Advisories
Open SourceExploitedCISA KEV listed2023-09-15
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-09-13
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-09-12
libwebp: OOB write in BuildHuffmanTable
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chai2010/webp |
affected |
github.com |
github.com/chai2010/webp |
— |
| chai2010/webp |
affected |
github.com |
github.com/chai2010/webp |
— |
| electron |
affected |
npm |
electron |
— |
| firefox-esr |
affected |
chainguard |
firefox-esr |
— |
| github.com/chai2010/webp |
affected |
Go |
github.com/chai2010/webp |
— |
| libwebp |
affected |
wolfi |
libwebp |
— |
| libwebp |
affected |
chainguard |
libwebp |
— |
| libwebp |
affected |
webmproject |
— |
— |
| libwebp-sys |
affected |
crates.io |
libwebp-sys |
— |
| libwebp-sys2 |
affected |
crates.io |
libwebp-sys2 |
— |
| magick.net-q16-anycpu |
affected |
NuGet |
magick.net-q16-anycpu |
— |
| magick.net-q16-anycpu |
affected |
NuGet |
magick.net-q16-anycpu |
— |
| magick.net-q16-hdri-anycpu |
affected |
NuGet |
magick.net-q16-hdri-anycpu |
— |
| magick.net-q16-hdri-anycpu |
affected |
NuGet |
magick.net-q16-hdri-anycpu |
— |
| magick.net-q16-x64 |
affected |
NuGet |
magick.net-q16-x64 |
— |
| magick.net-q16-x64 |
affected |
NuGet |
magick.net-q16-x64 |
— |
| magick.net-q8-anycpu |
affected |
NuGet |
magick.net-q8-anycpu |
— |
| magick.net-q8-anycpu |
affected |
NuGet |
magick.net-q8-anycpu |
— |
| magick.net-q8-openmp-x64 |
affected |
NuGet |
magick.net-q8-openmp-x64 |
— |
| magick.net-q8-openmp-x64 |
affected |
NuGet |
magick.net-q8-openmp-x64 |
— |
| magick.net-q8-x64 |
affected |
NuGet |
magick.net-q8-x64 |
— |
| magick.net-q8-x64 |
affected |
NuGet |
magick.net-q8-x64 |
— |
| pillow |
affected |
PyPI |
pillow |
— |
| Pillow |
affected |
PyPI |
Pillow |
— |
| Pillow |
affected |
PyPI |
Pillow |
— |
| SkiaSharp |
affected |
NuGet |
SkiaSharp |
— |
| SkiaSharp |
affected |
NuGet |
SkiaSharp |
— |
| webp |
affected |
crates.io |
webp |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-09-12
libwebp: OOB write in BuildHuffmanTable
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chai2010/webp |
affected |
github.com |
github.com/chai2010/webp |
— |
| electron |
affected |
npm |
electron |
— |
| libwebp-sys |
affected |
crates.io |
libwebp-sys |
— |
| libwebp-sys2 |
affected |
crates.io |
libwebp-sys2 |
— |
| magick.net-q16-anycpu |
affected |
NuGet |
magick.net-q16-anycpu |
— |
| magick.net-q16-anycpu |
affected |
NuGet |
magick.net-q16-anycpu |
— |
| magick.net-q16-hdri-anycpu |
affected |
NuGet |
magick.net-q16-hdri-anycpu |
— |
| magick.net-q16-hdri-anycpu |
affected |
NuGet |
magick.net-q16-hdri-anycpu |
— |
| magick.net-q16-x64 |
affected |
NuGet |
magick.net-q16-x64 |
— |
| magick.net-q16-x64 |
affected |
NuGet |
magick.net-q16-x64 |
— |
| magick.net-q8-anycpu |
affected |
NuGet |
magick.net-q8-anycpu |
— |
| magick.net-q8-anycpu |
affected |
NuGet |
magick.net-q8-anycpu |
— |
| magick.net-q8-openmp-x64 |
affected |
NuGet |
magick.net-q8-openmp-x64 |
— |
| magick.net-q8-openmp-x64 |
affected |
NuGet |
magick.net-q8-openmp-x64 |
— |
| magick.net-q8-x64 |
affected |
NuGet |
magick.net-q8-x64 |
— |
| magick.net-q8-x64 |
affected |
NuGet |
magick.net-q8-x64 |
— |
| pillow |
affected |
PyPI |
pillow |
— |
| SkiaSharp |
affected |
NuGet |
SkiaSharp |
— |
| SkiaSharp |
affected |
NuGet |
SkiaSharp |
— |
| webp |
affected |
crates.io |
webp |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-09-12
DEBIAN-CVE-2023-4863
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| firefox-esr |
affected |
Debian:11 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:12 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:13 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:14 |
firefox-esr |
— |
| libwebp |
affected |
Debian:11 |
libwebp |
— |
| libwebp |
affected |
Debian:12 |
libwebp |
— |
| libwebp |
affected |
Debian:13 |
libwebp |
— |
| libwebp |
affected |
Debian:14 |
libwebp |
— |
| thunderbird |
affected |
Debian:11 |
thunderbird |
— |
| thunderbird |
affected |
Debian:12 |
thunderbird |
— |
| thunderbird |
affected |
Debian:13 |
thunderbird |
— |
| thunderbird |
affected |
Debian:14 |
thunderbird |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-09-11
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
CVEs:CVE-2023-4863
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| active_iq_unified_manager |
affected |
netapp |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| edge_chromium |
affected |
microsoft |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| firefox |
affected |
mozilla |
— |
— |
| honeyview |
affected |
bandisoft |
— |
— |
| libwebp |
affected |
webmproject |
— |
— |
| seequent_leapfrog |
affected |
bentley |
— |
— |
| teams |
affected |
microsoft |
— |
— |
| thunderbird |
affected |
mozilla |
— |
— |
| webp_image_extension |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2023-09-11
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
CVEs:CVE-2023-4863
Open SourceExploitedCISA KEV listedCRITICAL2023-09-11
libwebp: OOB write in BuildHuffmanTable
CVEs:CVE-2023-4863
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chai2010/webp |
affected |
github.com |
github.com/chai2010/webp |
— |
| electron |
affected |
npm |
electron |
— |
| libwebp-sys |
affected |
crates.io |
libwebp-sys |
— |
| libwebp-sys2 |
affected |
crates.io |
libwebp-sys2 |
— |
| magick.net-q16-anycpu |
affected |
NuGet |
magick.net-q16-anycpu |
— |
| magick.net-q16-hdri-anycpu |
affected |
NuGet |
magick.net-q16-hdri-anycpu |
— |
| magick.net-q16-x64 |
affected |
NuGet |
magick.net-q16-x64 |
— |
| magick.net-q8-anycpu |
affected |
NuGet |
magick.net-q8-anycpu |
— |
| magick.net-q8-openmp-x64 |
affected |
NuGet |
magick.net-q8-openmp-x64 |
— |
| magick.net-q8-x64 |
affected |
NuGet |
magick.net-q8-x64 |
— |
| pillow |
affected |
PyPI |
pillow |
— |
| SkiaSharp |
affected |
NuGet |
SkiaSharp |
— |
| webp |
affected |
crates.io |
webp |
— |
Open SourceExploitedCISA KEV listedHIGH2023-09-11
libwebp: OOB write in BuildHuffmanTable
CVEs:CVE-2023-4863
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chai2010/webp |
affected |
github.com |
github.com/chai2010/webp |
— |
| electron |
affected |
npm |
electron |
— |
| libwebp-sys |
affected |
crates.io |
libwebp-sys |
— |
| libwebp-sys2 |
affected |
crates.io |
libwebp-sys2 |
— |
| magick.net-q16-anycpu |
affected |
NuGet |
magick.net-q16-anycpu |
— |
| magick.net-q16-hdri-anycpu |
affected |
NuGet |
magick.net-q16-hdri-anycpu |
— |
| magick.net-q16-x64 |
affected |
NuGet |
magick.net-q16-x64 |
— |
| magick.net-q8-anycpu |
affected |
NuGet |
magick.net-q8-anycpu |
— |
| magick.net-q8-openmp-x64 |
affected |
NuGet |
magick.net-q8-openmp-x64 |
— |
| magick.net-q8-x64 |
affected |
NuGet |
magick.net-q8-x64 |
— |
| pillow |
affected |
PyPI |
pillow |
— |
| SkiaSharp |
affected |
NuGet |
SkiaSharp |
— |
| webp |
affected |
crates.io |
webp |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-09-29
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
Open SourceExploitedCISA KEV listed2023-09-29
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-09-28
DEBIAN-CVE-2023-5217
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| firefox-esr |
