20839

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-32809

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In bluetooth driver, there is a possible read and write access to registers due to improper access control of register interface. This could lead to local leak of sensitive information with System execution privileges needed. User interaction is not ne...

CVEs:CVE-2023-32809

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32808

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In bluetooth driver, there is a possible read and write access to registers due to improper access control of register interface. This could lead to local leak of sensitive information with System execution privileges needed. User interaction is not ne...

CVEs:CVE-2023-32808

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35677

Open SourceCoalition ESS < 30%MEDIUM2023-09-05

In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges neede...

CVEs:CVE-2023-35677

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-44122

Open SourceCoalition ESS < 30%CRITICAL2023-09-27

The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app...

CVEs:CVE-2023-44122

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35666

Open SourceCoalition ESS < 30%HIGH2023-09-05

In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35666

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20847

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue...

CVEs:CVE-2023-20847

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20837

Open SourceCoalition ESS < 30%HIGH2023-09-04

In seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07992786; Issue I...

CVEs:CVE-2023-20837

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32805

Open SourceCoalition ESS < 30%HIGH2023-09-04

In power, there is a possible out of bounds write due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08102892; Issue ID:...

CVEs:CVE-2023-32805

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32817

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; ...

CVEs:CVE-2023-32817

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32815

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08037801; ...

CVEs:CVE-2023-32815

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
yocto affected linuxfoundation
Upstream advisory

CVE-2023-44129

Open SourceCoalition ESS < 30%LOW2023-09-27

The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this functionality...

CVEs:CVE-2023-44129

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47353

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vdsp device, there is a possible system crash due to improper input validation.This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2022-47353

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48453

Open SourceCoalition ESS < 30%CRITICAL2023-09-04

In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2022-48453

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-47352

Open SourceCoalition ESS < 30%HIGH2023-09-04

In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2022-47352

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-44124

Open SourceCoalition ESS < 30%CRITICAL2023-09-27

The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is that the app...

CVEs:CVE-2023-44124

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20838

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In imgsys, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326...

CVEs:CVE-2023-20838

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20828

Open SourceCoalition ESS < 30%HIGH2023-09-04

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ...

CVEs:CVE-2023-20828

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20829

Open SourceCoalition ESS < 30%HIGH2023-09-04

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ...

CVEs:CVE-2023-20829

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20830

Open SourceCoalition ESS < 30%HIGH2023-09-04

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ...

CVEs:CVE-2023-20830

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20831

Open SourceCoalition ESS < 30%HIGH2023-09-04

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ...

CVEs:CVE-2023-20831

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20832

Open SourceCoalition ESS < 30%HIGH2023-09-04

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ...

CVEs:CVE-2023-20832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20821

Open SourceCoalition ESS < 30%HIGH2023-09-04

In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937113; Issue ID...

CVEs:CVE-2023-20821

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20822

Open SourceCoalition ESS < 30%HIGH2023-09-04

In netdagent, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944012; Issu...

CVEs:CVE-2023-20822

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38553

Open SourceCoalition ESS < 30%CRITICAL2023-09-04

In gnss service, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed

CVEs:CVE-2023-38553

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20836

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In camsys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07505629; Issue ID:...

CVEs:CVE-2023-20836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38468

Open SourceCoalition ESS < 30%CRITICAL2023-09-04

In urild service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-38468

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20833

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; I...

CVEs:CVE-2023-20833

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48452

Open SourceCoalition ESS < 30%HIGH2023-09-04

In Ifaa service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2022-48452

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35667

Open SourceCoalition ESS < 30%HIGH2023-09-05

In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges...

CVEs:CVE-2023-35667

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20851

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In stc, there is a possible out of bounds read due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08048635; Issue ID: ALPS08048635.

CVEs:CVE-2023-20851

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20823

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In cmdq, there is a possible out of bounds read due to an incorrect status check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08021592; Issue ID: ALP...

