MGASA-2023-0355
New chromium-browser-stable 120.0.6099.129 fixes bugs and vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 21 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
New chromium-browser-stable 120.0.6099.129 fixes bugs and vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
DEBIAN-CVE-2023-7024
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-7024
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-7024
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2023-7024
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-7024
ASB-A-300941008
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-299649795
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-266568298
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
Man-in-the-middle attacker can compromise integrity of secure channel in golang.org/x/crypto
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | wolfi | aactl | — |
| aactl | affected | chainguard | aactl | — |
| actions-runner-controller | affected | wolfi | actions-runner-controller | — |
| actions-runner-controller | affected | chainguard | actions-runner-controller | — |
| amass | affected | chainguard | amass | — |
| amass | affected | wolfi | amass | — |
| apko | affected | chainguard | apko | — |
| apko | affected | wolfi | apko | — |
| argo-workflows | affected | wolfi | argo-workflows | — |
| argo-workflows | affected | chainguard | argo-workflows | — |
| atlantis | affected | chainguard | atlantis | — |
| atlantis | affected | wolfi | atlantis | — |
| atlantis-fips | affected | chainguard | atlantis-fips | — |
| azure-aad-pod-identity-mic | affected | chainguard | azure-aad-pod-identity-mic | — |
| bank-vaults | affected | wolfi | bank-vaults | — |
| bank-vaults | affected | chainguard | bank-vaults | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| bom | affected | wolfi | bom | — |
| bom | affected | chainguard | bom | — |
| boring-registry | affected | chainguard | boring-registry | — |
| boring-registry | affected | wolfi | boring-registry | — |
| buf | affected | chainguard | buf | — |
| buf | affected | wolfi | buf | — |
| buildkitd | affected | chainguard | buildkitd | — |
| buildkitd | affected | wolfi | buildkitd | — |
| caddy | affected | chainguard | caddy | — |
| caddy | affected | wolfi | caddy | — |
| cadvisor | affected | chainguard | cadvisor | — |
| cadvisor | affected | wolfi | cadvisor | — |
| certificate-transparency | affected | chainguard | certificate-transparency | — |
| certificate-transparency | affected | wolfi | certificate-transparency | — |
| certificate-transparency-fips | affected | chainguard | certificate-transparency-fips | — |
| cfssl | affected | wolfi | cfssl | — |
| cfssl | affected | chainguard | cfssl | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cloudflared | affected | wolfi | cloudflared | — |
| cloudflared | affected | chainguard | cloudflared | — |
| cloud-sql-proxy-fips | affected | chainguard | cloud-sql-proxy-fips | — |
| conftest | affected | chainguard | conftest | — |
| conftest | affected | wolfi | conftest | — |
| conftest-fips | affected | chainguard | conftest-fips | — |
| cortex | affected | wolfi | cortex | — |
| cortex | affected | chainguard | cortex | — |
| cosign | affected | chainguard | cosign | — |
| cosign | affected | wolfi | cosign | — |
| cosign-fips | affected | chainguard | cosign-fips | — |
| crossplane-provider-aws | affected | chainguard | crossplane-provider-aws | — |
| crossplane-provider-aws | affected | wolfi | crossplane-provider-aws | — |
| crossplane-provider-azure | affected | wolfi | crossplane-provider-azure | — |
| crossplane-provider-azure | affected | chainguard | crossplane-provider-azure | — |
| crossplane-provider-azure-authorization | affected | wolfi | crossplane-provider-azure-authorization | — |
| crossplane-provider-azure-authorization | affected | chainguard | crossplane-provider-azure-authorization | — |
| crossplane-provider-azure-managedidentity | affected | wolfi | crossplane-provider-azure-managedidentity | — |
| crossplane-provider-azure-managedidentity | affected | chainguard | crossplane-provider-azure-managedidentity | — |
| crossplane-provider-azure-sql | affected | chainguard | crossplane-provider-azure-sql | — |
| crossplane-provider-azure-sql | affected | wolfi | crossplane-provider-azure-sql | — |
| crossplane-provider-azure-storage | affected | chainguard | crossplane-provider-azure-storage | — |
| crossplane-provider-azure-storage | affected | wolfi | crossplane-provider-azure-storage | — |
| crossplane-provider-family-azure | affected | chainguard | crossplane-provider-family-azure | — |
| crossplane-provider-family-azure | affected | wolfi | crossplane-provider-family-azure | — |
| dex | affected | wolfi | dex | — |
| dex | affected | chainguard | dex | — |
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| dgraph | affected | chainguard | dgraph | — |
| dgraph | affected | wolfi | dgraph | — |
| docker-credential-acr-env | affected | chainguard | docker-credential-acr-env | — |
| docker-credential-acr-env | affected | wolfi | docker-credential-acr-env | — |
| dockerize | affected | chainguard | dockerize | — |
| dockerize | affected | wolfi | dockerize | — |
| dockerize-fips | affected | chainguard | dockerize-fips | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| eksctl | affected | wolfi | eksctl | — |
| eksctl | affected | chainguard | eksctl | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| ferretdb | affected | chainguard | ferretdb | — |
| ferretdb | affected | wolfi | ferretdb | — |
| flux | affected | wolfi | flux | — |
| flux | affected | chainguard | flux | — |
| flux-helm-controller | affected | wolfi | flux-helm-controller | — |
| flux-helm-controller | affected | chainguard | flux-helm-controller | — |
| flux-image-automation-controller | affected | chainguard | flux-image-automation-controller | — |
| flux-image-automation-controller | affected | wolfi | flux-image-automation-controller | — |
| flux-image-reflector-controller | affected | chainguard | flux-image-reflector-controller | — |
| flux-image-reflector-controller | affected | wolfi | flux-image-reflector-controller | — |
| flux-kustomize-controller | affected | chainguard | flux-kustomize-controller | — |
| flux-kustomize-controller | affected | wolfi | flux-kustomize-controller | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| fq | affected | wolfi | fq | — |
| fq | affected | chainguard | fq | — |
| frp | affected | chainguard | frp | — |
| frp | affected | wolfi | frp | — |
| fulcio | affected | wolfi | fulcio | — |
| fulcio | affected | chainguard | fulcio | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| gh | affected | wolfi | gh | — |
| gh | affected | chainguard | gh | — |
| git-lfs | affected | wolfi | git-lfs | — |
| git-lfs | affected | chainguard | git-lfs | — |
| gitness | affected | chainguard | gitness | — |
| gitness | affected | wolfi | gitness | — |
| gitsign | affected | chainguard | gitsign | — |
| gitsign | affected | wolfi | gitsign | — |
| gobuster | affected | chainguard | gobuster | — |
| gobuster | affected | wolfi | gobuster | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-licenses | affected | wolfi | go-licenses | — |
| gomplate | affected | wolfi | gomplate | — |
| gomplate | affected | chainguard | gomplate | — |
| grpc-health-probe | affected | wolfi | grpc-health-probe | — |
| grpc-health-probe | affected | chainguard | grpc-health-probe | — |
| grype | affected | chainguard | grype | — |
| grype | affected | wolfi | grype | — |
| haproxy-ingress | affected | chainguard | haproxy-ingress | — |
| haproxy-ingress | affected | wolfi | haproxy-ingress | — |
| helm | affected | chainguard | helm | — |
| helm | affected | wolfi | helm | — |
| helm-3 | affected | chainguard | helm-3 | — |
| helm-3 | affected | wolfi | helm-3 | — |
| helm-4 | affected | wolfi | helm-4 | — |
| helm-4 | affected | chainguard | helm-4 | — |
| helm-push | affected | wolfi | helm-push | — |
| helm-push | affected | chainguard | helm-push | — |
| hugo | affected | chainguard | hugo | — |
| hugo | affected | wolfi | hugo | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| k3s | affected | chainguard | k3s | — |
| k3s | affected | wolfi | k3s | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| kaf | affected | wolfi | kaf | — |
| kaf | affected | chainguard | kaf | — |
| kiam | affected | chainguard | kiam | — |
| ko | affected | wolfi | ko | — |
| ko | affected | chainguard | ko | — |
| ko-fips | affected | chainguard | ko-fips | — |
| kots | affected | wolfi | kots | — |
| kots | affected | chainguard | kots | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kube-fluentd-operator | affected | wolfi | kube-fluentd-operator | — |
| kube-fluentd-operator | affected | chainguard | kube-fluentd-operator | — |
| kube-logging-logging-operator-3.17 | affected | chainguard | kube-logging-logging-operator-3.17 | — |
| kube-oidc-proxy | affected | chainguard | kube-oidc-proxy | — |
| kube-rbac-proxy | affected | wolfi | kube-rbac-proxy | — |
| kube-rbac-proxy | affected | chainguard | kube-rbac-proxy | — |
| kubernetes-1.27 | affected | wolfi | kubernetes-1.27 | — |
| kubernetes-1.28 | affected | chainguard | kubernetes-1.28 | — |
| kubernetes-1.28 | affected | wolfi | kubernetes-1.28 | — |
| kubernetes-1.29 | affected | wolfi | kubernetes-1.29 | — |
| kubernetes-1.29 | affected | chainguard | kubernetes-1.29 | — |
| kubernetes-dashboard | affected | wolfi | kubernetes-dashboard | — |
| kubernetes-dashboard | affected | chainguard | kubernetes-dashboard | — |
| kubernetes-event-exporter | affected | wolfi | kubernetes-event-exporter | — |
| kubernetes-event-exporter | affected | chainguard | kubernetes-event-exporter | — |
| kubescape | affected | wolfi | kubescape | — |
| kubescape | affected | chainguard | kubescape | — |
| kube-state-metrics | affected | chainguard | kube-state-metrics | — |
| kube-state-metrics | affected | wolfi | kube-state-metrics | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| kube-state-metrics-fips | affected | chainguard | kube-state-metrics-fips | — |
| kubewatch | affected | chainguard | kubewatch | — |
| kubewatch | affected | wolfi | kubewatch | — |
| kyverno-policy-reporter | affected | chainguard | kyverno-policy-reporter | — |
| kyverno-policy-reporter | affected | wolfi | kyverno-policy-reporter | — |
| libssh | affected | wolfi | libssh | — |
| libssh | affected | chainguard | libssh | — |
| libssh2 | affected | wolfi | libssh2 | — |
| libssh2 | affected | chainguard | libssh2 | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| melange | affected | chainguard | melange | — |
| melange | affected | wolfi | melange | — |
| memcached-exporter | affected | wolfi | memcached-exporter | — |
| memcached-exporter | affected | chainguard | memcached-exporter | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server | affected | chainguard | metrics-server | — |
| metrics-server-fips | affected | chainguard | metrics-server-fips | — |
| mongo-tools | affected | wolfi | mongo-tools | — |
| mongo-tools | affected | chainguard | mongo-tools | — |
| nats | affected | wolfi | nats | — |
| nats | affected | chainguard | nats | — |
| nats-server | affected | chainguard | nats-server | — |
| nats-server | affected | wolfi | nats-server | — |
| nerdctl | affected | chainguard | nerdctl | — |
| nerdctl | affected | wolfi | nerdctl | — |
| nfs-subdir-external-provisioner | affected | wolfi | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner | affected | chainguard | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner-fips | affected | chainguard | nfs-subdir-external-provisioner-fips | — |
| node-problem-detector-0.8 | affected | chainguard | node-problem-detector-0.8 | — |
| nri-kafka | affected | chainguard | nri-kafka | — |
| nri-kafka | affected | wolfi | nri-kafka | — |
| nri-mssql | affected | wolfi | nri-mssql | — |
| nri-mssql | affected | chainguard | nri-mssql | — |
| nsc | affected | wolfi | nsc | — |
| nsc | affected | chainguard | nsc | — |
| oauth2-proxy | affected | chainguard | oauth2-proxy | — |
| oauth2-proxy | affected | wolfi | oauth2-proxy | — |
| ollama | affected | chainguard | ollama | — |
| ollama | affected | wolfi | ollama | — |
| prometheus-adapter | affected | wolfi | prometheus-adapter | — |
| prometheus-adapter | affected | chainguard | prometheus-adapter | — |
| prometheus-adapter-0.10 | affected | chainguard | prometheus-adapter-0.10 | — |
| prometheus-adapter-fips | affected | chainguard | prometheus-adapter-fips | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-alertmanager | affected | wolfi | prometheus-alertmanager | — |
| prometheus-alertmanager | affected | chainguard | prometheus-alertmanager | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-blackbox-exporter | affected | chainguard | prometheus-blackbox-exporter | — |
| prometheus-elasticsearch-exporter-fips | affected | chainguard | prometheus-elasticsearch-exporter-fips | — |
| prometheus-mongodb-exporter | affected | chainguard | prometheus-mongodb-exporter | — |
| prometheus-mongodb-exporter-0.37 | affected | chainguard | prometheus-mongodb-exporter-0.37 | — |
| prometheus-mongodb-exporter-fips | affected | chainguard | prometheus-mongodb-exporter-fips | — |
| prometheus-mongodb-exporter-fips-0.37 | affected | chainguard | prometheus-mongodb-exporter-fips-0.37 | — |
| prometheus-mysqld-exporter | affected | chainguard | prometheus-mysqld-exporter | — |
| prometheus-nats-exporter | affected | chainguard | prometheus-nats-exporter | — |