affected |
Debian:14 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:11 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:12 |
firefox-esr |
— |
| firefox-esr |
affected |
Debian:13 |
firefox-esr |
— |
| libvpx |
affected |
Debian:11 |
libvpx |
— |
| libvpx |
affected |
Debian:12 |
libvpx |
— |
| libvpx |
affected |
Debian:13 |
libvpx |
— |
| libvpx |
affected |
Debian:14 |
libvpx |
— |
| thunderbird |
affected |
Debian:11 |
thunderbird |
— |
| thunderbird |
affected |
Debian:12 |
thunderbird |
— |
| thunderbird |
affected |
Debian:13 |
thunderbird |
— |
| thunderbird |
affected |
Debian:14 |
thunderbird |
— |
GoogleExploitedCISA KEV listedHIGH2023-09-27
Electron affected by libvpx's heap buffer overflow in vp8 encoding
CVEs:CVE-2023-5217
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| electron |
affected |
npm |
electron |
— |
GoogleExploitedCISA KEV listedHIGH2023-09-27
Electron affected by libvpx's heap buffer overflow in vp8 encoding
CVEs:CVE-2023-5217
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| electron |
affected |
npm |
electron |
— |
Project ZeroExploitedCISA KEV listed2023-09-27
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5217
Open SourceExploitedCISA KEV listedCRITICAL2023-09-27
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5217
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| edge |
affected |
microsoft |
— |
— |
| edge_chromium |
affected |
microsoft |
— |
— |
| enterprise_linux |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| firefox |
affected |
mozilla |
— |
— |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| libvpx |
affected |
webmproject |
— |
— |
| thunderbird |
affected |
mozilla |
— |
— |
GoogleExploitedCISA KEV listedCRITICAL2023-09-07
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted...
CVEs:CVE-2023-41064
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
GoogleExploitedCISA KEV listedHIGH2023-09-07
CVEs:CVE-2023-41064
Project ZeroExploitedCISA KEV listed2023-09-07
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2023-41064
Open SourceExploitedCISA KEV listedCRITICAL2023-09-12
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
Open SourceExploitedCISA KEV listed2023-09-07
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-09-05
DEBIAN-CVE-2023-4762
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceExploitedCISA KEV listedCRITICAL2023-09-05
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4762
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| edge_chromium |
affected |
microsoft |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleExploitedCISA KEV listedHIGH2023-09-05
CVEs:CVE-2023-4762
GoogleExploitedCISA KEV listed2023-09-05
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4762
Project ZeroExploitedCISA KEV listed2023-09-05
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4762
GoogleExploitedCISA KEV listedHIGH2023-09-12
CVEs:CVE-2023-36802
GoogleExploitedCISA KEV listedCRITICAL2023-09-12
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
CVEs:CVE-2023-36802
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_10_21h2 |
affected |
microsoft |
— |
— |
| windows_10_22h2 |
affected |
microsoft |
— |
— |
| windows_11_21h2 |
affected |
microsoft |
— |
— |
| windows_11_22h2 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
| windows_server_2022 |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2023-09-12
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
CVEs:CVE-2023-36802
GoogleExploitedCISA KEV listedMEDIUM2023-09-12
CVEs:CVE-2023-36761
GoogleExploitedCISA KEV listedHIGH2023-09-12
Microsoft Word Information Disclosure Vulnerability
CVEs:CVE-2023-36761
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| 365_apps |
affected |
microsoft |
— |
— |
| office |
affected |
microsoft |
— |
— |
| office_long_term_servicing_channel |
affected |
microsoft |
— |
— |
| word |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2023-09-12
Microsoft Word Information Disclosure Vulnerability
CVEs:CVE-2023-36761
Project ZeroExploitedCISA KEV listed2023-09-12
[Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild
CVEs:CVE-2023-26369
GoogleExploitedCISA KEV listedHIGH2023-09-12
CVEs:CVE-2023-26369
GoogleExploitedCISA KEV listedHIGH2023-09-12
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploit...
CVEs:CVE-2023-26369
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| acrobat |
affected |
adobe |
— |
— |
| acrobat_dc |
affected |
adobe |
— |
— |
| acrobat_reader |
affected |
adobe |
— |
— |
| acrobat_reader_dc |
affected |
adobe |
— |
— |
GoogleExploitedCISA KEV listedMEDIUM2023-09-21
CVEs:CVE-2023-41991
GoogleExploitedCISA KEV listedMEDIUM2023-09-21
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited a...
CVEs:CVE-2023-41991
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2023-09-21
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
CVEs:CVE-2023-41991
GoogleExploitedCISA KEV listedHIGH2023-09-07
CVEs:CVE-2023-41061
GoogleExploitedCISA KEV listedCRITICAL2023-09-07
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been ...
CVEs:CVE-2023-41061
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2023-09-07
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVEs:CVE-2023-41061
GoogleExploitedCISA KEV listedHIGH2023-09-21
CVEs:CVE-2023-41992
GoogleExploitedCISA KEV listedHIGH2023-09-21
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been a...
CVEs:CVE-2023-41992
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2023-09-21
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
CVEs:CVE-2023-41992
Open SourceExploitedCISA KEV listedHIGH2023-09-05
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2023-35674
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Project ZeroExploitedCISA KEV listed2023-09-05
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35674
GoogleExploitedCISA KEV listedHIGH2023-09-05
CVEs:CVE-2023-35674
GoogleExploitedCISA KEV listed2023-09-01
PUB-A-294605494
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)CRITICAL2023-09-11
Updated chromium-browser-stable packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:9 |
chromium-browser-stable |
— |
Open SourceActive exploitation (sightings)HIGH2023-09-05
DEBIAN-CVE-2023-4761
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2023-09-05
CVEs:CVE-2023-4761
GoogleActive exploitation (sightings)2023-09-05
Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4761
GoogleActive exploitation (sightings)HIGH2023-09-05
Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4761
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2023-09-05
DEBIAN-CVE-2023-4763
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2023-09-05
Use after free in Networks in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4763
GoogleActive exploitation (sightings)CRITICAL2023-09-05
Use after free in Networks in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4763
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-09-05
CVEs:CVE-2023-4763
Open SourceActive exploitation (sightings)CRITICAL2023-09-06
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourceActive exploitation (sightings)2023-09-18
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2023-09-05
Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.