CVEs:CVE-2023-20823

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38467

Open SourceCoalition ESS < 30%CRITICAL2023-09-04

In urild service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-38467

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35664

Open SourceCoalition ESS < 30%MEDIUM2023-09-05

In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2023-35664

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38436

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-38436

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38437

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-38437

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38438

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-38438

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38439

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-38439

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33917

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-33917

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33918

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-33918

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-33916

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-33916

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38554

Open SourceCoalition ESS < 30%CRITICAL2023-09-04

In wcn bsp driver, there is a possible out of bounds write due to a missing bounds check.This could lead to local denial of service with no additional execution privileges

CVEs:CVE-2023-38554

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38449

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38449

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38450

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38450

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38451

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38451

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38452

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38452

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38453

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38453

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38455

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38455

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38456

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38456

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38458

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38458

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38459

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38459

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38460

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38460

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38464

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38464

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38443

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38443

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38444

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVEs:CVE-2023-38444

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20825

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07...

CVEs:CVE-2023-20825

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20826

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07978550...

CVEs:CVE-2023-20826

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20824

Open SourceCoalition ESS < 30%MEDIUM2023-09-04

In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07...

CVEs:CVE-2023-20824

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38466

Open SourceCoalition ESS < 30%HIGH2023-09-04

In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-38466

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38454

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-38454

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38465

Open SourceCoalition ESS < 30%HIGH2023-09-04

In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-38465

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38440

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-38440

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38441

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-38441

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38442

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVEs:CVE-2023-38442

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38447

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVEs:CVE-2023-38447

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38448

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVEs:CVE-2023-38448

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38457

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVEs:CVE-2023-38457

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38461

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVEs:CVE-2023-38461

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38462

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVEs:CVE-2023-38462

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38463

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVEs:CVE-2023-38463

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38445

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVEs:CVE-2023-38445

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38446

Open SourceCoalition ESS < 30%HIGH2023-09-04

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVEs:CVE-2023-38446

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-44128

Open SourceCoalition ESS < 30%MEDIUM2023-09-27

he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are fi...

CVEs:CVE-2023-44128

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20834

Open SourceCoalition ESS < 30%HIGH2023-09-04

In pda, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608514; Issue ID: ALPS07608514.

CVEs:CVE-2023-20834

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-20835

Open SourceCoalition ESS < 30%HIGH2023-09-04

In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS0732...

CVEs:CVE-2023-20835

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
yocto affected linuxfoundation
Upstream advisory

CVE-2023-20827

Open SourceCoalition ESS < 30%HIGH2023-09-04

In ims service, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937105; Issue ID: ...

CVEs:CVE-2023-20827

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-29332

Open SourceEPSS <= 49%CRITICAL2023-09-12

Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

CVEs:CVE-2023-29332

Affected products

ProductStatusVendorPackageEcosystem
azure_kubernetes_service affected microsoft
Upstream advisory

GHSA-vfw5-hrgq-h5wf

Open SourceEPSS <= 49%HIGH2023-09-25

x/net/html Vulnerable to DoS During HTML Parsing

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

GHSA-vfw5-hrgq-h5wf

Open SourceEPSS <= 49%HIGH2023-09-25

x/net/html Vulnerable to DoS During HTML Parsing

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2023-30706

Open SourceEPSS <= 49%HIGH2023-09-05

Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read arbitrary file with system privilege.

CVEs:CVE-2023-30706

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30714

Open SourceEPSS <= 49%HIGH2023-09-05

Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.

CVEs:CVE-2023-30714

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-35673

Open SourceEPSS <= 49%HIGH2023-09-05

In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-35673

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-30721

Open SourceEPSS <= 49%MEDIUM2023-09-05

Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.

CVEs:CVE-2023-30721

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30707

Open SourceEPSS <= 49%HIGH2023-09-05

Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege.

CVEs:CVE-2023-30707

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30719

Open SourceEPSS <= 49%MEDIUM2023-09-05

Exposure of Sensitive Information vulnerability in InboundSmsHandler prior to SMR Sep-2023 Release 1 allows local attackers to access certain message data.

CVEs:CVE-2023-30719

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30716

Open SourceEPSS <= 49%MEDIUM2023-09-05

Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to trigger certain commands.

CVEs:CVE-2023-30716

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-30718

Open SourceEPSS <= 49%MEDIUM2023-09-05

Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.

CVEs:CVE-2023-30718

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-35680

Open SourceEPSS <= 49%MEDIUM2023-09-05

In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2023-35680

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35670

Open SourceEPSS <= 49%HIGH2023-09-05

In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges need...