| prometheus-node-exporter | affected | chainguard | prometheus-node-exporter | — |
| prometheus-node-exporter-1.4 | affected | chainguard | prometheus-node-exporter-1.4 | — |
| prometheus-node-exporter-1.5 | affected | chainguard | prometheus-node-exporter-1.5 | — |
| prometheus-node-exporter-fips | affected | chainguard | prometheus-node-exporter-fips | — |
| prometheus-postgres-exporter | affected | chainguard | prometheus-postgres-exporter | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| prometheus-postgres-exporter-fips | affected | chainguard | prometheus-postgres-exporter-fips | — |
| prometheus-pushgateway-1.4 | affected | chainguard | prometheus-pushgateway-1.4 | — |
| prometheus-pushgateway-fips | affected | chainguard | prometheus-pushgateway-fips | — |
| prometheus-pushgateway-fips-1.4 | affected | chainguard | prometheus-pushgateway-fips-1.4 | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter | affected | chainguard | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter-fips | affected | chainguard | prometheus-statsd-exporter-fips | — |
| pulumi | affected | chainguard | pulumi | — |
| pulumi | affected | wolfi | pulumi | — |
| rekor | affected | chainguard | rekor | — |
| rekor | affected | wolfi | rekor | — |
| rekor-fips | affected | chainguard | rekor-fips | — |
| rqlite | affected | wolfi | rqlite | — |
| rqlite | affected | chainguard | rqlite | — |
| scorecard | affected | chainguard | scorecard | — |
| scorecard | affected | wolfi | scorecard | — |
| secrets-store-csi-driver | affected | wolfi | secrets-store-csi-driver | — |
| secrets-store-csi-driver | affected | chainguard | secrets-store-csi-driver | — |
| secrets-store-csi-driver-provider-azure | affected | wolfi | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-azure | affected | chainguard | secrets-store-csi-driver-provider-azure | — |
| sigstore-scaffolding | affected | wolfi | sigstore-scaffolding | — |
| sigstore-scaffolding | affected | chainguard | sigstore-scaffolding | — |
| sigstore-scaffolding-fips | affected | chainguard | sigstore-scaffolding-fips | — |
| skopeo | affected | chainguard | skopeo | — |
| skopeo | affected | wolfi | skopeo | — |
| slsa-verifier | affected | wolfi | slsa-verifier | — |
| slsa-verifier | affected | chainguard | slsa-verifier | — |
| sops | affected | wolfi | sops | — |
| sops | affected | chainguard | sops | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spire-server | affected | wolfi | spire-server | — |
| spire-server | affected | chainguard | spire-server | — |
| spire-server-fips | affected | chainguard | spire-server-fips | — |
| src | affected | wolfi | src | — |
| src | affected | chainguard | src | — |
| src-fingerprint | affected | chainguard | src-fingerprint | — |
| src-fingerprint | affected | wolfi | src-fingerprint | — |
| step | affected | chainguard | step | — |
| step | affected | wolfi | step | — |
| step-ca | affected | chainguard | step-ca | — |
| step-ca | affected | wolfi | step-ca | — |
| tekton-chains | affected | wolfi | tekton-chains | — |
| tekton-chains | affected | chainguard | tekton-chains | — |
| temporal | affected | wolfi | temporal | — |
| temporal | affected | chainguard | temporal | — |
| temporal-fips | affected | chainguard | temporal-fips | — |
| temporal-server | affected | chainguard | temporal-server | — |
| temporal-server | affected | wolfi | temporal-server | — |
| temporal-server-fips | affected | chainguard | temporal-server-fips | — |
| temporal-ui-server | affected | wolfi | temporal-ui-server | — |
| temporal-ui-server | affected | chainguard | temporal-ui-server | — |
| temporal-ui-server-fips | affected | chainguard | temporal-ui-server-fips | — |
| terraform | affected | wolfi | terraform | — |
| terraform | affected | chainguard | terraform | — |
| terraform-docs | affected | chainguard | terraform-docs | — |
| terraform-docs | affected | wolfi | terraform-docs | — |
| terraform-provider-aws | affected | chainguard | terraform-provider-aws | — |
| terraform-provider-aws | affected | wolfi | terraform-provider-aws | — |
| terraform-provider-azurerm | affected | wolfi | terraform-provider-azurerm | — |
| terraform-provider-azurerm | affected | chainguard | terraform-provider-azurerm | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| terragrunt | affected | chainguard | terragrunt | — |
| terragrunt | affected | wolfi | terragrunt | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| tigera-operator-fips-1.29 | affected | chainguard | tigera-operator-fips-1.29 | — |
| timestamp-authority-fips | affected | chainguard | timestamp-authority-fips | — |
| tkn | affected | wolfi | tkn | — |
| tkn | affected | chainguard | tkn | — |
| trillian | affected | wolfi | trillian | — |
| trillian | affected | chainguard | trillian | — |
| trillian-fips | affected | chainguard | trillian-fips | — |
| trivy | affected | chainguard | trivy | — |
| trivy | affected | wolfi | trivy | — |
| up | affected | chainguard | up | — |
| up | affected | wolfi | up | — |
| vault-csi-provider | affected | chainguard | vault-csi-provider | — |
| vault-k8s | affected | wolfi | vault-k8s | — |
| vault-k8s | affected | chainguard | vault-k8s | — |
| vault-k8s-fips | affected | chainguard | vault-k8s-fips | — |
| vexctl | affected | wolfi | vexctl | — |
| vexctl | affected | chainguard | vexctl | — |
| wavefront-collector-for-kubernetes-1.12 | affected | chainguard | wavefront-collector-for-kubernetes-1.12 | — |
| wavefront-collector-for-kubernetes-1.13 | affected | chainguard | wavefront-collector-for-kubernetes-1.13 | — |
| weaviate | affected | wolfi | weaviate | — |
| weaviate | affected | chainguard | weaviate | — |
| wireguard-go | affected | wolfi | wireguard-go | — |
| wireguard-go | affected | chainguard | wireguard-go | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
| zot | affected | chainguard | zot | — |
| zot | affected | wolfi | zot | — |
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| paramiko | affected | PyPI | paramiko | — |
| russh | affected | crates.io | russh | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | chainguard | aactl | — |
| aactl | affected | wolfi | aactl | — |
| actions-runner-controller | affected | chainguard | actions-runner-controller | — |
| actions-runner-controller | affected | wolfi | actions-runner-controller | — |
| amass | affected | chainguard | amass | — |
| amass | affected | wolfi | amass | — |
| apko | affected | chainguard | apko | — |
| apko | affected | wolfi | apko | — |
| argo-cd-2.7 | affected | wolfi | argo-cd-2.7 | — |
| argo-cd-2.7 | affected | chainguard | argo-cd-2.7 | — |
| argo-cd-2.8 | affected | chainguard | argo-cd-2.8 | — |
| argo-cd-2.8 | affected | wolfi | argo-cd-2.8 | — |
| argo-cd-2.9 | affected | wolfi | argo-cd-2.9 | — |
| argo-cd-2.9 | affected | chainguard | argo-cd-2.9 | — |
| argo-workflows | affected | chainguard | argo-workflows | — |
| argo-workflows | affected | wolfi | argo-workflows | — |
| atlantis | affected | chainguard | atlantis | — |
| atlantis | affected | wolfi | atlantis | — |
| atlantis-fips | affected | chainguard | atlantis-fips | — |
| azure-aad-pod-identity-mic | affected | chainguard | azure-aad-pod-identity-mic | — |
| bank-vaults | affected | wolfi | bank-vaults | — |
| bank-vaults | affected | chainguard | bank-vaults | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| bom | affected | wolfi | bom | — |
| bom | affected | chainguard | bom | — |
| boring-registry | affected | chainguard | boring-registry | — |
| boring-registry | affected | wolfi | boring-registry | — |
| buf | affected | wolfi | buf | — |
| buf | affected | chainguard | buf | — |
| buildkitd | affected | wolfi | buildkitd | — |
| buildkitd | affected | chainguard | buildkitd | — |
| caddy | affected | chainguard | caddy | — |
| caddy | affected | wolfi | caddy | — |
| cadvisor | affected | chainguard | cadvisor | — |
| cadvisor | affected | wolfi | cadvisor | — |
| calico | affected | wolfi | calico | — |
| calico | affected | chainguard | calico | — |
| calico-fips | affected | chainguard | calico-fips | — |
| calico-fips-3.25 | affected | chainguard | calico-fips-3.25 | — |
| certificate-transparency | affected | wolfi | certificate-transparency | — |
| certificate-transparency | affected | chainguard | certificate-transparency | — |
| certificate-transparency-fips | affected | chainguard | certificate-transparency-fips | — |
| cert-manager-1.11 | affected | wolfi | cert-manager-1.11 | — |
| cert-manager-1.11 | affected | chainguard | cert-manager-1.11 | — |
| cert-manager-1.12 | affected | wolfi | cert-manager-1.12 | — |
| cert-manager-1.12 | affected | chainguard | cert-manager-1.12 | — |
| cert-manager-1.13 | affected | wolfi | cert-manager-1.13 | — |
| cert-manager-1.13 | affected | chainguard | cert-manager-1.13 | — |
| cert-manager-fips-1.12 | affected | chainguard | cert-manager-fips-1.12 | — |
| cert-manager-fips-1.13 | affected | chainguard | cert-manager-fips-1.13 | — |
| cfssl | affected | wolfi | cfssl | — |
| cfssl | affected | chainguard | cfssl | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cloudflared | affected | wolfi | cloudflared | — |
| cloudflared | affected | chainguard | cloudflared | — |
| cloud-sql-proxy | affected | chainguard | cloud-sql-proxy | — |
| cloud-sql-proxy | affected | wolfi | cloud-sql-proxy | — |
| cloud-sql-proxy-fips | affected | chainguard | cloud-sql-proxy-fips | — |
| cluster-autoscaler-1.25 | affected | wolfi | cluster-autoscaler-1.25 | — |
| cluster-autoscaler-1.25 | affected | chainguard | cluster-autoscaler-1.25 | — |
| cluster-autoscaler-fips-1.25 | affected | chainguard | cluster-autoscaler-fips-1.25 | — |
| cluster-autoscaler-fips-1.26 | affected | chainguard | cluster-autoscaler-fips-1.26 | — |
| cluster-autoscaler-fips-1.27 | affected | chainguard | cluster-autoscaler-fips-1.27 | — |
| cluster-autoscaler-fips-1.28 | affected | chainguard | cluster-autoscaler-fips-1.28 | — |
| conftest | affected | wolfi | conftest | — |
| conftest | affected | chainguard | conftest | — |
| conftest-fips | affected | chainguard | conftest-fips | — |
| consul-1.15 | affected | chainguard | consul-1.15 | — |
| consul-1.15 | affected | wolfi | consul-1.15 | — |
| consul-1.16 | affected | wolfi | consul-1.16 | — |
| consul-1.16 | affected | chainguard | consul-1.16 | — |
| containerd | affected | chainguard | containerd | — |
| containerd | affected | wolfi | containerd | — |
| coredns | affected | chainguard | coredns | — |
| coredns | affected | wolfi | coredns | — |
| cortex | affected | wolfi | cortex | — |
| cortex | affected | chainguard | cortex | — |
| cosign | affected | chainguard | cosign | — |
| cosign | affected | wolfi | cosign | — |
| cosign-fips | affected | wolfi | cosign-fips | — |
| cosign-fips | affected | chainguard | cosign-fips | — |
| crossplane | affected | chainguard | crossplane | — |
| crossplane | affected | wolfi | crossplane | — |
| crossplane-provider-aws | affected | chainguard | crossplane-provider-aws | — |
| crossplane-provider-aws | affected | wolfi | crossplane-provider-aws | — |
| crossplane-provider-azure | affected | chainguard | crossplane-provider-azure | — |
| crossplane-provider-azure | affected | wolfi | crossplane-provider-azure | — |
| crossplane-provider-azure-authorization | affected | chainguard | crossplane-provider-azure-authorization | — |
| crossplane-provider-azure-authorization | affected | wolfi | crossplane-provider-azure-authorization | — |
| crossplane-provider-azure-managedidentity | affected | wolfi | crossplane-provider-azure-managedidentity | — |
| crossplane-provider-azure-managedidentity | affected | chainguard | crossplane-provider-azure-managedidentity | — |
| crossplane-provider-azure-sql | affected | wolfi | crossplane-provider-azure-sql | — |
| crossplane-provider-azure-sql | affected | chainguard | crossplane-provider-azure-sql | — |
| crossplane-provider-azure-storage | affected | wolfi | crossplane-provider-azure-storage | — |
| crossplane-provider-azure-storage | affected | chainguard | crossplane-provider-azure-storage | — |
| crossplane-provider-family-azure | affected | wolfi | crossplane-provider-family-azure | — |
| crossplane-provider-family-azure | affected | chainguard | crossplane-provider-family-azure | — |
| dex | affected | chainguard | dex | — |
| dex | affected | wolfi | dex | — |
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| dgraph | affected | wolfi | dgraph | — |
| dgraph | affected | chainguard | dgraph | — |
| docker-credential-acr-env | affected | chainguard | docker-credential-acr-env | — |
| docker-credential-acr-env | affected | wolfi | docker-credential-acr-env | — |
| dockerize | affected | chainguard | dockerize | — |
| dockerize | affected | wolfi | dockerize | — |
| dockerize-fips | affected | chainguard | dockerize-fips | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| eksctl | affected | chainguard | eksctl | — |
| eksctl | affected | wolfi | eksctl | — |
| external-dns | affected | chainguard | external-dns | — |
| external-dns | affected | wolfi | external-dns | — |
| external-dns-0.13.5 | affected | chainguard | external-dns-0.13.5 | — |
| external-dns-fips | affected | chainguard | external-dns-fips | — |
| external-secrets-0.7 | affected | chainguard | external-secrets-0.7 | — |
| external-secrets-operator | affected | chainguard | external-secrets-operator | — |
| external-secrets-operator | affected | wolfi | external-secrets-operator | — |
| falco | affected | chainguard | falco | — |