CVEs:CVE-2023-30708
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-09-05
CVEs:CVE-2023-30708
GoogleActive exploitation (sightings)HIGH2023-09-04
CVEs:CVE-2023-33914
Open SourceActive exploitation (sightings)HIGH2023-09-04
In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to remote information disclosure no additional execution privileges needed
CVEs:CVE-2023-33914
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-09-04
CVEs:CVE-2023-33915
Open SourceActive exploitation (sightings)HIGH2023-09-04
In LTE protocol stack, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
CVEs:CVE-2023-33915
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-10-26
CVEs:CVE-2023-31416
Open SourceActive exploitation (sightings)MEDIUM2023-09-26
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
CVEs:CVE-2023-31416
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| elastic_cloud_on_kubernetes |
affected |
elastic |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-09-05
CVEs:CVE-2023-30712
Open SourceActive exploitation (sightings)HIGH2023-09-05
Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.
CVEs:CVE-2023-30712
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-09-05
Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.
CVEs:CVE-2023-30710
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2023-09-05
CVEs:CVE-2023-30710
GoogleActive exploitation (sightings)HIGH2023-09-05
CVEs:CVE-2023-30709
Open SourceActive exploitation (sightings)HIGH2023-09-05
Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.
CVEs:CVE-2023-30709
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-09-05
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
CVEs:CVE-2023-30711
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)LOW2023-09-05
CVEs:CVE-2023-30711
GoogleActive exploitation (sightings)LOW2023-09-05
CVEs:CVE-2023-30715
Open SourceActive exploitation (sightings)MEDIUM2023-09-05
Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.
CVEs:CVE-2023-30715
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-09-05
Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to get unresettable identifiers.
CVEs:CVE-2023-30717
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)LOW2023-09-05
CVEs:CVE-2023-30717
GoogleActive exploitation (sightings)MEDIUM2023-09-05
CVEs:CVE-2023-30713
Open SourceActive exploitation (sightings)MEDIUM2023-09-05
Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.
CVEs:CVE-2023-30713
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-09-05
PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.
CVEs:CVE-2023-30720
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-09-05
CVEs:CVE-2023-30720
GoogleActive exploitation (sightings)MEDIUM2023-09-27
CVEs:CVE-2023-44121
Open SourceActive exploitation (sightings)CRITICAL2023-09-27
The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a...
CVEs:CVE-2023-44121
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-09-04
CVEs:CVE-2023-32810
Open SourceActive exploitation (sightings)MEDIUM2023-09-04
In bluetooth driver, there is a possible out of bounds read due to improper input validation. This could lead to local information leak with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07867212; Is...
CVEs:CVE-2023-32810
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleActive exploitation (sightings)2023-09-04
In bluetooth driver, there is a possible out of bounds read due to improper input validation. This could lead to local information leak with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07867212; Issue ID: ALPS07867212.
CVEs:CVE-2023-32810
GoogleActive exploitation (sightings)MEDIUM2023-09-04
CVEs:CVE-2023-32811
GoogleActive exploitation (sightings)MEDIUM2023-09-04
CVEs:CVE-2023-32806
Open SourceActive exploitation (sightings)HIGH2023-09-04
In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID...
CVEs:CVE-2023-32811
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-09-04
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441589;...
CVEs:CVE-2023-32806
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2023-09-04
CVEs:CVE-2023-32816
GoogleActive exploitation (sightings)MEDIUM2023-09-04
CVEs:CVE-2023-32813
GoogleActive exploitation (sightings)MEDIUM2023-09-04
CVEs:CVE-2023-32814
GoogleActive exploitation (sightings)MEDIUM2023-09-04
CVEs:CVE-2023-32807
Open SourceActive exploitation (sightings)MEDIUM2023-09-04
In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; ...
CVEs:CVE-2023-32816
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-09-04
In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08031947; ...
CVEs:CVE-2023-32814
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2023-09-04
In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017370;...
CVEs:CVE-2023-32813
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2023-09-04
In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588360; ...
CVEs:CVE-2023-32807
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourcePoC exploitHIGH2023-09-15
CVE-2023-38039 affecting package tensorflow for versions less than 2.16.1-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:3 |
tensorflow |
— |
Open SourcePoC exploitCRITICAL2023-09-19
Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS |
protobuf |
— |
| python-cryptography |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS |
python-cryptography |
— |
| python-psutil |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS |
python-psutil |
— |
| python-requests |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS |
python-requests |
— |
| python-websocket-client |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS |
python-websocket-client |
— |
Open SourcePoC exploitHIGH2023-09-12
Fix CVE(s): CVE-2022-48565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python3.6 |
affected |
TuxCare:Ubuntu:18.04 |
idle-python3.6 |
— |
| libpython3.6 |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6 |
— |
| libpython3.6-dev |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-dev |
— |
| libpython3.6-minimal |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-minimal |
— |
| libpython3.6-stdlib |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-stdlib |
— |
| libpython3.6-testsuite |
affected |
TuxCare:Ubuntu:18.04 |
libpython3.6-testsuite |
— |
| python3.6 |
affected |
TuxCare:Ubuntu:18.04 |
python3.6 |
— |
| python3.6-dev |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-dev |
— |
| python3.6-doc |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-doc |
— |
| python3.6-examples |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-examples |
— |
| python3.6-minimal |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-minimal |
— |
| python3.6-venv |
affected |
TuxCare:Ubuntu:18.04 |
python3.6-venv |
— |
Open SourcePoC exploit2023-09-12
Fix CVE(s): CVE-2022-48565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python2.7 |
affected |
TuxCare:Ubuntu:18.04 |
idle-python2.7 |
— |
| libpython2.7 |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7 |
— |
| libpython2.7-dev |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-dev |
— |
| libpython2.7-minimal |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-minimal |
— |
| libpython2.7-stdlib |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-stdlib |
— |
| libpython2.7-testsuite |
affected |
TuxCare:Ubuntu:18.04 |
libpython2.7-testsuite |
— |
| python2.7 |
affected |
TuxCare:Ubuntu:18.04 |
python2.7 |
— |
| python2.7-dev |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-dev |
— |
| python2.7-doc |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-doc |
— |
| python2.7-examples |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-examples |
— |
| python2.7-minimal |
affected |
TuxCare:Ubuntu:18.04 |
python2.7-minimal |
— |
Open SourcePoC exploitHIGH2023-09-12
Fix CVE(s): CVE-2022-48565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python3.5 |
— |
| libpython3.5 |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5 |
— |
| libpython3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-dev |
— |
| libpython3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-minimal |
— |
| libpython3.5-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-stdlib |
— |
| libpython3.5-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython3.5-testsuite |
— |
| python3.5 |
affected |
TuxCare:Ubuntu:16.04 |
python3.5 |
— |
| python3.5-dev |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-dev |
— |
| python3.5-doc |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-doc |
— |
| python3.5-examples |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-examples |
— |
| python3.5-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-minimal |
— |
| python3.5-venv |
affected |
TuxCare:Ubuntu:16.04 |
python3.5-venv |
— |
Open SourcePoC exploit2023-09-12
Fix CVE(s): CVE-2022-48565
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| idle-python2.7 |
affected |
TuxCare:Ubuntu:16.04 |
idle-python2.7 |
— |
| libpython2.7 |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7 |
— |
| libpython2.7-dev |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-dev |
— |
| libpython2.7-minimal |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-minimal |
— |
| libpython2.7-stdlib |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-stdlib |
— |
| libpython2.7-testsuite |
affected |
TuxCare:Ubuntu:16.04 |
libpython2.7-testsuite |
— |
| python2.7 |
affected |
TuxCare:Ubuntu:16.04 |
python2.7 |
— |
| python2.7-dev |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-dev |
— |
| python2.7-doc |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-doc |
— |
| python2.7-examples |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-examples |
— |
| python2.7-minimal |
affected |
TuxCare:Ubuntu:16.04 |
python2.7-minimal |
— |
Open SourcePoC exploitCRITICAL2023-09-28
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