CVEs:CVE-2023-35670

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35676

Open SourceEPSS <= 49%HIGH2023-09-05

In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed...

CVEs:CVE-2023-35676

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GO-2023-2048

Open SourceAll remaining2023-09-13

Paths outside of the rootfs could be produced on Windows in github.com/cyphar/filepath-securejoin

Affected products

ProductStatusVendorPackageEcosystem
cadvisor affected chainguard cadvisor
cadvisor affected wolfi cadvisor
ctop affected chainguard ctop
ctop affected wolfi ctop
cyphar/filepath-securejoin affected github.com github.com/cyphar/filepath-securejoin
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected wolfi helm-3
helm-3 affected chainguard helm-3
helm-4 affected chainguard helm-4
helm-4 affected wolfi helm-4
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
k3s affected chainguard k3s
k3s affected wolfi k3s
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
kots affected chainguard kots
kots affected wolfi kots
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
runc affected wolfi runc
runc affected chainguard runc
tomcat-8.5.87 affected chainguard tomcat-8.5.87
up affected chainguard up
up affected wolfi up
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

GHSA-6xv5-86q9-7xr8

GoogleAll remaining2023-09-07

SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced

Affected products

ProductStatusVendorPackageEcosystem
cyphar/filepath-securejoin affected github.com github.com/cyphar/filepath-securejoin
Upstream advisory

GHSA-6xv5-86q9-7xr8

Open SourceAll remaining2023-09-07

SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced

Affected products

ProductStatusVendorPackageEcosystem
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.8 affected wolfi argo-cd-2.8
cadvisor affected wolfi cadvisor
cadvisor affected chainguard cadvisor
ctop affected wolfi ctop
ctop affected chainguard ctop
cyphar/filepath-securejoin affected github.com
cyphar/filepath-securejoin affected github.com github.com/cyphar/filepath-securejoin
cyphar/filepath-securejoin affected github.com github.com/cyphar/filepath-securejoin
flux-0 affected chainguard flux-0
flux-0.37 affected chainguard flux-0.37
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller-0 affected chainguard flux-helm-controller-0
flux-helm-controller-0.37 affected chainguard flux-helm-controller-0.37
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller-0 affected chainguard flux-kustomize-controller-0
flux-kustomize-controller-0.37 affected chainguard flux-kustomize-controller-0.37
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller-0 affected chainguard flux-notification-controller-0
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller-0 affected chainguard flux-source-controller-0
flux-source-controller-0.37 affected chainguard flux-source-controller-0.37
github.com/cyphar/filepath-securejoin affected Go github.com/cyphar/filepath-securejoin
helm affected chainguard helm
helm affected wolfi helm
helm-3 affected wolfi helm-3
helm-3 affected chainguard helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-pilot-agent-1.18 affected chainguard istio-pilot-agent-1.18
istio-pilot-agent-1.18 affected wolfi istio-pilot-agent-1.18
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
k3s affected chainguard k3s
k3s affected wolfi k3s
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
kots affected chainguard kots
kots affected wolfi kots
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kyverno affected wolfi kyverno
kyverno affected chainguard kyverno
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
node-problem-detector-0.8 affected wolfi node-problem-detector-0.8
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
runc affected chainguard runc
runc affected wolfi runc
tomcat-8.5.87 affected chainguard tomcat-8.5.87
up affected wolfi up
up affected chainguard up
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

SUSE-SU-2023:3532-1

Open SourceAll remaining2023-09-05

Security update for kubernetes1.18

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.18 affected SUSE:Linux Enterprise Server 15 SP2-LTSS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server 15 SP3-LTSS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP2 kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kubernetes1.18
kubernetes1.18 affected SUSE:Enterprise Storage 7 kubernetes1.18
kubernetes1.18 affected SUSE:Enterprise Storage 7.1 kubernetes1.18
kubernetes1.18 affected openSUSE:Leap 15.5 kubernetes1.18
kubernetes1.18 affected openSUSE:Leap 15.4 kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise Module for Containers 15 SP4 kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS kubernetes1.18
kubernetes1.18 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kubernetes1.18
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.