| falco | affected | wolfi | falco | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| ferretdb | affected | chainguard | ferretdb | — |
| ferretdb | affected | wolfi | ferretdb | — |
| flux | affected | chainguard | flux | — |
| flux | affected | wolfi | flux | — |
| flux-0 | affected | chainguard | flux-0 | — |
| flux-0.37 | affected | chainguard | flux-0.37 | — |
| flux-2.0 | affected | chainguard | flux-2.0 | — |
| flux-helm-controller | affected | chainguard | flux-helm-controller | — |
| flux-helm-controller | affected | wolfi | flux-helm-controller | — |
| flux-helm-controller-0 | affected | chainguard | flux-helm-controller-0 | — |
| flux-helm-controller-0.37 | affected | chainguard | flux-helm-controller-0.37 | — |
| flux-helm-controller-2.0 | affected | chainguard | flux-helm-controller-2.0 | — |
| flux-image-automation-controller | affected | wolfi | flux-image-automation-controller | — |
| flux-image-automation-controller | affected | chainguard | flux-image-automation-controller | — |
| flux-image-reflector-controller | affected | chainguard | flux-image-reflector-controller | — |
| flux-image-reflector-controller | affected | wolfi | flux-image-reflector-controller | — |
| flux-image-reflector-controller-0 | affected | chainguard | flux-image-reflector-controller-0 | — |
| flux-kustomize-controller | affected | chainguard | flux-kustomize-controller | — |
| flux-kustomize-controller | affected | wolfi | flux-kustomize-controller | — |
| flux-kustomize-controller-0 | affected | chainguard | flux-kustomize-controller-0 | — |
| flux-kustomize-controller-0.37 | affected | chainguard | flux-kustomize-controller-0.37 | — |
| flux-kustomize-controller-2.0 | affected | chainguard | flux-kustomize-controller-2.0 | — |
| flux-notification-controller-0 | affected | chainguard | flux-notification-controller-0 | — |
| flux-notification-controller-0.37 | affected | chainguard | flux-notification-controller-0.37 | — |
| flux-notification-controller-2.0 | affected | chainguard | flux-notification-controller-2.0 | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flux-source-controller-0 | affected | chainguard | flux-source-controller-0 | — |
| flux-source-controller-0.37 | affected | chainguard | flux-source-controller-0.37 | — |
| flux-source-controller-2.0 | affected | chainguard | flux-source-controller-2.0 | — |
| fq | affected | chainguard | fq | — |
| fq | affected | wolfi | fq | — |
| frp | affected | wolfi | frp | — |
| frp | affected | chainguard | frp | — |
| fulcio | affected | wolfi | fulcio | — |
| fulcio | affected | chainguard | fulcio | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| gatekeeper-3.12 | affected | wolfi | gatekeeper-3.12 | — |
| gatekeeper-3.12 | affected | chainguard | gatekeeper-3.12 | — |
| gatekeeper-3.13 | affected | wolfi | gatekeeper-3.13 | — |
| gatekeeper-3.13 | affected | chainguard | gatekeeper-3.13 | — |
| gatekeeper-3.14 | affected | wolfi | gatekeeper-3.14 | — |
| gatekeeper-3.14 | affected | chainguard | gatekeeper-3.14 | — |
| gatekeeper-fips-3.13 | affected | chainguard | gatekeeper-fips-3.13 | — |
| gatekeeper-fips-3.14 | affected | chainguard | gatekeeper-fips-3.14 | — |
| gh | affected | wolfi | gh | — |
| gh | affected | chainguard | gh | — |
| gitlab-kas | affected | chainguard | gitlab-kas | — |
| gitlab-kas | affected | wolfi | gitlab-kas | — |
| gitlab-pages | affected | chainguard | gitlab-pages | — |
| gitlab-pages | affected | wolfi | gitlab-pages | — |
| gitlab-runner | affected | wolfi | gitlab-runner | — |
| gitlab-runner | affected | chainguard | gitlab-runner | — |
| git-lfs | affected | wolfi | git-lfs | — |
| git-lfs | affected | chainguard | git-lfs | — |
| gitness | affected | wolfi | gitness | — |
| gitness | affected | chainguard | gitness | — |
| gitsign | affected | chainguard | gitsign | — |
| gitsign | affected | wolfi | gitsign | — |
| gobuster | affected | chainguard | gobuster | — |
| gobuster | affected | wolfi | gobuster | — |
| golang.org/x/crypto | affected | Go | golang.org/x/crypto | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-licenses | affected | wolfi | go-licenses | — |
| gomplate | affected | chainguard | gomplate | — |
| gomplate | affected | wolfi | gomplate | — |
| goreleaser-1.18 | affected | chainguard | goreleaser-1.18 | — |
| goreleaser-1.18 | affected | wolfi | goreleaser-1.18 | — |
| gpu-operator | affected | chainguard | gpu-operator | — |
| grafana | affected | chainguard | grafana | — |
| grafana | affected | wolfi | grafana | — |
| grafana-7 | affected | chainguard | grafana-7 | — |
| grafana-9.3 | affected | chainguard | grafana-9.3 | — |
| grpc-health-probe | affected | chainguard | grpc-health-probe | — |
| grpc-health-probe | affected | wolfi | grpc-health-probe | — |
| grype | affected | chainguard | grype | — |
| grype | affected | wolfi | grype | — |
| haproxy-ingress | affected | wolfi | haproxy-ingress | — |
| haproxy-ingress | affected | chainguard | haproxy-ingress | — |
| helm | affected | wolfi | helm | — |
| helm | affected | chainguard | helm | — |
| helm-3 | affected | chainguard | helm-3 | — |
| helm-3 | affected | wolfi | helm-3 | — |
| helm-4 | affected | wolfi | helm-4 | — |
| helm-4 | affected | chainguard | helm-4 | — |
| helm-push | affected | wolfi | helm-push | — |
| helm-push | affected | chainguard | helm-push | — |
| hugo | affected | wolfi | hugo | — |
| hugo | affected | chainguard | hugo | — |
| influxd | affected | wolfi | influxd | — |
| influxd | affected | chainguard | influxd | — |
| ipfs | affected | chainguard | ipfs | — |
| ipfs | affected | wolfi | ipfs | — |
| istio-cni-1.19 | affected | wolfi | istio-cni-1.19 | — |
| istio-cni-1.19 | affected | chainguard | istio-cni-1.19 | — |
| istio-cni-fips-1.19 | affected | chainguard | istio-cni-fips-1.19 | — |
| istio-operator-1.19 | affected | wolfi | istio-operator-1.19 | — |
| istio-operator-1.19 | affected | chainguard | istio-operator-1.19 | — |
| istio-operator-1.20 | affected | wolfi | istio-operator-1.20 | — |
| istio-operator-1.20 | affected | chainguard | istio-operator-1.20 | — |
| istio-operator-fips-1.19 | affected | chainguard | istio-operator-fips-1.19 | — |
| istio-pilot-agent-1.18 | affected | chainguard | istio-pilot-agent-1.18 | — |
| istio-pilot-agent-1.18 | affected | wolfi | istio-pilot-agent-1.18 | — |
| istio-pilot-agent-1.19 | affected | wolfi | istio-pilot-agent-1.19 | — |
| istio-pilot-agent-1.19 | affected | chainguard | istio-pilot-agent-1.19 | — |
| istio-pilot-agent-1.20 | affected | chainguard | istio-pilot-agent-1.20 | — |
| istio-pilot-agent-1.20 | affected | wolfi | istio-pilot-agent-1.20 | — |
| istio-pilot-agent-fips-1.19 | affected | chainguard | istio-pilot-agent-fips-1.19 | — |
| istio-pilot-discovery-1.18 | affected | wolfi | istio-pilot-discovery-1.18 | — |
| istio-pilot-discovery-1.18 | affected | chainguard | istio-pilot-discovery-1.18 | — |
| istio-pilot-discovery-1.19 | affected | chainguard | istio-pilot-discovery-1.19 | — |
| istio-pilot-discovery-1.19 | affected | wolfi | istio-pilot-discovery-1.19 | — |
| istio-pilot-discovery-1.20 | affected | wolfi | istio-pilot-discovery-1.20 | — |
| istio-pilot-discovery-1.20 | affected | chainguard | istio-pilot-discovery-1.20 | — |
| istio-pilot-discovery-fips-1.19 | affected | chainguard | istio-pilot-discovery-fips-1.19 | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| k3s | affected | chainguard | k3s | — |
| k3s | affected | wolfi | k3s | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| kaf | affected | wolfi | kaf | — |
| kaf | affected | chainguard | kaf | — |
| karpenter-0.23 | affected | chainguard | karpenter-0.23 | — |
| keda-2.8 | affected | chainguard | keda-2.8 | — |
| keda-2.9 | affected | chainguard | keda-2.9 | — |
| kiam | affected | chainguard | kiam | — |
| ko | affected | wolfi | ko | — |
| ko | affected | chainguard | ko | — |
| ko-fips | affected | wolfi | ko-fips | — |
| ko-fips | affected | chainguard | ko-fips | — |
| kots | affected | chainguard | kots | — |
| kots | affected | wolfi | kots | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kube-fluentd-operator | affected | wolfi | kube-fluentd-operator | — |
| kube-fluentd-operator | affected | chainguard | kube-fluentd-operator | — |
| kube-logging-logging-operator-3.17 | affected | chainguard | kube-logging-logging-operator-3.17 | — |
| kube-oidc-proxy | affected | chainguard | kube-oidc-proxy | — |
| kube-rbac-proxy | affected | wolfi | kube-rbac-proxy | — |
| kube-rbac-proxy | affected | chainguard | kube-rbac-proxy | — |
| kubernetes-1.28 | affected | wolfi | kubernetes-1.28 | — |
| kubernetes-1.28 | affected | chainguard | kubernetes-1.28 | — |
| kubernetes-1.29 | affected | chainguard | kubernetes-1.29 | — |
| kubernetes-1.29 | affected | wolfi | kubernetes-1.29 | — |
| kubernetes-dashboard | affected | wolfi | kubernetes-dashboard | — |
| kubernetes-dashboard | affected | chainguard | kubernetes-dashboard | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
| kubernetes-event-exporter | affected | wolfi | kubernetes-event-exporter | — |
| kubernetes-event-exporter | affected | chainguard | kubernetes-event-exporter | — |
| kubernetes-fips-1.27 | affected | chainguard | kubernetes-fips-1.27 | — |
| kubernetes-fips-1.28 | affected | chainguard | kubernetes-fips-1.28 | — |
| kubernetes-fips-1.29 | affected | chainguard | kubernetes-fips-1.29 | — |
| kubescape | affected | wolfi | kubescape | — |
| kubescape | affected | chainguard | kubescape | — |
| kube-state-metrics | affected | chainguard | kube-state-metrics | — |
| kube-state-metrics | affected | wolfi | kube-state-metrics | — |
| kube-state-metrics-2.2.0 | affected | chainguard | kube-state-metrics-2.2.0 | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| kube-state-metrics-fips | affected | chainguard | kube-state-metrics-fips | — |
| kubewatch | affected | wolfi | kubewatch | — |
| kubewatch | affected | chainguard | kubewatch | — |
| kyverno | affected | chainguard | kyverno | — |
| kyverno | affected | wolfi | kyverno | — |
| kyverno-policy-reporter | affected | chainguard | kyverno-policy-reporter | — |
| kyverno-policy-reporter | affected | wolfi | kyverno-policy-reporter | — |
| libssh | affected | chainguard | libssh | — |
| libssh | affected | wolfi | libssh | — |
| libssh2 | affected | chainguard | libssh2 | — |
| libssh2 | affected | wolfi | libssh2 | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| loki | affected | chainguard | loki | — |
| loki | affected | wolfi | loki | — |
| melange | affected | wolfi | melange | — |
| melange | affected | chainguard | melange | — |
| memcached-exporter | affected | wolfi | memcached-exporter | — |
| memcached-exporter | affected | chainguard | memcached-exporter | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server | affected | chainguard | metrics-server | — |
| metrics-server-fips | affected | chainguard | metrics-server-fips | — |
| mongo-tools | affected | wolfi | mongo-tools | — |
| mongo-tools | affected | chainguard | mongo-tools | — |
| nats | affected | wolfi | nats | — |
| nats | affected | chainguard | nats | — |
| nats-server | affected | wolfi | nats-server | — |
| nats-server | affected | chainguard | nats-server | — |
| nerdctl | affected | chainguard | nerdctl | — |
| nerdctl | affected | wolfi | nerdctl | — |
| nfs-subdir-external-provisioner | affected | wolfi | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner | affected | chainguard | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner-fips | affected | chainguard | nfs-subdir-external-provisioner-fips | — |
| node-problem-detector-0.8 | affected | chainguard | node-problem-detector-0.8 | — |
| node-problem-detector-0.8 | affected | wolfi | node-problem-detector-0.8 | — |
| nri-kafka | affected | wolfi | nri-kafka | — |
| nri-kafka | affected | chainguard | nri-kafka | — |
| nri-mssql | affected | wolfi | nri-mssql | — |
| nri-mssql | affected | chainguard | nri-mssql | — |
| nsc | affected | chainguard | nsc | — |
| nsc | affected | wolfi | nsc | — |
| oauth2-proxy | affected | wolfi | oauth2-proxy | — |
| oauth2-proxy | affected | chainguard | oauth2-proxy | — |
| ollama | affected | wolfi | ollama | — |
| ollama | affected | chainguard | ollama | — |
| opentofu | affected | wolfi | opentofu | — |
| opentofu | affected | chainguard | opentofu | — |
| opentofu-1.6 | affected | chainguard | opentofu-1.6 | — |
| paramiko | affected | PyPI | paramiko | — |
| paramiko | affected | PyPI | paramiko | — |
| prometheus | affected | wolfi | prometheus | — |
| prometheus | affected | chainguard | prometheus | — |
| prometheus-2.38 | affected | chainguard | prometheus-2.38 | — |
| prometheus-adapter | affected | chainguard | prometheus-adapter | — |
| prometheus-adapter | affected | wolfi | prometheus-adapter | — |
| prometheus-adapter-0.10 | affected | chainguard | prometheus-adapter-0.10 | — |
| prometheus-adapter-fips | affected | chainguard | prometheus-adapter-fips | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-alertmanager | affected | wolfi | prometheus-alertmanager | — |
| prometheus-alertmanager | affected | chainguard | prometheus-alertmanager | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-bind-exporter | affected | wolfi | prometheus-bind-exporter | — |
| prometheus-blackbox-exporter | affected | wolfi | prometheus-blackbox-exporter | — |
| prometheus-blackbox-exporter | affected | chainguard | prometheus-blackbox-exporter | — |
| prometheus-elasticsearch-exporter-fips | affected | chainguard | prometheus-elasticsearch-exporter-fips | — |
| prometheus-fips | affected | chainguard | prometheus-fips | — |