golang-github-prometheus-node_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
golang-github-QubitProducts-exporter_exporter |
— |
| prometheus-postgres_exporter |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
prometheus-postgres_exporter |
— |
| scap-security-guide |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
scap-security-guide |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
spacecmd |
— |
Open SourcePoC exploitCRITICAL2023-09-28
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:EL-9:Update:Products:ManagerTools:Update |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:EL-9:Update:Products:ManagerTools:Update |
golang-github-prometheus-node_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
golang-github-QubitProducts-exporter_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:EL-9:Update:Products:ManagerTools:Update |
golang-github-QubitProducts-exporter_exporter |
— |
| prometheus-postgres_exporter |
affected |
SUSE:EL-9:Update:Products:ManagerTools:Update |
prometheus-postgres_exporter |
— |
| prometheus-postgres_exporter |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
prometheus-postgres_exporter |
— |
| scap-security-guide |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
scap-security-guide |
— |
| scap-security-guide |
affected |
SUSE:EL-9:Update:Products:ManagerTools:Update |
scap-security-guide |
— |
| spacecmd |
affected |
SUSE:EL-9:Update:Products:ManagerTools:Update |
spacecmd |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS |
spacecmd |
— |
Open SourcePoC exploitHIGH2023-09-28
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Proxy Module 4.3 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
openSUSE:Leap 15.5 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Client Tools 15 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
openSUSE:Leap 15.4 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Server Module 4.3 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Server Module 4.2 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Proxy Module 4.2 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 15 |
golang-github-prometheus-prometheus |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Client Tools 15 |
golang-github-QubitProducts-exporter_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Server Module 4.2 |
golang-github-QubitProducts-exporter_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
openSUSE:Leap 15.4 |
golang-github-QubitProducts-exporter_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Server Module 4.3 |
golang-github-QubitProducts-exporter_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Proxy Module 4.2 |
golang-github-QubitProducts-exporter_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
openSUSE:Leap 15.5 |
golang-github-QubitProducts-exporter_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Client Tools for SLE Micro 5 |
golang-github-QubitProducts-exporter_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Proxy Module 4.3 |
golang-github-QubitProducts-exporter_exporter |
— |
| grafana |
affected |
SUSE:Manager Client Tools 15 |
grafana |
— |
| prometheus-blackbox_exporter |
affected |
openSUSE:Leap 15.5 |
prometheus-blackbox_exporter |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Client Tools for SLE Micro 5 |
prometheus-blackbox_exporter |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Proxy Module 4.2 |
prometheus-blackbox_exporter |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Proxy Module 4.3 |
prometheus-blackbox_exporter |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Client Tools 15 |
prometheus-blackbox_exporter |
— |
| prometheus-blackbox_exporter |
affected |
openSUSE:Leap 15.4 |
prometheus-blackbox_exporter |
— |
| prometheus-postgres_exporter |
affected |
openSUSE:Leap 15.5 |
prometheus-postgres_exporter |
— |
| prometheus-postgres_exporter |
affected |
SUSE:Manager Server Module 4.2 |
prometheus-postgres_exporter |
— |
| prometheus-postgres_exporter |
affected |
SUSE:Manager Client Tools 15 |
prometheus-postgres_exporter |
— |
| prometheus-postgres_exporter |
affected |
openSUSE:Leap 15.4 |
prometheus-postgres_exporter |
— |
| python-pyvmomi |
affected |
SUSE:Manager Client Tools 15 |
python-pyvmomi |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 15 |
spacecmd |
— |
| spacecmd |
affected |
openSUSE:Leap 15.4 |
spacecmd |
— |
| spacecmd |
affected |
openSUSE:Leap 15.5 |
spacecmd |
— |
| supportutils-plugin-susemanager-client |
affected |
openSUSE:Leap 15.5 |
supportutils-plugin-susemanager-client |
— |
| supportutils-plugin-susemanager-client |
affected |
openSUSE:Leap 15.4 |
supportutils-plugin-susemanager-client |
— |
| supportutils-plugin-susemanager-client |
affected |
SUSE:Manager Client Tools 15 |
supportutils-plugin-susemanager-client |
— |
| uyuni-common-libs |
affected |
SUSE:Manager Client Tools 15 |
uyuni-common-libs |
— |
Open SourcePoC exploitHIGH2023-09-28
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Client Tools 12 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-prometheus-alertmanager |
affected |
SUSE:Manager Client Tools 12 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server 12 SP5 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Manager Client Tools 12 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 12 |
golang-github-prometheus-prometheus |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Client Tools 12 |
golang-github-QubitProducts-exporter_exporter |
— |
| grafana |
affected |
SUSE:Manager Client Tools 12 |
grafana |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Client Tools 12 |
prometheus-blackbox_exporter |
— |
| prometheus-postgres_exporter |
affected |
SUSE:Manager Client Tools 12 |
prometheus-postgres_exporter |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 12 |
spacecmd |
— |
| supportutils-plugin-susemanager-client |
affected |
SUSE:Manager Client Tools 12 |
supportutils-plugin-susemanager-client |
— |
| uyuni-common-libs |
affected |
SUSE:Manager Client Tools 12 |
uyuni-common-libs |
— |
GooglePoC exploitCRITICAL2023-09-06
The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command f...
CVEs:CVE-2023-39320
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
GooglePoC exploitCRITICAL2023-09-06
CVEs:CVE-2023-39320
GooglePoC exploit2023-09-06
The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.
CVEs:CVE-2023-39320
Open SourcePoC exploitCRITICAL2023-09-28
Security update for Golang Prometheus
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-prometheus-alertmanager |
affected |
SUSE:Manager Proxy Module 4.3 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-alertmanager |
affected |
SUSE:Manager Client Tools 15 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-alertmanager |
affected |
SUSE:Linux Enterprise Module for Package Hub 15 SP5 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-alertmanager |
affected |
SUSE:Manager Proxy Module 4.2 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-alertmanager |
affected |
openSUSE:Leap 15.4 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-alertmanager |
affected |
openSUSE:Leap 15.5 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Manager Client Tools for SLE Micro 5 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server 15 SP1-LTSS |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server 15 SP2-LTSS |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server 15 SP3-LTSS |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Manager Proxy 4.2 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Manager Server 4.2 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Enterprise Storage 7.1 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Module for Basesystem 15 SP4 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Linux Enterprise Module for Basesystem 15 SP5 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
openSUSE:Leap 15.5 |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-node_exporter |
affected |
openSUSE:Leap 15.4 |
golang-github-prometheus-node_exporter |
— |
Open SourcePoC exploitNONE2023-09-02
golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
openEuler:22.03-LTS-SP1 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-28
DEBIAN-CVE-2023-5186
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploit2023-09-27
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)
CVEs:CVE-2023-5186
GooglePoC exploitHIGH2023-09-27
CVEs:CVE-2023-5186
GooglePoC exploitCRITICAL2023-09-27
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)
CVEs:CVE-2023-5186
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39318 affecting package golang for versions less than 1.20.10-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39318 affecting package msft-golang for versions less than 1.20.10-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| msft-golang |
affected |
Azure Linux:2 |
msft-golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39318 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39318 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39318 affecting package golang for versions less than 1.20.10-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39318 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
DEBIAN-CVE-2023-39318
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
Open SourcePoC exploitCRITICAL2023-09-07
Improper handling of HTML-like comments in script contexts in html/template
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kind |
affected |
chainguard |
kind |
— |
| kind |
affected |
wolfi |
kind |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| stdlib |
affected |
Go |
stdlib |
— |
| stdlib |
affected |
Go |
— |
— |
GooglePoC exploit2023-09-06
The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack.
CVEs:CVE-2023-39318
GooglePoC exploitMEDIUM2023-09-06
CVEs:CVE-2023-39318
GooglePoC exploitCRITICAL2023-09-06
The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be ...
CVEs:CVE-2023-39318
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39319 affecting package golang for versions less than 1.20.10-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39319 affecting package msft-golang for versions less than 1.20.10-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| msft-golang |
affected |
Azure Linux:2 |
msft-golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39319 affecting package golang for versions less than 1.20.10-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39319 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39319 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
CVE-2023-39319 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitCRITICAL2023-09-08
DEBIAN-CVE-2023-39319
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
Open SourcePoC exploitCRITICAL2023-09-07
Improper handling of special tags within script contexts in html/template
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kind |
affected |
chainguard |
kind |
— |
| kind |
affected |
wolfi |
kind |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| stdlib |
affected |
Go |
stdlib |
— |
GooglePoC exploit2023-09-06
The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack.
CVEs:CVE-2023-39319
GooglePoC exploitMEDIUM2023-09-06
CVEs:CVE-2023-39319
GooglePoC exploitCRITICAL2023-09-06
The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated ...
CVEs:CVE-2023-39319
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploitCRITICAL2023-09-28
DEBIAN-CVE-2023-5187
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitCRITICAL2023-09-27
Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5187
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GooglePoC exploitHIGH2023-09-27
CVEs:CVE-2023-5187
GooglePoC exploit2023-09-27
Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-5187
Open SourcePoC exploitCRITICAL2023-09-22
grpc security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
openEuler:20.03-LTS-SP3 |
grpc |
— |
| grpc |
affected |
openEuler:22.03-LTS |
grpc |
— |
| grpc |
affected |
openEuler:22.03-LTS-SP1 |
grpc |
— |
| grpc |
affected |
openEuler:22.03-LTS-SP2 |
grpc |
— |
Open SourcePoC exploitHIGH2023-09-13
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
Open SourcePoC exploitHIGH2023-09-13
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
RubyGems |
grpc |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
| grpcio |
affected |
PyPI |
grpcio |
— |
| kube-fluentd-operator |
affected |
chainguard |
kube-fluentd-operator |
— |
| kube-fluentd-operator |
affected |
wolfi |
kube-fluentd-operator |
— |
Open SourcePoC exploitHIGH2023-09-13
CVE-2023-4785 affecting package grpc for versions less than 1.62.0-2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Azure Linux:3 |
grpc |
— |
Open SourcePoC exploitHIGH2023-09-13
DEBIAN-CVE-2023-4785
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Debian:11 |
grpc |
— |
| grpc |
affected |
Debian:12 |
grpc |
— |
| grpc |
affected |
Debian:13 |
grpc |
— |
| grpc |
affected |
Debian:14 |
grpc |
— |
Open SourcePoC exploitHIGH2023-09-13
BELL-CVE-2023-4785
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Alpaquita:stream |
grpc |
— |
| grpc |
affected |
Alpaquita:23 |
grpc |
— |
Open SourcePoC exploitCRITICAL2023-09-19
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
GooglePoC exploitMEDIUM2023-09-12
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4901
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GooglePoC exploitMEDIUM2023-09-12
CVEs:CVE-2023-4901
Open SourcePoC exploitMEDIUM2023-09-12
DEBIAN-CVE-2023-4901
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitMEDIUM2023-09-12
CVEs:CVE-2023-4905
GooglePoC exploitMEDIUM2023-09-12
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4905
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourcePoC exploitMEDIUM2023-09-12
DEBIAN-CVE-2023-4905
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitMEDIUM2023-09-12
Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-4907
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GooglePoC exploitMEDIUM2023-09-12
CVEs:CVE-2023-4907
Open SourcePoC exploitMEDIUM2023-09-12
DEBIAN-CVE-2023-4907
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
GooglePoC exploitMEDIUM2023-09-12
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4900
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GooglePoC exploitMEDIUM2023-09-12
CVEs:CVE-2023-4900
GooglePoC exploitMEDIUM2023-09-12
Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4902
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GooglePoC exploitMEDIUM2023-09-12
CVEs:CVE-2023-4902
GooglePoC exploitMEDIUM2023-09-12
CVEs:CVE-2023-4903
GooglePoC exploitMEDIUM2023-09-12
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-4903
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourcePoC exploitMEDIUM2023-09-12
DEBIAN-CVE-2023-4900
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourcePoC exploitMEDIUM2023-09-12
DEBIAN-CVE-2023-4902
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploitMEDIUM2023-09-12
DEBIAN-CVE-2023-4903
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitCRITICAL2023-09-12
Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-4906
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GooglePoC exploitMEDIUM2023-09-12
CVEs:CVE-2023-4906
Open SourcePoC exploitCRITICAL2023-09-12
DEBIAN-CVE-2023-4906
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitMEDIUM2023-09-12
CVEs:CVE-2023-4908
GooglePoC exploitMEDIUM2023-09-12
Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-4908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GooglePoC exploitMEDIUM2023-09-12
Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-4909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GooglePoC exploitMEDIUM2023-09-12
CVEs:CVE-2023-4909
Open SourcePoC exploitMEDIUM2023-09-12
DEBIAN-CVE-2023-4908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploitMEDIUM2023-09-12
DEBIAN-CVE-2023-4909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GooglePoC exploitCRITICAL2023-09-12
Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)
CVEs:CVE-2023-4904
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GooglePoC exploitMEDIUM2023-09-12
CVEs:CVE-2023-4904
Open SourcePoC exploitCRITICAL2023-09-12
DEBIAN-CVE-2023-4904
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourcePoC exploitCRITICAL2023-09-05
In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35681
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2023-09-05
CVEs:CVE-2023-35681
Open SourcePoC exploitMEDIUM2023-09-05
DEBIAN-CVE-2023-36308
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-disintegration-imaging |
affected |
Debian:12 |
golang-github-disintegration-imaging |
— |
| golang-github-disintegration-imaging |
affected |
Debian:11 |
golang-github-disintegration-imaging |
— |
| golang-github-disintegration-imaging |
affected |
Debian:13 |
golang-github-disintegration-imaging |
— |
| golang-github-disintegration-imaging |
affected |
Debian:14 |
golang-github-disintegration-imaging |
— |
Open SourcePoC exploitMEDIUM2023-09-05
In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to ...
CVEs:CVE-2023-35671
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2023-09-05
CVEs:CVE-2023-35671
GooglePoC exploitHIGH2023-09-05
CVEs:CVE-2023-35687
Open SourcePoC exploitHIGH2023-09-05
In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35687
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-09-15
CVEs:CVE-2023-36735
Open SourceCoalition ESS < 30%CRITICAL2023-09-12
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2023-36735
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-27
CVEs:CVE-2023-44216
Open SourceCoalition ESS < 30%CRITICAL2023-09-27
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. ...
CVEs:CVE-2023-44216
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| core_i7-10510u |
affected |
intel |
— |
— |
| core_i7-10610u |
affected |
intel |
— |
— |
| core_i7-11800h |
affected |
intel |
— |
— |
| core_i7-12700k |
affected |
intel |
— |
— |
| core_i7-8700 |
affected |
intel |
— |
— |
| geforce_rtx_2080_super |
affected |
nvidia |
— |
— |
| geforce_rtx_3060 |
affected |
nvidia |
— |
— |
| m1_mac_mini |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| pixel_6 |
affected |
google |
— |
— |
| ryzen_5_7600x |
affected |
amd |
— |
— |
| ryzen_7_4800u |
affected |
amd |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
| windows_10 |
affected |
microsoft |
— |
— |
| windows_11 |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-09-28
Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". ...
CVEs:CVE-2023-39323
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-09-28
CVEs:CVE-2023-39323
GoogleCoalition ESS < 30%2023-09-28
Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.