| prometheus-mongodb-exporter | affected | wolfi | prometheus-mongodb-exporter | — |
| prometheus-mongodb-exporter | affected | chainguard | prometheus-mongodb-exporter | — |
| prometheus-mongodb-exporter-0.37 | affected | chainguard | prometheus-mongodb-exporter-0.37 | — |
| prometheus-mongodb-exporter-fips | affected | chainguard | prometheus-mongodb-exporter-fips | — |
| prometheus-mongodb-exporter-fips-0.37 | affected | chainguard | prometheus-mongodb-exporter-fips-0.37 | — |
| prometheus-mysqld-exporter | affected | chainguard | prometheus-mysqld-exporter | — |
| prometheus-mysqld-exporter | affected | wolfi | prometheus-mysqld-exporter | — |
| prometheus-nats-exporter | affected | chainguard | prometheus-nats-exporter | — |
| prometheus-nats-exporter | affected | wolfi | prometheus-nats-exporter | — |
| prometheus-node-exporter | affected | chainguard | prometheus-node-exporter | — |
| prometheus-node-exporter | affected | wolfi | prometheus-node-exporter | — |
| prometheus-node-exporter-1.4 | affected | chainguard | prometheus-node-exporter-1.4 | — |
| prometheus-node-exporter-1.5 | affected | chainguard | prometheus-node-exporter-1.5 | — |
| prometheus-node-exporter-fips | affected | chainguard | prometheus-node-exporter-fips | — |
| prometheus-postgres-exporter | affected | wolfi | prometheus-postgres-exporter | — |
| prometheus-postgres-exporter | affected | chainguard | prometheus-postgres-exporter | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| prometheus-postgres-exporter-0.13 | affected | chainguard | prometheus-postgres-exporter-0.13 | — |
| prometheus-postgres-exporter-fips | affected | chainguard | prometheus-postgres-exporter-fips | — |
| prometheus-pushgateway-1.4 | affected | chainguard | prometheus-pushgateway-1.4 | — |
| prometheus-pushgateway-fips | affected | chainguard | prometheus-pushgateway-fips | — |
| prometheus-pushgateway-fips-1.4 | affected | chainguard | prometheus-pushgateway-fips-1.4 | — |
| prometheus-stackdriver-exporter | affected | wolfi | prometheus-stackdriver-exporter | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter | affected | chainguard | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter | affected | wolfi | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter-fips | affected | chainguard | prometheus-statsd-exporter-fips | — |
| pulumi | affected | wolfi | pulumi | — |
| pulumi | affected | chainguard | pulumi | — |
| rekor | affected | wolfi | rekor | — |
| rekor | affected | chainguard | rekor | — |
| rekor-fips | affected | chainguard | rekor-fips | — |
| rqlite | affected | wolfi | rqlite | — |
| rqlite | affected | chainguard | rqlite | — |
| russh | affected | crates.io | russh | — |
| scorecard | affected | wolfi | scorecard | — |
| scorecard | affected | chainguard | scorecard | — |
| secrets-store-csi-driver | affected | chainguard | secrets-store-csi-driver | — |
| secrets-store-csi-driver | affected | wolfi | secrets-store-csi-driver | — |
| secrets-store-csi-driver-provider-azure | affected | chainguard | secrets-store-csi-driver-provider-azure | — |
| secrets-store-csi-driver-provider-azure | affected | wolfi | secrets-store-csi-driver-provider-azure | — |
| sigstore-scaffolding | affected | chainguard | sigstore-scaffolding | — |
| sigstore-scaffolding | affected | wolfi | sigstore-scaffolding | — |
| sigstore-scaffolding-fips | affected | chainguard | sigstore-scaffolding-fips | — |
| skopeo | affected | chainguard | skopeo | — |
| skopeo | affected | wolfi | skopeo | — |
| slsa-verifier | affected | wolfi | slsa-verifier | — |
| slsa-verifier | affected | chainguard | slsa-verifier | — |
| sops | affected | chainguard | sops | — |
| sops | affected | wolfi | sops | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spire-server | affected | wolfi | spire-server | — |
| spire-server | affected | chainguard | spire-server | — |
| spire-server-fips | affected | chainguard | spire-server-fips | — |
| src | affected | wolfi | src | — |
| src | affected | chainguard | src | — |
| src-fingerprint | affected | wolfi | src-fingerprint | — |
| src-fingerprint | affected | chainguard | src-fingerprint | — |
| step | affected | wolfi | step | — |
| step | affected | chainguard | step | — |
| step-ca | affected | chainguard | step-ca | — |
| step-ca | affected | wolfi | step-ca | — |
| tekton-chains | affected | wolfi | tekton-chains | — |
| tekton-chains | affected | chainguard | tekton-chains | — |
| tekton-pipelines | affected | wolfi | tekton-pipelines | — |
| tekton-pipelines | affected | chainguard | tekton-pipelines | — |
| telegraf-1.26 | affected | chainguard | telegraf-1.26 | — |
| telegraf-1.26 | affected | wolfi | telegraf-1.26 | — |
| telegraf-1.27 | affected | chainguard | telegraf-1.27 | — |
| telegraf-1.27 | affected | wolfi | telegraf-1.27 | — |
| telegraf-1.28 | affected | chainguard | telegraf-1.28 | — |
| telegraf-1.28 | affected | wolfi | telegraf-1.28 | — |
| telegraf-1.29 | affected | wolfi | telegraf-1.29 | — |
| telegraf-1.29 | affected | chainguard | telegraf-1.29 | — |
| temporal | affected | wolfi | temporal | — |
| temporal | affected | chainguard | temporal | — |
| temporal-fips | affected | chainguard | temporal-fips | — |
| temporal-server | affected | wolfi | temporal-server | — |
| temporal-server | affected | chainguard | temporal-server | — |
| temporal-server-fips | affected | chainguard | temporal-server-fips | — |
| temporal-ui-server | affected | chainguard | temporal-ui-server | — |
| temporal-ui-server | affected | wolfi | temporal-ui-server | — |
| temporal-ui-server-fips | affected | chainguard | temporal-ui-server-fips | — |
| terraform | affected | chainguard | terraform | — |
| terraform | affected | wolfi | terraform | — |
| terraform-docs | affected | wolfi | terraform-docs | — |
| terraform-docs | affected | chainguard | terraform-docs | — |
| terraform-fips-1.5 | affected | chainguard | terraform-fips-1.5 | — |
| terraform-provider-aws | affected | wolfi | terraform-provider-aws | — |
| terraform-provider-aws | affected | chainguard | terraform-provider-aws | — |
| terraform-provider-azurerm | affected | chainguard | terraform-provider-azurerm | — |
| terraform-provider-azurerm | affected | wolfi | terraform-provider-azurerm | — |
| terraform-provider-sendgrid | affected | wolfi | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid | affected | chainguard | terraform-provider-sendgrid | — |
| terraform-provider-sendgrid-fips | affected | chainguard | terraform-provider-sendgrid-fips | — |
| terragrunt | affected | wolfi | terragrunt | — |
| terragrunt | affected | chainguard | terragrunt | — |
| thanos-0.31 | affected | wolfi | thanos-0.31 | — |
| thanos-0.31 | affected | chainguard | thanos-0.31 | — |
| thanos-0.32 | affected | chainguard | thanos-0.32 | — |
| thanos-0.32 | affected | wolfi | thanos-0.32 | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| tigera-operator-1.30 | affected | wolfi | tigera-operator-1.30 | — |
| tigera-operator-1.30 | affected | chainguard | tigera-operator-1.30 | — |
| tigera-operator-1.31 | affected | wolfi | tigera-operator-1.31 | — |
| tigera-operator-1.31 | affected | chainguard | tigera-operator-1.31 | — |
| tigera-operator-fips | affected | chainguard | tigera-operator-fips | — |
| tigera-operator-fips-1.29 | affected | chainguard | tigera-operator-fips-1.29 | — |
| tigera-operator-fips-1.32 | affected | chainguard | tigera-operator-fips-1.32 | — |
| timestamp-authority-fips | affected | chainguard | timestamp-authority-fips | — |
| tkn | affected | wolfi | tkn | — |
| tkn | affected | chainguard | tkn | — |
| traefik | affected | chainguard | traefik | — |
| traefik | affected | wolfi | traefik | — |
| trillian | affected | wolfi | trillian | — |
| trillian | affected | chainguard | trillian | — |
| trillian-fips | affected | chainguard | trillian-fips | — |
| trivy | affected | wolfi | trivy | — |
| trivy | affected | chainguard | trivy | — |
| up | affected | wolfi | up | — |
| up | affected | chainguard | up | — |
| vault-1.13 | affected | wolfi | vault-1.13 | — |
| vault-1.13 | affected | chainguard | vault-1.13 | — |
| vault-csi-provider | affected | chainguard | vault-csi-provider | — |
| vault-csi-provider | affected | wolfi | vault-csi-provider | — |
| vault-fips-1.14 | affected | chainguard | vault-fips-1.14 | — |
| vault-k8s | affected | wolfi | vault-k8s | — |
| vault-k8s | affected | chainguard | vault-k8s | — |
| vault-k8s-fips | affected | chainguard | vault-k8s-fips | — |
| vexctl | affected | chainguard | vexctl | — |
| vexctl | affected | wolfi | vexctl | — |
| wavefront-collector-for-kubernetes-1.12 | affected | chainguard | wavefront-collector-for-kubernetes-1.12 | — |
| wavefront-collector-for-kubernetes-1.13 | affected | chainguard | wavefront-collector-for-kubernetes-1.13 | — |
| weaviate | affected | wolfi | weaviate | — |
| weaviate | affected | chainguard | weaviate | — |
| wireguard-go | affected | chainguard | wireguard-go | — |
| wireguard-go | affected | wolfi | wireguard-go | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
| zot | affected | chainguard | zot | — |
| zot | affected | wolfi | zot | — |
CVE-2023-48795 affecting package kubernetes for versions less than 1.28.4-4
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Azure Linux:2 | kubernetes | — |
CVE-2023-48795 affecting package kubernetes for versions less than 1.30.1-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Azure Linux:3 | kubernetes | — |
DEBIAN-CVE-2023-48795
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| dropbear | affected | Debian:13 | dropbear | — |
| dropbear | affected | Debian:11 | dropbear | — |
| dropbear | affected | Debian:12 | dropbear | — |
| dropbear | affected | Debian:14 | dropbear | — |
| erlang | affected | Debian:12 | erlang | — |
| erlang | affected | Debian:14 | erlang | — |
| erlang | affected | Debian:11 | erlang | — |
| erlang | affected | Debian:13 | erlang | — |
| filezilla | affected | Debian:12 | filezilla | — |
| filezilla | affected | Debian:14 | filezilla | — |
| filezilla | affected | Debian:11 | filezilla | — |
| filezilla | affected | Debian:13 | filezilla | — |
| golang-go.crypto | affected | Debian:12 | golang-go.crypto | — |
| golang-go.crypto | affected | Debian:14 | golang-go.crypto | — |
| golang-go.crypto | affected | Debian:11 | golang-go.crypto | — |
| golang-go.crypto | affected | Debian:13 | golang-go.crypto | — |
| libssh | affected | Debian:13 | libssh | — |
| libssh | affected | Debian:12 | libssh | — |
| libssh | affected | Debian:11 | libssh | — |
| libssh | affected | Debian:14 | libssh | — |
| libssh2 | affected | Debian:14 | libssh2 | — |
| libssh2 | affected | Debian:13 | libssh2 | — |
| openssh | affected | Debian:13 | openssh | — |
| openssh | affected | Debian:14 | openssh | — |
| openssh | affected | Debian:11 | openssh | — |
| openssh | affected | Debian:12 | openssh | — |
| paramiko | affected | Debian:14 | paramiko | — |
| paramiko | affected | Debian:11 | paramiko | — |
| paramiko | affected | Debian:12 | paramiko | — |
| paramiko | affected | Debian:13 | paramiko | — |
| php-phpseclib | affected | Debian:14 | php-phpseclib | — |
| php-phpseclib | affected | Debian:13 | php-phpseclib | — |
| php-phpseclib | affected | Debian:11 | php-phpseclib | — |
| php-phpseclib | affected | Debian:12 | php-phpseclib | — |
| php-phpseclib3 | affected | Debian:14 | php-phpseclib3 | — |
| php-phpseclib3 | affected | Debian:12 | php-phpseclib3 | — |
| php-phpseclib3 | affected | Debian:13 | php-phpseclib3 | — |
| phpseclib | affected | Debian:11 | phpseclib | — |
| phpseclib | affected | Debian:12 | phpseclib | — |
| phpseclib | affected | Debian:13 | phpseclib | — |
| proftpd-dfsg | affected | Debian:13 | proftpd-dfsg | — |
| proftpd-dfsg | affected | Debian:14 | proftpd-dfsg | — |
| proftpd-dfsg | affected | Debian:11 | proftpd-dfsg | — |
| proftpd-dfsg | affected | Debian:12 | proftpd-dfsg | — |
| proftpd-mod-proxy | affected | Debian:14 | proftpd-mod-proxy | — |
| proftpd-mod-proxy | affected | Debian:13 | proftpd-mod-proxy | — |
| proftpd-mod-proxy | affected | Debian:12 | proftpd-mod-proxy | — |
| proftpd-mod-proxy | affected | Debian:11 | proftpd-mod-proxy | — |
| putty | affected | Debian:14 | putty | — |
| putty | affected | Debian:11 | putty | — |
| putty | affected | Debian:12 | putty | — |
| putty | affected | Debian:13 | putty | — |
| python-asyncssh | affected | Debian:14 | python-asyncssh | — |
| python-asyncssh | affected | Debian:11 | python-asyncssh | — |
| python-asyncssh | affected | Debian:12 | python-asyncssh | — |
| python-asyncssh | affected | Debian:13 | python-asyncssh | — |
| tinyssh | affected | Debian:14 | tinyssh | — |
| tinyssh | affected | Debian:13 | tinyssh | — |
| tinyssh | affected | Debian:11 | tinyssh | — |
| tinyssh | affected | Debian:12 | tinyssh | — |
| trilead-ssh2 | affected | Debian:14 | trilead-ssh2 | — |
| trilead-ssh2 | affected | Debian:11 | trilead-ssh2 | — |
| trilead-ssh2 | affected | Debian:12 | trilead-ssh2 | — |
| trilead-ssh2 | affected | Debian:13 | trilead-ssh2 | — |
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
CVEs:CVE-2023-48795
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| paramiko | affected | PyPI | paramiko | — |
| russh | affected | crates.io | russh | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
CVEs:CVE-2023-48795
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| paramiko | affected | PyPI | paramiko | — |
| russh | affected | crates.io | russh | — |
| x/crypto | affected | golang.org | golang.org/x/crypto | — |
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and...