CVEs:CVE-2023-39323
Open SourceCoalition ESS < 30%2023-09-07
Panic when processing post-handshake message on QUIC connections in crypto/tls
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| stdlib |
affected |
Go |
stdlib |
— |
GoogleCoalition ESS < 30%2023-09-06
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
CVEs:CVE-2023-39321
GoogleCoalition ESS < 30%HIGH2023-09-06
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
CVEs:CVE-2023-39321
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-06
CVEs:CVE-2023-39321
Open SourceCoalition ESS < 30%HIGH2023-09-07
Memory exhaustion in QUIC connection handling in crypto/tls
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| metrics-server |
affected |
wolfi |
metrics-server |
— |
| metrics-server |
affected |
chainguard |
metrics-server |
— |
| stdlib |
affected |
Go |
stdlib |
— |
GoogleCoalition ESS < 30%HIGH2023-09-06
QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65...
CVEs:CVE-2023-39322
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-06
CVEs:CVE-2023-39322
GoogleCoalition ESS < 30%2023-09-06
QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.
CVEs:CVE-2023-39322
Open SourceCoalition ESS < 30%MEDIUM2023-09-05
DEBIAN-CVE-2023-4764
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-05
CVEs:CVE-2023-4764
GoogleCoalition ESS < 30%MEDIUM2023-09-05
Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4764
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%2023-09-05
Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-4764
Open SourceCoalition ESS < 30%HIGH2023-09-22
DEBIAN-CVE-2023-42821
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-gomarkdown-markdown |
affected |
Debian:12 |
golang-github-gomarkdown-markdown |
— |
| golang-github-gomarkdown-markdown |
affected |
Debian:13 |
golang-github-gomarkdown-markdown |
— |
| golang-github-gomarkdown-markdown |
affected |
Debian:14 |
golang-github-gomarkdown-markdown |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-15
CVEs:CVE-2023-36727
Open SourceCoalition ESS < 30%MEDIUM2023-09-12
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2023-36727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-15
CVEs:CVE-2023-36562
Open SourceCoalition ESS < 30%CRITICAL2023-09-12
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2023-36562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-06
Jenkins Google Login Plugin non-constant time token comparison
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-login |
affected |
Maven |
org.jenkins-ci.plugins:google-login |
— |
GoogleCoalition ESS < 30%HIGH2023-09-06
Jenkins Google Login Plugin non-constant time token comparison
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-login |
affected |
Maven |
org.jenkins-ci.plugins:google-login |
— |
GoogleCoalition ESS < 30%2023-09-06
Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.
CVEs:CVE-2023-41936
GoogleCoalition ESS < 30%HIGH2023-09-06
Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.
CVEs:CVE-2023-41936
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_login |
affected |
jenkins |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-06
Jenkins Google Login Plugin non-constant time token comparison
CVEs:CVE-2023-41936
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-login |
affected |
Maven |
org.jenkins-ci.plugins:google-login |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-09-19
A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if ...
CVEs:CVE-2023-41387
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| flutter_downloader |
affected |
patreon |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2023-09-19
CVEs:CVE-2023-41387
GoogleCoalition ESS < 30%MEDIUM2023-09-12
CVEs:CVE-2023-4887
GoogleCoalition ESS < 30%HIGH2023-09-12
The Google Maps Plugin by Intergeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes...
CVEs:CVE-2023-4887
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_maps_plugin_by_intergeo |
affected |
themeisle |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-05
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible privilege escalation due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2023-35658
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-05
CVEs:CVE-2023-35658
GoogleCoalition ESS < 30%MEDIUM2023-09-05
CVEs:CVE-2023-35683
Open SourceCoalition ESS < 30%HIGH2023-09-05
In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2023-35683
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-05
In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to an integer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35684
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-05
CVEs:CVE-2023-35684
Open SourceCoalition ESS < 30%CRITICAL2023-09-27
The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app. The attacker's app, if i...
CVEs:CVE-2023-44123
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-27
CVEs:CVE-2023-44123
Open SourceCoalition ESS < 30%CRITICAL2023-09-27
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The attacker's app, ...
CVEs:CVE-2023-44125
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-27
CVEs:CVE-2023-44125
Open SourceCoalition ESS < 30%CRITICAL2023-09-27
he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as contact detail...
CVEs:CVE-2023-44127
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-09-27
CVEs:CVE-2023-44127
GoogleCoalition ESS < 30%LOW2023-09-27
CVEs:CVE-2023-44126
Open SourceCoalition ESS < 30%CRITICAL2023-09-27
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data suc...
CVEs:CVE-2023-44126
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2023-09-01
ASB-A-285903020
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
| vendor/qcom/opensource/graphics-kernel |
affected |
platform |
platform/vendor/qcom/opensource/graphics-kernel |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-09-05
In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user on the same device due to a logic error in the code. This could lead to local information disclosure with no addi...
CVEs:CVE-2023-35675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-05
CVEs:CVE-2023-35675
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20849
Open SourceCoalition ESS < 30%HIGH2023-09-04
In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Iss...
CVEs:CVE-2023-20849
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-05
CVEs:CVE-2023-35669
Open SourceCoalition ESS < 30%HIGH2023-09-05
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed...
CVEs:CVE-2023-35669
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-05
CVEs:CVE-2023-35679
Open SourceCoalition ESS < 30%MEDIUM2023-09-05
In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
CVEs:CVE-2023-35679
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-05
CVEs:CVE-2023-35682
Open SourceCoalition ESS < 30%HIGH2023-09-05
In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary components due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVEs:CVE-2023-35682
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20850
Open SourceCoalition ESS < 30%HIGH2023-09-04
In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433...
CVEs:CVE-2023-20850
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Iss...
CVEs:CVE-2023-20841
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20841
Open SourceCoalition ESS < 30%HIGH2023-09-04
In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS0735425...
CVEs:CVE-2023-20842
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20842
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20848
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433;...
CVEs:CVE-2023-20848
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20840
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS0732...
CVEs:CVE-2023-20840
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-05
CVEs:CVE-2023-35665
Open SourceCoalition ESS < 30%HIGH2023-09-05
In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2023-35665
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-32812
Open SourceCoalition ESS < 30%HIGH2023-09-04
In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017365...
CVEs:CVE-2023-32812
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-32809
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-32808
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340119; ...
CVEs:CVE-2023-20843
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20843
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; ...
CVEs:CVE-2023-20844
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20844
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07197795; Issue...
CVEs:CVE-2023-20845
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20845
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20846
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354023; ...
CVEs:CVE-2023-20846
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue...
CVEs:CVE-2023-20839
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20839
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In bluetooth driver, there is a possible read and write access to registers due to improper access control of register interface. This could lead to local leak of sensitive information with System execution privileges needed. User interaction is not ne...
CVEs:CVE-2023-32809
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In bluetooth driver, there is a possible read and write access to registers due to improper access control of register interface. This could lead to local leak of sensitive information with System execution privileges needed. User interaction is not ne...
CVEs:CVE-2023-32808
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-05
CVEs:CVE-2023-35677
Open SourceCoalition ESS < 30%MEDIUM2023-09-05
In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges neede...
CVEs:CVE-2023-35677
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-27
CVEs:CVE-2023-44122
Open SourceCoalition ESS < 30%CRITICAL2023-09-27
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app...
CVEs:CVE-2023-44122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-05
In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35666
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-05
CVEs:CVE-2023-35666
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-32805
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue...
CVEs:CVE-2023-20847
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20847
Open SourceCoalition ESS < 30%HIGH2023-09-04
In seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07992786; Issue I...
CVEs:CVE-2023-20837
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20837
Open SourceCoalition ESS < 30%HIGH2023-09-04
In power, there is a possible out of bounds write due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08102892; Issue ID:...