CVEs:CVE-2023-48795
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| advanced_cluster_security | affected | redhat | — | — |
| asyncssh | affected | asyncssh_project | — | — |
| ceph_storage | affected | redhat | — | — |
| cert-manager_operator_for_red_hat_openshift | affected | redhat | — | — |
| crushftp | affected | crushftp | — | — |
| crypto | affected | golang | — | — |
| cyclone_ssh | affected | oryx-embedded | — | — |
| debian_linux | affected | debian | — | — |
| discovery | affected | redhat | — | — |
| dropbear_ssh | affected | dropbear_ssh_project | — | — |
| enterprise_linux | affected | redhat | — | — |
| erlang\/otp | affected | erlang | — | — |
| fedora | affected | fedoraproject | — | — |
| filezilla_client | affected | filezilla-project | — | — |
| freebsd | affected | freebsd | — | — |
| jboss_enterprise_application_platform | affected | redhat | — | — |
| jsch | affected | matez | — | — |
| keycloak | affected | redhat | — | — |
| kitty | affected | 9bis | — | — |
| lanconfig | affected | lancom-systems | — | — |
| lcos | affected | lancom-systems | — | — |
| lcos_fx | affected | lancom-systems | — | — |
| lcos_lx | affected | lancom-systems | — | — |
| lcos_sx | affected | lancom-systems | — | — |
| libssh | affected | libssh | — | — |
| libssh2 | affected | libssh2 | — | — |
| macos | affected | apple | — | — |
| maverick_synergy_java_ssh_api | affected | jadaptive | — | — |
| net-ssh | affected | net-ssh | — | — |
| nova | affected | panic | — | — |
| openshift_api_for_data_protection | affected | redhat | — | — |
| openshift_container_platform | affected | redhat | — | — |
| openshift_data_foundation | affected | redhat | — | — |
| openshift_developer_tools_and_services | affected | redhat | — | — |
| openshift_dev_spaces | affected | redhat | — | — |
| openshift_gitops | affected | redhat | — | — |
| openshift_pipelines | affected | redhat | — | — |
| openshift_serverless | affected | redhat | — | — |
| openshift_virtualization | affected | redhat | — | — |
| openssh | affected | openbsd | — | — |
| openstack_platform | affected | redhat | — | — |
| paramiko | affected | paramiko | — | — |
| pfsense_ce | affected | netgate | — | — |
| pfsense_plus | affected | netgate | — | — |
| pkixssh | affected | roumenpetrov | — | — |
| proftpd | affected | proftpd | — | — |
| putty | affected | putty | — | — |
| russh | affected | russh_project | — | — |
| securecrt | affected | vandyke | — | — |
| security | affected | gentoo | — | — |
| sftp_gateway_firmware | affected | thorntech | — | — |
| sftpgo | affected | sftpgo_project | — | — |
| single_sign-on | affected | redhat | — | — |
| ssh | affected | ssh | — | — |
| ssh2 | affected | ssh2_project | — | — |
| ssh2 | affected | trilead | — | — |
| ssh_client | affected | bitvise | — | — |
| sshd | affected | apache | — | — |
| sshj | affected | apache | — | — |
| sshlib | affected | connectbot | — | — |
| ssh_server | affected | bitvise | — | — |
| storage | affected | redhat | — | — |
| tera_term | affected | tera_term_project | — | — |
| thrussh | affected | crates | — | — |
| tinyssh | affected | tinyssh | — | — |
| transmit_5 | affected | panic | — | — |
| winscp | affected | winscp | — | — |
| xshell_7 | affected | netsarang | — | — |
CVEs:CVE-2023-40088
In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. ...
CVEs:CVE-2023-40088
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
DEBIAN-CVE-2023-6702
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-6702
CVEs:CVE-2023-6702
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-6702
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2023-36880
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVEs:CVE-2023-36880
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
DEBIAN-CVE-2023-6512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-6512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-6512
CVEs:CVE-2023-6512
DEBIAN-CVE-2023-6508
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-6508
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-6508
CVEs:CVE-2023-6508
DEBIAN-CVE-2023-6510
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-6510
Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
CVEs:CVE-2023-6510
Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity:...
CVEs:CVE-2023-6510
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2023-6509
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-6509
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)
CVEs:CVE-2023-6509
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security sever...
CVEs:CVE-2023-6509
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2023-6511
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-6511
Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2023-6511
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2023-6511
DEBIAN-CVE-2023-6705
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-6705
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-6705
DEBIAN-CVE-2023-6704
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| libavif | affected | Debian:13 | libavif | — |
| libavif | affected | Debian:14 | libavif | — |
Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted image file. (Chromium security severity: High)
CVEs:CVE-2023-6704
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-6704
DEBIAN-CVE-2023-6707
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2023-6707
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-6707
DEBIAN-CVE-2023-6703
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2023-6706
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2023-6703
Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-6703
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2023-6706
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-6706
CVEs:CVE-2023-47548
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Goog...
CVEs:CVE-2023-47548
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| integrate_google_drive | affected | softlabbd | — | — |
CVEs:CVE-2023-6181
An oversight in BCB handling of reboot reason that allows for persistent code execution
CVEs:CVE-2023-6181
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromecast_firmware | affected | — | — |
CVEs:CVE-2023-51373
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ian Kennerley Google Photos Gallery with Shortcodes allows Reflected XSS.This issue affects Google Photos Gallery with Shortcodes: from n/a through 4....
CVEs:CVE-2023-51373
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_photos_gallery_with_shortcodes | affected | nakunakifi | — | — |
CVEs:CVE-2024-3173
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
CVEs:CVE-2024-3173
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
CVEs:CVE-2024-3173
Logging of the firestore key within nodejs-firestore
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firestore | affected | google-cloud | @google-cloud/firestore | — |
Logging of the firestore key within nodejs-firestore
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firestore | affected | google-cloud | @google-cloud/firestore | — |
Logging of the firestore key within nodejs-firestore
CVEs:CVE-2023-6460
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firestore | affected | google-cloud | @google-cloud/firestore | — |
Logging of the firestore key within nodejs-firestore
CVEs:CVE-2023-6460
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firestore | affected | google-cloud | @google-cloud/firestore | — |
A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We reco...
CVEs:CVE-2023-6460
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cloud_firestore | affected | — | — |
CVEs:CVE-2023-32859
CVEs:CVE-2023-32860
In display, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929788; Is...
CVEs:CVE-2023-32860
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In meta, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08000473; Issue...
CVEs:CVE-2023-32859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-32854
CVEs:CVE-2023-32861
CVEs:CVE-2023-32862
CVEs:CVE-2023-32863
CVEs:CVE-2023-32864
CVEs:CVE-2023-32865
CVEs:CVE-2023-32866
CVEs:CVE-2023-32867
CVEs:CVE-2023-32868
CVEs:CVE-2023-32869
CVEs:CVE-2023-32870
CVEs:CVE-2023-32853
In display drm, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363740; Iss...
CVEs:CVE-2023-32870
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363632; Is...
CVEs:CVE-2023-32869
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363632; Is...
CVEs:CVE-2023-32868
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560793; Is...
CVEs:CVE-2023-32867
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In mmp, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342152; Issue ID:...
CVEs:CVE-2023-32866
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363456;...
CVEs:CVE-2023-32865
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292187;...
CVEs:CVE-2023-32864
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In display drm, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326314; Iss...
CVEs:CVE-2023-32863
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388762; Issu...
CVEs:CVE-2023-32862
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08059081; Issu...
CVEs:CVE-2023-32861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08240132; Issue ID: ...
CVEs:CVE-2023-32854
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In rpmb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648764; Issue ID:...
CVEs:CVE-2023-32853
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-32856
CVEs:CVE-2023-32857
In display, there is a possible out of bounds read due to an incorrect status check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issue...
CVEs:CVE-2023-32857
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In display, there is a possible out of bounds read due to an incorrect status check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issue...
CVEs:CVE-2023-32856
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-32852
In cameraisp, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07670971;...
CVEs:CVE-2023-32852
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-32855
CVEs:CVE-2023-32858
In GZ, there is a possible information disclosure due to a missing data erasing. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07806008; Issue ID:...
CVEs:CVE-2023-32858
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Is...
CVEs:CVE-2023-32855
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| openwrt | affected | openwrt | — | — |
| rdk-b | affected | rdkcentral | — | — |
| yocto | affected | linuxfoundation | — | — |
CVEs:CVE-2023-32849
In cmdq, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08161758; Issue ID: ALPS081...
CVEs:CVE-2023-32849
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occu...
CVEs:CVE-2023-45866
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| ubuntu_linux | affected | canonical | — | — |
CVEs:CVE-2023-45866
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
CVEs:CVE-2023-45866
Updated golang packages fix security vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:8 | golang | — |
| golang | affected | Mageia:9 | golang | — |
Withdrawn Advisory: Prometheus XSS Vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| prometheus/prometheus | affected | github.com | github.com/prometheus/prometheus | — |
Withdrawn Advisory: Prometheus XSS Vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| agentbeat-fips | affected | chainguard | agentbeat-fips | — |
| amazon-cloudwatch-agent | affected | wolfi | amazon-cloudwatch-agent | — |
| amazon-cloudwatch-agent | affected | chainguard | amazon-cloudwatch-agent | — |
| amazon-cloudwatch-agent-fips | affected | chainguard | amazon-cloudwatch-agent-fips | — |
| amazon-cloudwatch-agent-operator | affected | chainguard | amazon-cloudwatch-agent-operator | — |
| amazon-cloudwatch-agent-operator | affected | wolfi | amazon-cloudwatch-agent-operator | — |
| amazon-cloudwatch-agent-operator-fips | affected | chainguard | amazon-cloudwatch-agent-operator-fips | — |
| beats-7 | affected | chainguard | beats-7 | — |
| beats-8 | affected | chainguard | beats-8 | — |
| beats-fips-7 | affected | chainguard | beats-fips-7 | — |
| beats-fips-8 | affected | chainguard | beats-fips-8 | — |
| certificate-transparency | affected | chainguard | certificate-transparency | — |
| certificate-transparency | affected | wolfi | certificate-transparency | — |
| certificate-transparency-fips | affected | chainguard | certificate-transparency-fips | — |
| cloud-sql-proxy | affected | chainguard | cloud-sql-proxy | — |
| cloud-sql-proxy | affected | wolfi | cloud-sql-proxy | — |
| cloud-sql-proxy-fips | affected | chainguard | cloud-sql-proxy-fips | — |
| cortex | affected | chainguard | cortex | — |
| cortex | affected | wolfi | cortex | — |
| cortex-fips | affected | chainguard | cortex-fips | — |
| elastic-agent-fips | affected | chainguard | elastic-agent-fips | — |
| fluent-bit-plugin-loki | affected | chainguard | fluent-bit-plugin-loki | — |
| fluent-bit-plugin-loki | affected | wolfi | fluent-bit-plugin-loki | — |
| gatekeeper-3.12 | affected | wolfi | gatekeeper-3.12 | — |
| gatekeeper-3.12 | affected | chainguard | gatekeeper-3.12 | — |
| gatekeeper-3.13 | affected | wolfi | gatekeeper-3.13 | — |
| gatekeeper-3.13 | affected | chainguard | gatekeeper-3.13 | — |
| gatekeeper-3.14 | affected | wolfi | gatekeeper-3.14 | — |
| gatekeeper-3.14 | affected | chainguard | gatekeeper-3.14 | — |
| gcsfuse | affected | chainguard | gcsfuse | — |
| gcsfuse | affected | wolfi | gcsfuse | — |
| gitaly-17.2 | affected | wolfi | gitaly-17.2 | — |
| gitaly-17.2 | affected | chainguard | gitaly-17.2 | — |
| gitaly-17.3 | affected | chainguard | gitaly-17.3 | — |
| gitaly-17.3 | affected | wolfi | gitaly-17.3 | — |
| gitaly-17.4 | affected | chainguard | gitaly-17.4 | — |
| gitaly-17.4 | affected | wolfi | gitaly-17.4 | — |
| gitaly-17.5 | affected | chainguard | gitaly-17.5 | — |
| gitaly-17.5 | affected | wolfi | gitaly-17.5 | — |
| gitaly-17.6 | affected | wolfi | gitaly-17.6 | — |
| gitaly-17.6 | affected | chainguard | gitaly-17.6 | — |
| gitaly-17.7 | affected | wolfi | gitaly-17.7 | — |
| gitaly-17.7 | affected | chainguard | gitaly-17.7 | — |
| gitaly-17.8 | affected | chainguard | gitaly-17.8 | — |
| gitaly-17.8 | affected | wolfi | gitaly-17.8 | — |
| gitaly-17.9 | affected | chainguard | gitaly-17.9 | — |
| gitaly-17.9 | affected | wolfi | gitaly-17.9 | — |
| gitaly-fips-17.2 | affected | chainguard | gitaly-fips-17.2 | — |
| gitaly-fips-17.3 | affected | chainguard | gitaly-fips-17.3 | — |
| gitaly-fips-17.4 | affected | chainguard | gitaly-fips-17.4 | — |
| gitaly-fips-17.5 | affected | chainguard | gitaly-fips-17.5 | — |
| gitaly-fips-17.6 | affected | chainguard | gitaly-fips-17.6 | — |
| gitaly-fips-17.7 | affected | chainguard | gitaly-fips-17.7 | — |
| gitaly-fips-17.8 | affected | chainguard | gitaly-fips-17.8 | — |
| gitaly-fips-17.9 | affected | chainguard | gitaly-fips-17.9 | — |
| grafana | affected | chainguard | grafana | — |
| grafana | affected | wolfi | grafana | — |
| grafana-10.4 | affected | chainguard | grafana-10.4 | — |
| grafana-10.4 | affected | wolfi | grafana-10.4 | — |
| grafana-11.0 | affected | chainguard | grafana-11.0 | — |
| grafana-11.0 | affected | wolfi | grafana-11.0 | — |
| grafana-11.1 | affected | chainguard | grafana-11.1 | — |
| grafana-11.1 | affected | wolfi | grafana-11.1 | — |
| grafana-11.2 | affected | wolfi | grafana-11.2 | — |
| grafana-11.2 | affected | chainguard | grafana-11.2 | — |
| grafana-11.3 | affected | wolfi | grafana-11.3 | — |
| grafana-11.3 | affected | chainguard | grafana-11.3 | — |
| grafana-11.4 | affected | chainguard | grafana-11.4 | — |
| grafana-11.4 | affected | wolfi | grafana-11.4 | — |
| grafana-11.5 | affected | chainguard | grafana-11.5 | — |
| grafana-11.5 | affected | wolfi | grafana-11.5 | — |
| grafana-7 | affected | chainguard | grafana-7 | — |
| grafana-9.3 | affected | chainguard | grafana-9.3 | — |
| grafana-fips-10.4 | affected | chainguard | grafana-fips-10.4 | — |
| grafana-fips-11.0 | affected | chainguard | grafana-fips-11.0 | — |
| grafana-fips-11.1 | affected | chainguard | grafana-fips-11.1 | — |
| grafana-fips-11.2 | affected | chainguard | grafana-fips-11.2 | — |
| grafana-fips-11.3 | affected | chainguard | grafana-fips-11.3 | — |
| grafana-fips-11.4 | affected | chainguard | grafana-fips-11.4 | — |
| grafana-fips-11.5 | affected | chainguard | grafana-fips-11.5 | — |
| istio-1.24 | affected | wolfi | istio-1.24 | — |
| istio-1.24 | affected | chainguard | istio-1.24 | — |
| istio-1.25 | affected | wolfi | istio-1.25 | — |
| istio-1.25 | affected | chainguard | istio-1.25 | — |
| istio-fips-1.21 | affected | chainguard | istio-fips-1.21 | — |
| istio-fips-1.22 | affected | chainguard | istio-fips-1.22 | — |
| istio-fips-1.23 | affected | chainguard | istio-fips-1.23 | — |
| istio-fips-1.24 | affected | chainguard | istio-fips-1.24 | — |
| istio-fips-1.25 | affected | chainguard | istio-fips-1.25 | — |
| istio-operator-1.19 | affected | chainguard | istio-operator-1.19 | — |
| istio-operator-1.19 | affected | wolfi | istio-operator-1.19 | — |
| istio-operator-1.20 | affected | wolfi | istio-operator-1.20 | — |
| istio-operator-1.20 | affected | chainguard | istio-operator-1.20 | — |
| istio-operator-1.21 | affected | chainguard | istio-operator-1.21 | — |
| istio-operator-1.21 | affected | wolfi | istio-operator-1.21 | — |
| istio-operator-1.22 | affected | chainguard | istio-operator-1.22 | — |
| istio-operator-1.22 | affected | wolfi | istio-operator-1.22 | — |
| istio-operator-fips-1.19 | affected | chainguard | istio-operator-fips-1.19 | — |
| istio-pilot-agent-1.18 | affected | chainguard | istio-pilot-agent-1.18 | — |
| istio-pilot-agent-1.18 | affected | wolfi | istio-pilot-agent-1.18 | — |
| istio-pilot-agent-1.19 | affected | chainguard | istio-pilot-agent-1.19 | — |
| istio-pilot-agent-1.19 | affected | wolfi | istio-pilot-agent-1.19 | — |
| istio-pilot-agent-1.20 | affected | wolfi | istio-pilot-agent-1.20 | — |
| istio-pilot-agent-1.20 | affected | chainguard | istio-pilot-agent-1.20 | — |
| istio-pilot-agent-fips-1.19 | affected | chainguard | istio-pilot-agent-fips-1.19 | — |
| istio-pilot-discovery-1.19 | affected | wolfi | istio-pilot-discovery-1.19 | — |
| istio-pilot-discovery-1.19 | affected | chainguard | istio-pilot-discovery-1.19 | — |
| istio-pilot-discovery-1.20 | affected | wolfi | istio-pilot-discovery-1.20 | — |
| istio-pilot-discovery-1.20 | affected | chainguard | istio-pilot-discovery-1.20 | — |
| istio-pilot-discovery-1.21 | affected | wolfi | istio-pilot-discovery-1.21 | — |
| istio-pilot-discovery-1.21 | affected | chainguard | istio-pilot-discovery-1.21 | — |
| istio-pilot-discovery-1.22 | affected | chainguard | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22 | affected | wolfi | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-fips-1.19 | affected | chainguard | istio-pilot-discovery-fips-1.19 | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| keda-2.16 | affected | chainguard | keda-2.16 | — |
| keda-2.16 | affected | wolfi | keda-2.16 | — |
| keda-fips | affected | chainguard | keda-fips | — |
| loki | affected | wolfi | loki | — |
| loki | affected | chainguard | loki | — |
| loki-3.2 | affected | chainguard | loki-3.2 | — |
| loki-3.2 | affected | wolfi | loki-3.2 | — |
| loki-3.3 | affected | chainguard | loki-3.3 | — |
| loki-3.3 | affected | wolfi | loki-3.3 | — |
| loki-3.4 | affected | wolfi | loki-3.4 | — |
| loki-3.4 | affected | chainguard | loki-3.4 | — |
| loki-fips-3.2 | affected | chainguard | loki-fips-3.2 | — |
| loki-fips-3.3 | affected | chainguard | loki-fips-3.3 | — |
| loki-fips-3.4 | affected | chainguard | loki-fips-3.4 | — |
| mc | affected | wolfi | mc | — |
| mc | affected | chainguard | mc | — |
| mc-fips | affected | chainguard | mc-fips | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server | affected | chainguard | metrics-server | — |
| metrics-server-fips | affected | chainguard | metrics-server-fips | — |
| minio | affected | chainguard | minio | — |
| minio | affected | wolfi | minio | — |
| minio-fips | affected | chainguard | minio-fips | — |
| node-problem-detector-0.8 | affected | chainguard | node-problem-detector-0.8 | — |
| node-problem-detector-0.8 | affected | wolfi | node-problem-detector-0.8 | — |
| node-problem-detector-fips-0.8 | affected | chainguard | node-problem-detector-fips-0.8 | — |
| opentelemetry-collector | affected | wolfi | opentelemetry-collector | — |
| opentelemetry-collector | affected | chainguard | opentelemetry-collector | — |
| opentelemetry-collector-contrib | affected | wolfi | opentelemetry-collector-contrib | — |
| opentelemetry-collector-contrib | affected | chainguard | opentelemetry-collector-contrib | — |
| opentelemetry-collector-contrib-fips | affected | chainguard | opentelemetry-collector-contrib-fips | — |
| opentelemetry-collector-fips | affected | chainguard | opentelemetry-collector-fips | — |
| opentelemetry-operator | affected | wolfi | opentelemetry-operator | — |
| opentelemetry-operator | affected | chainguard | opentelemetry-operator | — |
| opentelemetry-operator-fips | affected | chainguard | opentelemetry-operator-fips | — |
| plutono | affected | chainguard | plutono | — |
| plutono-fips | affected | chainguard | plutono-fips | — |
| prometheus-2.51 | affected | wolfi | prometheus-2.51 | — |
| prometheus-2.51 | affected | chainguard | prometheus-2.51 | — |
| prometheus-2.53 | affected | wolfi | prometheus-2.53 | — |
| prometheus-2.53 | affected | chainguard | prometheus-2.53 | — |
| prometheus-2.54 | affected | wolfi | prometheus-2.54 | — |
| prometheus-2.54 | affected | chainguard | prometheus-2.54 | — |
| prometheus-2.55 | affected | chainguard | prometheus-2.55 | — |
| prometheus-2.55 | affected | wolfi | prometheus-2.55 | — |
| prometheus-3.0 | affected | wolfi | prometheus-3.0 | — |
| prometheus-3.0 | affected | chainguard | prometheus-3.0 | — |
| prometheus-3.2 | affected | wolfi | prometheus-3.2 | — |
| prometheus-3.2 | affected | chainguard | prometheus-3.2 | — |
| prometheus-operator | affected | wolfi | prometheus-operator | — |
| prometheus-operator | affected | chainguard | prometheus-operator | — |
| prometheus-operator-fips | affected | chainguard | prometheus-operator-fips | — |
| prometheus/prometheus | affected | github.com | github.com/prometheus/prometheus | — |
| prometheus-pushgateway | affected | chainguard | prometheus-pushgateway | — |
| prometheus-pushgateway | affected | wolfi | prometheus-pushgateway | — |
| prometheus-pushgateway-fips | affected | chainguard | prometheus-pushgateway-fips | — |
| splunk-otel-collector | affected | wolfi | splunk-otel-collector | — |
| splunk-otel-collector | affected | chainguard | splunk-otel-collector | — |
| splunk-otel-collector-fips | affected | chainguard | splunk-otel-collector-fips | — |
| telegraf-1.26 | affected | chainguard | telegraf-1.26 | — |
| telegraf-1.26 | affected | wolfi | telegraf-1.26 | — |
| telegraf-1.27 | affected | wolfi | telegraf-1.27 | — |
| telegraf-1.27 | affected | chainguard | telegraf-1.27 | — |
| telegraf-1.29 | affected | chainguard | telegraf-1.29 | — |
| telegraf-1.29 | affected | wolfi | telegraf-1.29 | — |
| telegraf-1.31 | affected | wolfi | telegraf-1.31 | — |
| telegraf-1.31 | affected | chainguard | telegraf-1.31 | — |
| telegraf-1.32 | affected | chainguard | telegraf-1.32 | — |
| telegraf-1.32 | affected | wolfi | telegraf-1.32 | — |
| telegraf-1.33 | affected | wolfi | telegraf-1.33 | — |
| telegraf-1.33 | affected | chainguard | telegraf-1.33 | — |
| tempo | affected | chainguard | tempo | — |
| tempo | affected | wolfi | tempo | — |
| tempo-2.3 | affected | chainguard | tempo-2.3 | — |
| tempo-fips | affected | chainguard | tempo-fips | — |
| thanos | affected | chainguard | thanos | — |
| thanos | affected | wolfi | thanos | — |
| thanos-0.31 | affected | wolfi | thanos-0.31 | — |
| thanos-0.31 | affected | chainguard | thanos-0.31 | — |
| thanos-0.32 | affected | wolfi | thanos-0.32 | — |
| thanos-0.32 | affected | chainguard | thanos-0.32 | — |
| thanos-fips | affected | chainguard | thanos-fips | — |
| trillian | affected | chainguard | trillian | — |
| trillian | affected | wolfi | trillian | — |
| trillian-fips | affected | chainguard | trillian-fips | — |
| wavefront-collector-for-kubernetes-1.12 | affected | chainguard | wavefront-collector-for-kubernetes-1.12 | — |
| wavefront-collector-for-kubernetes-1.13 | affected | chainguard | wavefront-collector-for-kubernetes-1.13 | — |
Fix CVE(s): CVE-2022-48560
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:18.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:18.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:18.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:18.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:18.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:18.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:18.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:18.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:18.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:18.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:18.04 | python2.7-minimal | — |
Fix CVE(s): CVE-2022-48560
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:16.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:16.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:16.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:16.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:16.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:16.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:16.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:16.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:16.04 | python2.7-minimal | — |
Fix CVE(s): CVE-2022-48564, CVE-2023-40217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.5 | affected | TuxCare:Ubuntu:16.04 | idle-python3.5 | — |
| libpython3.5 | affected | TuxCare:Ubuntu:16.04 | libpython3.5 | — |
| libpython3.5-dev | affected | TuxCare:Ubuntu:16.04 | libpython3.5-dev | — |
| libpython3.5-minimal | affected | TuxCare:Ubuntu:16.04 | libpython3.5-minimal | — |
| libpython3.5-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython3.5-stdlib | — |
| libpython3.5-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython3.5-testsuite | — |
| python3.5 | affected | TuxCare:Ubuntu:16.04 | python3.5 | — |
| python3.5-dev | affected | TuxCare:Ubuntu:16.04 | python3.5-dev | — |
| python3.5-doc | affected | TuxCare:Ubuntu:16.04 | python3.5-doc | — |
| python3.5-examples | affected | TuxCare:Ubuntu:16.04 | python3.5-examples | — |
| python3.5-minimal | affected | TuxCare:Ubuntu:16.04 | python3.5-minimal | — |
| python3.5-venv | affected | TuxCare:Ubuntu:16.04 | python3.5-venv | — |
Fix CVE(s): CVE-2022-48564, CVE-2023-40217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.6 | affected | TuxCare:Ubuntu:18.04 | idle-python3.6 | — |
| libpython3.6 | affected | TuxCare:Ubuntu:18.04 | libpython3.6 | — |
| libpython3.6-dev | affected | TuxCare:Ubuntu:18.04 | libpython3.6-dev | — |
| libpython3.6-minimal | affected | TuxCare:Ubuntu:18.04 | libpython3.6-minimal | — |
| libpython3.6-stdlib | affected | TuxCare:Ubuntu:18.04 | libpython3.6-stdlib | — |
| libpython3.6-testsuite | affected | TuxCare:Ubuntu:18.04 | libpython3.6-testsuite | — |
| python3.6 | affected | TuxCare:Ubuntu:18.04 | python3.6 | — |
| python3.6-dev | affected | TuxCare:Ubuntu:18.04 | python3.6-dev | — |
| python3.6-doc | affected | TuxCare:Ubuntu:18.04 | python3.6-doc | — |
| python3.6-examples | affected | TuxCare:Ubuntu:18.04 | python3.6-examples | — |
| python3.6-minimal | affected | TuxCare:Ubuntu:18.04 | python3.6-minimal | — |
| python3.6-venv | affected | TuxCare:Ubuntu:18.04 | python3.6-venv | — |
CVE-2023-45287 affecting package golang for versions less than 1.20.0-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-45287 affecting package msft-golang for versions less than 1.20.0-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| msft-golang | affected | Azure Linux:2 | msft-golang | — |
CVE-2023-45287 affecting package golang for versions less than 1.20.0-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVE-2023-45287 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-45287 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-45287 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVEs:CVE-2023-45287
DEBIAN-CVE-2023-45287
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.