CVEs:CVE-2023-32805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-32817
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-32815
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; ...
CVEs:CVE-2023-32817
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08037801; ...
CVEs:CVE-2023-32815
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%LOW2023-09-27
The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this functionality...
CVEs:CVE-2023-44129
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-09-27
CVEs:CVE-2023-44129
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2022-47353
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vdsp device, there is a possible system crash due to improper input validation.This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2022-47353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2022-48453
Open SourceCoalition ESS < 30%CRITICAL2023-09-04
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2022-48453
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2022-47352
Open SourceCoalition ESS < 30%HIGH2023-09-04
In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2022-47352
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2023-09-27
The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is that the app...
CVEs:CVE-2023-44124
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-09-27
CVEs:CVE-2023-44124
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In imgsys, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326...
CVEs:CVE-2023-20838
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| linux_kernel |
affected |
linux |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20838
Open SourceCoalition ESS < 30%HIGH2023-09-04
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ...
CVEs:CVE-2023-20828
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| rdk-b |
affected |
rdkcentral |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20828
Open SourceCoalition ESS < 30%HIGH2023-09-04
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ...
CVEs:CVE-2023-20829
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| rdk-b |
affected |
rdkcentral |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20829
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20830
Open SourceCoalition ESS < 30%HIGH2023-09-04
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ...
CVEs:CVE-2023-20830
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| rdk-b |
affected |
rdkcentral |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20831
Open SourceCoalition ESS < 30%HIGH2023-09-04
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ...
CVEs:CVE-2023-20831
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| rdk-b |
affected |
rdkcentral |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20832
Open SourceCoalition ESS < 30%HIGH2023-09-04
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ...
CVEs:CVE-2023-20832
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| rdk-b |
affected |
rdkcentral |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937113; Issue ID...
CVEs:CVE-2023-20821
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| rdk-b |
affected |
rdkcentral |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20821
Open SourceCoalition ESS < 30%HIGH2023-09-04
In netdagent, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944012; Issu...
CVEs:CVE-2023-20822
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20822
Open SourceCoalition ESS < 30%CRITICAL2023-09-04
In gnss service, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed
CVEs:CVE-2023-38553
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38553
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20836
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In camsys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07505629; Issue ID:...
CVEs:CVE-2023-20836
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38468
Open SourceCoalition ESS < 30%CRITICAL2023-09-04
In urild service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-38468
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; I...
CVEs:CVE-2023-20833
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20833
Open SourceCoalition ESS < 30%HIGH2023-09-04
In Ifaa service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2022-48452
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2022-48452
Open SourceCoalition ESS < 30%HIGH2023-09-05
In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges...
CVEs:CVE-2023-35667
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-05
CVEs:CVE-2023-35667
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20851
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In stc, there is a possible out of bounds read due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08048635; Issue ID: ALPS08048635.
CVEs:CVE-2023-20851
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In cmdq, there is a possible out of bounds read due to an incorrect status check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08021592; Issue ID: ALP...
CVEs:CVE-2023-20823
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20823
Open SourceCoalition ESS < 30%CRITICAL2023-09-04
In urild service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-38467
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38467
GoogleCoalition ESS < 30%MEDIUM2023-09-05
CVEs:CVE-2023-35664
Open SourceCoalition ESS < 30%MEDIUM2023-09-05
In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2023-35664
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-33916
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-33917
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-33918
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-38436
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38436
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38437
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-38437
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-38438
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38438
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-38439
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38439
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-33917
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-33918
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-33916
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38554
Open SourceCoalition ESS < 30%CRITICAL2023-09-04
In wcn bsp driver, there is a possible out of bounds write due to a missing bounds check.This could lead to local denial of service with no additional execution privileges
CVEs:CVE-2023-38554
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38449
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38449
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38450
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38450
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38451
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38451
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38452
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38452
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38453
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38453
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38455
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38455
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38456
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38456
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38458
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38458
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38459
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38459
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38460
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38460
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38464
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38464
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38443
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38443
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
CVEs:CVE-2023-38444
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2023-09-04
CVEs:CVE-2023-38444
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20825
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07...
CVEs:CVE-2023-20825
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20826
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07978550...
CVEs:CVE-2023-20826
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20824
Open SourceCoalition ESS < 30%MEDIUM2023-09-04
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07...
CVEs:CVE-2023-20824
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-38466
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38466
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-38454
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38454
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38465
Open SourceCoalition ESS < 30%HIGH2023-09-04
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-38465
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-38440
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38440
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38441
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-38441
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38442
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVEs:CVE-2023-38442
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38447
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
CVEs:CVE-2023-38447
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
CVEs:CVE-2023-38448
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38448
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38457
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
CVEs:CVE-2023-38457
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38461
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
CVEs:CVE-2023-38461
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38462
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
CVEs:CVE-2023-38462
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38463
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
CVEs:CVE-2023-38463
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38445
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
CVEs:CVE-2023-38445
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
CVEs:CVE-2023-38446
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-38446
Open SourceCoalition ESS < 30%MEDIUM2023-09-27
he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are fi...
CVEs:CVE-2023-44128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2023-09-27
CVEs:CVE-2023-44128
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20834
Open SourceCoalition ESS < 30%HIGH2023-09-04
In pda, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608514; Issue ID: ALPS07608514.
CVEs:CVE-2023-20834
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20835
Open SourceCoalition ESS < 30%HIGH2023-09-04
In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS0732...
CVEs:CVE-2023-20835
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| iot_yocto |
affected |
mediatek |
— |
— |
| yocto |
affected |
linuxfoundation |
— |
— |
Open SourceCoalition ESS < 30%HIGH2023-09-04
In ims service, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937105; Issue ID: ...
CVEs:CVE-2023-20827
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2023-09-04
CVEs:CVE-2023-20827
GoogleEPSS <= 49%CRITICAL2023-09-12
CVEs:CVE-2023-29332
Open SourceEPSS <= 49%CRITICAL2023-09-12
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVEs:CVE-2023-29332
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| azure_kubernetes_service |
affected |
microsoft |
— |
— |
Open SourceEPSS <= 49%HIGH2023-09-25
x/net/html Vulnerable to DoS During HTML Parsing
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourceEPSS <= 49%HIGH2023-09-25
x/net/html Vulnerable to DoS During HTML Parsing
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourceEPSS <= 49%HIGH2023-09-05
Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read arbitrary file with system privilege.
CVEs:CVE-2023-30706
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%HIGH2023-09-05
CVEs:CVE-2023-30706
Open SourceEPSS <= 49%HIGH2023-09-05
Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.
CVEs:CVE-2023-30714
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%MEDIUM2023-09-05
CVEs:CVE-2023-30714
GoogleEPSS <= 49%HIGH2023-09-05
CVEs:CVE-2023-35673
Open SourceEPSS <= 49%HIGH2023-09-05
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2023-35673
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%MEDIUM2023-09-05
Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.
CVEs:CVE-2023-30721
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%MEDIUM2023-09-05
CVEs:CVE-2023-30721
Open SourceEPSS <= 49%HIGH2023-09-05
Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege.
CVEs:CVE-2023-30707
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%HIGH2023-09-05
CVEs:CVE-2023-30707
GoogleEPSS <= 49%LOW2023-09-05
CVEs:CVE-2023-30719
Open SourceEPSS <= 49%MEDIUM2023-09-05
Exposure of Sensitive Information vulnerability in InboundSmsHandler prior to SMR Sep-2023 Release 1 allows local attackers to access certain message data.
CVEs:CVE-2023-30719
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%MEDIUM2023-09-05
CVEs:CVE-2023-30716
Open SourceEPSS <= 49%MEDIUM2023-09-05
Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to trigger certain commands.