CVEs:CVE-2023-45287
Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the rem...
CVEs:CVE-2023-45287
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| stdlib | affected | Go | stdlib | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:20.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP3 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP4 | golang | — |
| golang | affected | openEuler:22.03-LTS | golang | — |
| golang | affected | openEuler:22.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:22.03-LTS-SP2 | golang | — |
GHSA-9f76-wg39-x86h
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | wolfi | aactl | — |
| aactl | affected | chainguard | aactl | — |
| amass | affected | wolfi | amass | — |
| amass | affected | chainguard | amass | — |
| aws-ebs-csi-driver-1.18 | affected | chainguard | aws-ebs-csi-driver-1.18 | — |
| aws-ebs-csi-driver-1.19 | affected | chainguard | aws-ebs-csi-driver-1.19 | — |
| aws-flb-cloudwatch | affected | chainguard | aws-flb-cloudwatch | — |
| aws-flb-cloudwatch | affected | wolfi | aws-flb-cloudwatch | — |
| aws-flb-firehose | affected | wolfi | aws-flb-firehose | — |
| aws-flb-firehose | affected | chainguard | aws-flb-firehose | — |
| aws-flb-kinesis | affected | wolfi | aws-flb-kinesis | — |
| aws-flb-kinesis | affected | chainguard | aws-flb-kinesis | — |
| aws-load-balancer-controller-2.4.5 | affected | chainguard | aws-load-balancer-controller-2.4.5 | — |
| aws-load-balancer-controller-2.5 | affected | chainguard | aws-load-balancer-controller-2.5 | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| calico-fips-3.25 | affected | chainguard | calico-fips-3.25 | — |
| cass-operator | affected | wolfi | cass-operator | — |
| cass-operator | affected | chainguard | cass-operator | — |
| cass-operator-fips | affected | chainguard | cass-operator-fips | — |
| cilium-envoy | affected | chainguard | cilium-envoy | — |
| cilium-envoy | affected | wolfi | cilium-envoy | — |
| cluster-autoscaler-1.24 | affected | chainguard | cluster-autoscaler-1.24 | — |
| cluster-autoscaler-fips-1.25 | affected | chainguard | cluster-autoscaler-fips-1.25 | — |
| cni-plugins | affected | chainguard | cni-plugins | — |
| cni-plugins | affected | wolfi | cni-plugins | — |
| cni-plugins-fips | affected | chainguard | cni-plugins-fips | — |
| configmap-reload | affected | wolfi | configmap-reload | — |
| configmap-reload | affected | chainguard | configmap-reload | — |
| configmap-reload-fips | affected | chainguard | configmap-reload-fips | — |
| configmap-reload-fips-0.11 | affected | chainguard | configmap-reload-fips-0.11 | — |
| cortex | affected | wolfi | cortex | — |
| cortex | affected | chainguard | cortex | — |
| ctop | affected | chainguard | ctop | — |
| ctop | affected | wolfi | ctop | — |
| dgraph | affected | chainguard | dgraph | — |
| dgraph | affected | wolfi | dgraph | — |
| docker-cli | affected | wolfi | docker-cli | — |
| docker-cli | affected | chainguard | docker-cli | — |
| docker-credential-ecr-login | affected | chainguard | docker-credential-ecr-login | — |
| docker-credential-ecr-login | affected | wolfi | docker-credential-ecr-login | — |
| falco | affected | chainguard | falco | — |
| falco | affected | wolfi | falco | — |
| flannel-cni-plugin | affected | chainguard | flannel-cni-plugin | — |
| flannel-cni-plugin | affected | wolfi | flannel-cni-plugin | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| go-bindata | affected | wolfi | go-bindata | — |
| go-bindata | affected | chainguard | go-bindata | — |
| gobuster | affected | wolfi | gobuster | — |
| gobuster | affected | chainguard | gobuster | — |
| go-licenses | affected | wolfi | go-licenses | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-md2man | affected | wolfi | go-md2man | — |
| go-md2man | affected | chainguard | go-md2man | — |
| gops | affected | wolfi | gops | — |
| gops | affected | chainguard | gops | — |
| goreleaser-1.18 | affected | wolfi | goreleaser-1.18 | — |
| goreleaser-1.18 | affected | chainguard | goreleaser-1.18 | — |
| gosu | affected | chainguard | gosu | — |
| gosu | affected | wolfi | gosu | — |
| grpcurl | affected | chainguard | grpcurl | — |
| grpcurl | affected | wolfi | grpcurl | — |
| helm-push | affected | wolfi | helm-push | — |
| helm-push | affected | chainguard | helm-push | — |
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| hubble-ui | affected | wolfi | hubble-ui | — |
| hubble-ui | affected | chainguard | hubble-ui | — |
| hubble-ui-backend | affected | chainguard | hubble-ui-backend | — |
| influx | affected | chainguard | influx | — |
| influx | affected | wolfi | influx | — |
| ip-masq-agent | affected | wolfi | ip-masq-agent | — |
| ip-masq-agent | affected | chainguard | ip-masq-agent | — |
| jsonnet-bundler | affected | chainguard | jsonnet-bundler | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| kind | affected | wolfi | kind | — |
| kind | affected | chainguard | kind | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kube-logging-logging-operator-4.1 | affected | chainguard | kube-logging-logging-operator-4.1 | — |
| kubernetes-csi-external-resizer-1.8 | affected | chainguard | kubernetes-csi-external-resizer-1.8 | — |
| kubernetes-csi-livenessprobe-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-2.10 | — |
| kubernetes-csi-livenessprobe-fips | affected | chainguard | kubernetes-csi-livenessprobe-fips | — |
| kubernetes-csi-livenessprobe-fips-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-fips-2.10 | — |
| kubernetes-csi-node-driver-registrar-fips-2.8 | affected | chainguard | kubernetes-csi-node-driver-registrar-fips-2.8 | — |
| kubernetes-dashboard-metrics-scraper | affected | wolfi | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper | affected | chainguard | kubernetes-dashboard-metrics-scraper | — |
| kyverno-1.8 | affected | chainguard | kyverno-1.8 | — |
| kyverno-policy-reporter-2.11 | affected | chainguard | kyverno-policy-reporter-2.11 | — |
| kyverno-policy-reporter-kyverno-plugin-1.5 | affected | chainguard | kyverno-policy-reporter-kyverno-plugin-1.5 | — |
| kyverno-policy-reporter-ui-1.7 | affected | chainguard | kyverno-policy-reporter-ui-1.7 | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| mage | affected | chainguard | mage | — |
| mage | affected | wolfi | mage | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server | affected | chainguard | metrics-server | — |
| nats | affected | chainguard | nats | — |
| nats | affected | wolfi | nats | — |
| newrelic-nri-kube-events-1.9 | affected | chainguard | newrelic-nri-kube-events-1.9 | — |
| nri-discovery-kubernetes | affected | wolfi | nri-discovery-kubernetes | — |
| nri-discovery-kubernetes | affected | chainguard | nri-discovery-kubernetes | — |
| nsc | affected | chainguard | nsc | — |
| nsc | affected | wolfi | nsc | — |
| oras | affected | chainguard | oras | — |
| oras | affected | wolfi | oras | — |
| petname | affected | wolfi | petname | — |
| petname | affected | chainguard | petname | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-beat-exporter-fips | affected | chainguard | prometheus-beat-exporter-fips | — |
| prometheus-bind-exporter | affected | wolfi | prometheus-bind-exporter | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-fips-2.38 | affected | chainguard | prometheus-fips-2.38 | — |
| prometheus-redis-exporter-fips-1.44 | affected | chainguard | prometheus-redis-exporter-fips-1.44 | — |
| prometheus-stackdriver-exporter | affected | wolfi | prometheus-stackdriver-exporter | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter-0.22 | affected | chainguard | prometheus-statsd-exporter-0.22 | — |
| prometheus-statsd-exporter-fips-0.22 | affected | chainguard | prometheus-statsd-exporter-fips-0.22 | — |
| protoc-gen-go-grpc | affected | wolfi | protoc-gen-go-grpc | — |
| protoc-gen-go-grpc | affected | chainguard | protoc-gen-go-grpc | — |
| render-template | affected | wolfi | render-template | — |
| render-template | affected | chainguard | render-template | — |
| sbom-scorecard | affected | wolfi | sbom-scorecard | — |
| sbom-scorecard | affected | chainguard | sbom-scorecard | — |
| scorecard | affected | chainguard | scorecard | — |
| scorecard | affected | wolfi | scorecard | — |
| slsa-verifier | affected | chainguard | slsa-verifier | — |
| slsa-verifier | affected | wolfi | slsa-verifier | — |
| smarter-device-manager | affected | wolfi | smarter-device-manager | — |
| smarter-device-manager | affected | chainguard | smarter-device-manager | — |
| smarter-device-manager-fips | affected | chainguard | smarter-device-manager-fips | — |
| sonobuoy | affected | wolfi | sonobuoy | — |
| sonobuoy | affected | chainguard | sonobuoy | — |
| sops | affected | wolfi | sops | — |
| sops | affected | chainguard | sops | — |
| stakater-reloader-0.0.119 | affected | chainguard | stakater-reloader-0.0.119 | — |
| stakater-reloader-0.0.128 | affected | chainguard | stakater-reloader-0.0.128 | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| vertical-pod-autoscaler | affected | wolfi | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler | affected | chainguard | vertical-pod-autoscaler | — |
| wait-for-port | affected | chainguard | wait-for-port | — |
| wait-for-port | affected | wolfi | wait-for-port | — |
CVE-2023-39326 affecting package golang for versions less than 1.21.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-39326 affecting package msft-golang for versions less than 1.21.5-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| msft-golang | affected | Azure Linux:2 | msft-golang | — |
CVE-2023-39326 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-39326 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-39326 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2023-39326
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
Denial of service via chunk extensions in net/http
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | wolfi | aactl | — |
| aactl | affected | chainguard | aactl | — |
| amass | affected | wolfi | amass | — |
| amass | affected | chainguard | amass | — |
| aws-flb-cloudwatch | affected | wolfi | aws-flb-cloudwatch | — |
| aws-flb-cloudwatch | affected | chainguard | aws-flb-cloudwatch | — |
| aws-flb-firehose | affected | chainguard | aws-flb-firehose | — |
| aws-flb-firehose | affected | wolfi | aws-flb-firehose | — |
| aws-flb-kinesis | affected | chainguard | aws-flb-kinesis | — |
| aws-flb-kinesis | affected | wolfi | aws-flb-kinesis | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| cass-operator | affected | wolfi | cass-operator | — |
| cass-operator | affected | chainguard | cass-operator | — |
| cass-operator-fips | affected | chainguard | cass-operator-fips | — |
| cni-plugins | affected | wolfi | cni-plugins | — |
| cni-plugins | affected | chainguard | cni-plugins | — |
| cni-plugins-fips | affected | chainguard | cni-plugins-fips | — |
| configmap-reload | affected | wolfi | configmap-reload | — |
| configmap-reload | affected | chainguard | configmap-reload | — |
| configmap-reload-fips | affected | chainguard | configmap-reload-fips | — |
| configmap-reload-fips-0.11 | affected | chainguard | configmap-reload-fips-0.11 | — |
| cortex | affected | chainguard | cortex | — |
| cortex | affected | wolfi | cortex | — |
| ctop | affected | wolfi | ctop | — |
| ctop | affected | chainguard | ctop | — |
| dgraph | affected | wolfi | dgraph | — |
| dgraph | affected | chainguard | dgraph | — |
| docker-cli | affected | wolfi | docker-cli | — |
| docker-cli | affected | chainguard | docker-cli | — |
| docker-credential-ecr-login | affected | wolfi | docker-credential-ecr-login | — |
| docker-credential-ecr-login | affected | chainguard | docker-credential-ecr-login | — |
| flannel-cni-plugin | affected | chainguard | flannel-cni-plugin | — |
| flannel-cni-plugin | affected | wolfi | flannel-cni-plugin | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| go-bindata | affected | wolfi | go-bindata | — |
| go-bindata | affected | chainguard | go-bindata | — |
| gobuster | affected | chainguard | gobuster | — |
| gobuster | affected | wolfi | gobuster | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-licenses | affected | wolfi | go-licenses | — |
| go-md2man | affected | wolfi | go-md2man | — |
| go-md2man | affected | chainguard | go-md2man | — |
| gops | affected | chainguard | gops | — |
| gops | affected | wolfi | gops | — |
| gosu | affected | chainguard | gosu | — |
| gosu | affected | wolfi | gosu | — |
| grpcurl | affected | chainguard | grpcurl | — |
| grpcurl | affected | wolfi | grpcurl | — |
| helm-push | affected | chainguard | helm-push | — |
| helm-push | affected | wolfi | helm-push | — |
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| hubble-ui | affected | chainguard | hubble-ui | — |
| hubble-ui | affected | wolfi | hubble-ui | — |
| influx | affected | wolfi | influx | — |
| influx | affected | chainguard | influx | — |
| ip-masq-agent | affected | wolfi | ip-masq-agent | — |
| ip-masq-agent | affected | chainguard | ip-masq-agent | — |
| jsonnet-bundler | affected | chainguard | jsonnet-bundler | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| kind | affected | wolfi | kind | — |
| kind | affected | chainguard | kind | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kube-logging-logging-operator-4.1 | affected | chainguard | kube-logging-logging-operator-4.1 | — |