CVEs:CVE-2023-30716
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceEPSS <= 49%MEDIUM2023-09-05
Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.
CVEs:CVE-2023-30718
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleEPSS <= 49%LOW2023-09-05
CVEs:CVE-2023-30718
GoogleEPSS <= 49%MEDIUM2023-09-05
CVEs:CVE-2023-35680
Open SourceEPSS <= 49%MEDIUM2023-09-05
In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2023-35680
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2023-09-05
In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges need...
CVEs:CVE-2023-35670
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2023-09-05
CVEs:CVE-2023-35670
GoogleEPSS <= 49%HIGH2023-09-05
CVEs:CVE-2023-35676
Open SourceEPSS <= 49%HIGH2023-09-05
In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed...
CVEs:CVE-2023-35676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceAll remaining2023-09-13
Paths outside of the rootfs could be produced on Windows in github.com/cyphar/filepath-securejoin
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cadvisor |
affected |
chainguard |
cadvisor |
— |
| cadvisor |
affected |
wolfi |
cadvisor |
— |
| ctop |
affected |
chainguard |
ctop |
— |
| ctop |
affected |
wolfi |
ctop |
— |
| cyphar/filepath-securejoin |
affected |
github.com |
github.com/cyphar/filepath-securejoin |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-image-automation-controller |
affected |
wolfi |
flux-image-automation-controller |
— |
| flux-image-automation-controller |
affected |
chainguard |
flux-image-automation-controller |
— |
| flux-kustomize-controller |
affected |
wolfi |
flux-kustomize-controller |
— |
| flux-kustomize-controller |
affected |
chainguard |
flux-kustomize-controller |
— |
| flux-notification-controller |
affected |
chainguard |
flux-notification-controller |
— |
| flux-notification-controller |
affected |
wolfi |
flux-notification-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm-3 |
affected |
wolfi |
helm-3 |
— |
| helm-3 |
affected |
chainguard |
helm-3 |
— |
| helm-4 |
affected |
chainguard |
helm-4 |
— |
| helm-4 |
affected |
wolfi |
helm-4 |
— |
| helm-push |
affected |
chainguard |
helm-push |
— |
| helm-push |
affected |
wolfi |
helm-push |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| node-problem-detector-0.8 |
affected |
chainguard |
node-problem-detector-0.8 |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| runc |
affected |
wolfi |
runc |
— |
| runc |
affected |
chainguard |
runc |
— |
| tomcat-8.5.87 |
affected |
chainguard |
tomcat-8.5.87 |
— |
| up |
affected |
chainguard |
up |
— |
| up |
affected |
wolfi |
up |
— |
| zot |
affected |
chainguard |
zot |
— |
| zot |
affected |
wolfi |
zot |
— |
GoogleAll remaining2023-09-07
SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cyphar/filepath-securejoin |
affected |
github.com |
github.com/cyphar/filepath-securejoin |
— |
Open SourceAll remaining2023-09-07
SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| argo-cd-2.7 |
affected |
chainguard |
argo-cd-2.7 |
— |
| argo-cd-2.7 |
affected |
wolfi |
argo-cd-2.7 |
— |
| argo-cd-2.8 |
affected |
chainguard |
argo-cd-2.8 |
— |
| argo-cd-2.8 |
affected |
wolfi |
argo-cd-2.8 |
— |
| cadvisor |
affected |
wolfi |
cadvisor |
— |
| cadvisor |
affected |
chainguard |
cadvisor |
— |
| ctop |
affected |
wolfi |
ctop |
— |
| ctop |
affected |
chainguard |
ctop |
— |
| cyphar/filepath-securejoin |
affected |
github.com |
— |
— |
| cyphar/filepath-securejoin |
affected |
github.com |
github.com/cyphar/filepath-securejoin |
— |
| cyphar/filepath-securejoin |
affected |
github.com |
github.com/cyphar/filepath-securejoin |
— |
| flux-0 |
affected |
chainguard |
flux-0 |
— |
| flux-0.37 |
affected |
chainguard |
flux-0.37 |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-helm-controller-0 |
affected |
chainguard |
flux-helm-controller-0 |
— |
| flux-helm-controller-0.37 |
affected |
chainguard |
flux-helm-controller-0.37 |
— |
| flux-image-automation-controller |
affected |
wolfi |
flux-image-automation-controller |
— |
| flux-image-automation-controller |
affected |
chainguard |
flux-image-automation-controller |
— |
| flux-kustomize-controller |
affected |
chainguard |
flux-kustomize-controller |
— |
| flux-kustomize-controller |
affected |
wolfi |
flux-kustomize-controller |
— |
| flux-kustomize-controller-0 |
affected |
chainguard |
flux-kustomize-controller-0 |
— |
| flux-kustomize-controller-0.37 |
affected |
chainguard |
flux-kustomize-controller-0.37 |
— |
| flux-notification-controller |
affected |
chainguard |
flux-notification-controller |
— |
| flux-notification-controller |
affected |
wolfi |
flux-notification-controller |
— |
| flux-notification-controller-0 |
affected |
chainguard |
flux-notification-controller-0 |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| flux-source-controller-0 |
affected |
chainguard |
flux-source-controller-0 |
— |
| flux-source-controller-0.37 |
affected |
chainguard |
flux-source-controller-0.37 |
— |
| github.com/cyphar/filepath-securejoin |
affected |
Go |
github.com/cyphar/filepath-securejoin |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm-3 |
affected |
wolfi |
helm-3 |
— |
| helm-3 |
affected |
chainguard |
helm-3 |
— |
| helm-4 |
affected |
wolfi |
helm-4 |
— |
| helm-4 |
affected |
chainguard |
helm-4 |
— |
| helm-push |
affected |
wolfi |
helm-push |
— |
| helm-push |
affected |
chainguard |
helm-push |
— |
| istio-operator-1.19 |
affected |
wolfi |
istio-operator-1.19 |
— |
| istio-operator-1.19 |
affected |
chainguard |
istio-operator-1.19 |
— |
| istio-pilot-agent-1.18 |
affected |
chainguard |
istio-pilot-agent-1.18 |
— |
| istio-pilot-agent-1.18 |
affected |
wolfi |
istio-pilot-agent-1.18 |
— |
| istio-pilot-discovery-1.19 |
affected |
chainguard |
istio-pilot-discovery-1.19 |
— |
| istio-pilot-discovery-1.19 |
affected |
wolfi |
istio-pilot-discovery-1.19 |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kyverno |
affected |
wolfi |
kyverno |
— |
| kyverno |
affected |
chainguard |
kyverno |
— |
| node-problem-detector-0.8 |
affected |
chainguard |
node-problem-detector-0.8 |
— |
| node-problem-detector-0.8 |
affected |
wolfi |
node-problem-detector-0.8 |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| runc |
affected |
chainguard |
runc |
— |
| runc |
affected |
wolfi |
runc |
— |
| tomcat-8.5.87 |
affected |
chainguard |
tomcat-8.5.87 |
— |
| up |
affected |
wolfi |
up |
— |
| up |
affected |
chainguard |
up |
— |
| zot |
affected |
wolfi |
zot |
— |
| zot |
affected |
chainguard |
zot |
— |
Open SourceAll remaining2023-09-05
Security update for kubernetes1.18
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise Server 15 SP2-LTSS |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise Server 15 SP3-LTSS |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Enterprise Storage 7 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Enterprise Storage 7.1 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
openSUSE:Leap 15.5 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
openSUSE:Leap 15.4 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP4 |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS |
kubernetes1.18 |
— |
| kubernetes1.18 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS |
kubernetes1.18 |
— |