| kubernetes-csi-livenessprobe-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-2.10 | — |
| kubernetes-csi-livenessprobe-fips | affected | chainguard | kubernetes-csi-livenessprobe-fips | — |
| kubernetes-csi-livenessprobe-fips-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-fips-2.10 | — |
| kubernetes-dashboard-metrics-scraper | affected | wolfi | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper | affected | chainguard | kubernetes-dashboard-metrics-scraper | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| mage | affected | chainguard | mage | — |
| mage | affected | wolfi | mage | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server | affected | chainguard | metrics-server | — |
| nats | affected | chainguard | nats | — |
| nats | affected | wolfi | nats | — |
| nri-discovery-kubernetes | affected | wolfi | nri-discovery-kubernetes | — |
| nri-discovery-kubernetes | affected | chainguard | nri-discovery-kubernetes | — |
| nsc | affected | wolfi | nsc | — |
| nsc | affected | chainguard | nsc | — |
| oras | affected | chainguard | oras | — |
| oras | affected | wolfi | oras | — |
| petname | affected | wolfi | petname | — |
| petname | affected | chainguard | petname | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-beat-exporter-fips | affected | chainguard | prometheus-beat-exporter-fips | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter-fips-0.22 | affected | chainguard | prometheus-statsd-exporter-fips-0.22 | — |
| protoc-gen-go-grpc | affected | chainguard | protoc-gen-go-grpc | — |
| protoc-gen-go-grpc | affected | wolfi | protoc-gen-go-grpc | — |
| render-template | affected | wolfi | render-template | — |
| render-template | affected | chainguard | render-template | — |
| sbom-scorecard | affected | chainguard | sbom-scorecard | — |
| sbom-scorecard | affected | wolfi | sbom-scorecard | — |
| scorecard | affected | chainguard | scorecard | — |
| scorecard | affected | wolfi | scorecard | — |
| slsa-verifier | affected | chainguard | slsa-verifier | — |
| slsa-verifier | affected | wolfi | slsa-verifier | — |
| smarter-device-manager | affected | chainguard | smarter-device-manager | — |
| smarter-device-manager | affected | wolfi | smarter-device-manager | — |
| smarter-device-manager-fips | affected | chainguard | smarter-device-manager-fips | — |
| sonobuoy | affected | chainguard | sonobuoy | — |
| sonobuoy | affected | wolfi | sonobuoy | — |
| sops | affected | wolfi | sops | — |
| sops | affected | chainguard | sops | — |
| stakater-reloader-0.0.119 | affected | chainguard | stakater-reloader-0.0.119 | — |
| stakater-reloader-0.0.128 | affected | chainguard | stakater-reloader-0.0.128 | — |
| stdlib | affected | Go | stdlib | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| vertical-pod-autoscaler | affected | chainguard | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler | affected | wolfi | vertical-pod-autoscaler | — |
| wait-for-port | affected | wolfi | wait-for-port | — |
| wait-for-port | affected | chainguard | wait-for-port | — |
GHSA-5f94-vhjq-rpg8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | chainguard | aactl | — |
| aactl | affected | wolfi | aactl | — |
| amass | affected | wolfi | amass | — |
| amass | affected | chainguard | amass | — |
| aws-ebs-csi-driver-1.18 | affected | chainguard | aws-ebs-csi-driver-1.18 | — |
| aws-ebs-csi-driver-1.19 | affected | chainguard | aws-ebs-csi-driver-1.19 | — |
| aws-flb-cloudwatch | affected | chainguard | aws-flb-cloudwatch | — |
| aws-flb-cloudwatch | affected | wolfi | aws-flb-cloudwatch | — |
| aws-flb-firehose | affected | wolfi | aws-flb-firehose | — |
| aws-flb-firehose | affected | chainguard | aws-flb-firehose | — |
| aws-flb-kinesis | affected | chainguard | aws-flb-kinesis | — |
| aws-flb-kinesis | affected | wolfi | aws-flb-kinesis | — |
| aws-load-balancer-controller-2.4.5 | affected | chainguard | aws-load-balancer-controller-2.4.5 | — |
| aws-load-balancer-controller-2.5 | affected | chainguard | aws-load-balancer-controller-2.5 | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| calico-fips-3.25 | affected | chainguard | calico-fips-3.25 | — |
| cass-operator | affected | wolfi | cass-operator | — |
| cass-operator | affected | chainguard | cass-operator | — |
| cass-operator-fips | affected | chainguard | cass-operator-fips | — |
| cilium-envoy | affected | wolfi | cilium-envoy | — |
| cilium-envoy | affected | chainguard | cilium-envoy | — |
| cluster-autoscaler-1.24 | affected | chainguard | cluster-autoscaler-1.24 | — |
| cluster-autoscaler-fips-1.25 | affected | chainguard | cluster-autoscaler-fips-1.25 | — |
| cni-plugins | affected | chainguard | cni-plugins | — |
| cni-plugins | affected | wolfi | cni-plugins | — |
| cni-plugins-fips | affected | chainguard | cni-plugins-fips | — |
| configmap-reload | affected | wolfi | configmap-reload | — |
| configmap-reload | affected | chainguard | configmap-reload | — |
| configmap-reload-fips | affected | chainguard | configmap-reload-fips | — |
| configmap-reload-fips-0.11 | affected | chainguard | configmap-reload-fips-0.11 | — |
| cortex | affected | wolfi | cortex | — |
| cortex | affected | chainguard | cortex | — |
| ctop | affected | chainguard | ctop | — |
| ctop | affected | wolfi | ctop | — |
| dgraph | affected | wolfi | dgraph | — |
| dgraph | affected | chainguard | dgraph | — |
| docker-cli | affected | wolfi | docker-cli | — |
| docker-cli | affected | chainguard | docker-cli | — |
| docker-credential-ecr-login | affected | chainguard | docker-credential-ecr-login | — |
| docker-credential-ecr-login | affected | wolfi | docker-credential-ecr-login | — |
| falco | affected | wolfi | falco | — |
| falco | affected | chainguard | falco | — |
| flannel-cni-plugin | affected | wolfi | flannel-cni-plugin | — |
| flannel-cni-plugin | affected | chainguard | flannel-cni-plugin | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| go-bindata | affected | chainguard | go-bindata | — |
| go-bindata | affected | wolfi | go-bindata | — |
| gobuster | affected | chainguard | gobuster | — |
| gobuster | affected | wolfi | gobuster | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-licenses | affected | wolfi | go-licenses | — |
| go-md2man | affected | wolfi | go-md2man | — |
| go-md2man | affected | chainguard | go-md2man | — |
| gops | affected | chainguard | gops | — |
| gops | affected | wolfi | gops | — |
| goreleaser-1.18 | affected | wolfi | goreleaser-1.18 | — |
| goreleaser-1.18 | affected | chainguard | goreleaser-1.18 | — |
| gosu | affected | wolfi | gosu | — |
| gosu | affected | chainguard | gosu | — |
| grpcurl | affected | wolfi | grpcurl | — |
| grpcurl | affected | chainguard | grpcurl | — |
| helm-push | affected | wolfi | helm-push | — |
| helm-push | affected | chainguard | helm-push | — |
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| hubble-ui | affected | wolfi | hubble-ui | — |
| hubble-ui | affected | chainguard | hubble-ui | — |
| hubble-ui-backend | affected | chainguard | hubble-ui-backend | — |
| influx | affected | chainguard | influx | — |
| influx | affected | wolfi | influx | — |
| ip-masq-agent | affected | wolfi | ip-masq-agent | — |
| ip-masq-agent | affected | chainguard | ip-masq-agent | — |
| jsonnet-bundler | affected | chainguard | jsonnet-bundler | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| kind | affected | wolfi | kind | — |
| kind | affected | chainguard | kind | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kube-logging-logging-operator-4.1 | affected | chainguard | kube-logging-logging-operator-4.1 | — |
| kubernetes-csi-external-resizer-1.8 | affected | chainguard | kubernetes-csi-external-resizer-1.8 | — |
| kubernetes-csi-livenessprobe-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-2.10 | — |
| kubernetes-csi-livenessprobe-fips | affected | chainguard | kubernetes-csi-livenessprobe-fips | — |
| kubernetes-csi-livenessprobe-fips-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-fips-2.10 | — |
| kubernetes-csi-node-driver-registrar-fips-2.8 | affected | chainguard | kubernetes-csi-node-driver-registrar-fips-2.8 | — |
| kubernetes-dashboard-metrics-scraper | affected | wolfi | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper | affected | chainguard | kubernetes-dashboard-metrics-scraper | — |
| kyverno-1.8 | affected | chainguard | kyverno-1.8 | — |
| kyverno-policy-reporter-2.11 | affected | chainguard | kyverno-policy-reporter-2.11 | — |
| kyverno-policy-reporter-kyverno-plugin-1.5 | affected | chainguard | kyverno-policy-reporter-kyverno-plugin-1.5 | — |
| kyverno-policy-reporter-ui-1.7 | affected | chainguard | kyverno-policy-reporter-ui-1.7 | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| mage | affected | wolfi | mage | — |
| mage | affected | chainguard | mage | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server | affected | chainguard | metrics-server | — |
| nats | affected | chainguard | nats | — |
| nats | affected | wolfi | nats | — |
| newrelic-nri-kube-events-1.9 | affected | chainguard | newrelic-nri-kube-events-1.9 | — |
| nri-discovery-kubernetes | affected | chainguard | nri-discovery-kubernetes | — |
| nri-discovery-kubernetes | affected | wolfi | nri-discovery-kubernetes | — |
| nsc | affected | wolfi | nsc | — |
| nsc | affected | chainguard | nsc | — |
| oras | affected | wolfi | oras | — |
| oras | affected | chainguard | oras | — |
| petname | affected | wolfi | petname | — |
| petname | affected | chainguard | petname | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-beat-exporter-fips | affected | chainguard | prometheus-beat-exporter-fips | — |
| prometheus-bind-exporter | affected | wolfi | prometheus-bind-exporter | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-fips-2.38 | affected | chainguard | prometheus-fips-2.38 | — |
| prometheus-redis-exporter-fips-1.44 | affected | chainguard | prometheus-redis-exporter-fips-1.44 | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-stackdriver-exporter | affected | wolfi | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter-0.22 | affected | chainguard | prometheus-statsd-exporter-0.22 | — |
| prometheus-statsd-exporter-fips-0.22 | affected | chainguard | prometheus-statsd-exporter-fips-0.22 | — |
| protoc-gen-go-grpc | affected | wolfi | protoc-gen-go-grpc | — |
| protoc-gen-go-grpc | affected | chainguard | protoc-gen-go-grpc | — |
| render-template | affected | chainguard | render-template | — |
| render-template | affected | wolfi | render-template | — |
| sbom-scorecard | affected | wolfi | sbom-scorecard | — |
| sbom-scorecard | affected | chainguard | sbom-scorecard | — |
| scorecard | affected | chainguard | scorecard | — |
| scorecard | affected | wolfi | scorecard | — |
| slsa-verifier | affected | wolfi | slsa-verifier | — |
| slsa-verifier | affected | chainguard | slsa-verifier | — |
| smarter-device-manager | affected | wolfi | smarter-device-manager | — |
| smarter-device-manager | affected | chainguard | smarter-device-manager | — |
| smarter-device-manager-fips | affected | chainguard | smarter-device-manager-fips | — |
| sonobuoy | affected | chainguard | sonobuoy | — |
| sonobuoy | affected | wolfi | sonobuoy | — |
| sops | affected | wolfi | sops | — |
| sops | affected | chainguard | sops | — |
| stakater-reloader-0.0.119 | affected | chainguard | stakater-reloader-0.0.119 | — |
| stakater-reloader-0.0.128 | affected | chainguard | stakater-reloader-0.0.128 | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| vertical-pod-autoscaler | affected | chainguard | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler | affected | wolfi | vertical-pod-autoscaler | — |
| wait-for-port | affected | wolfi | wait-for-port | — |
| wait-for-port | affected | chainguard | wait-for-port | — |
CVE-2023-45285 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-45285 affecting package msft-golang for versions less than 1.22.3-1.
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| msft-golang | affected | Azure Linux:2 | msft-golang | — |
CVE-2023-45285 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-45285 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-45285 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
DEBIAN-CVE-2023-45285
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
Command 'go get' may unexpectedly fallback to insecure git in cmd/go
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | chainguard | aactl | — |
| aactl | affected | wolfi | aactl | — |
| amass | affected | chainguard | amass | — |
| amass | affected | wolfi | amass | — |
| aws-flb-cloudwatch | affected | wolfi | aws-flb-cloudwatch | — |
| aws-flb-cloudwatch | affected | chainguard | aws-flb-cloudwatch | — |
| aws-flb-firehose | affected | wolfi | aws-flb-firehose | — |
| aws-flb-firehose | affected | chainguard | aws-flb-firehose | — |
| aws-flb-kinesis | affected | chainguard | aws-flb-kinesis | — |
| aws-flb-kinesis | affected | wolfi | aws-flb-kinesis | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| cass-operator | affected | wolfi | cass-operator | — |
| cass-operator | affected | chainguard | cass-operator | — |
| cass-operator-fips | affected | chainguard | cass-operator-fips | — |
| cni-plugins | affected | chainguard | cni-plugins | — |
| cni-plugins | affected | wolfi | cni-plugins | — |
| cni-plugins-fips | affected | chainguard | cni-plugins-fips | — |
| configmap-reload | affected | chainguard | configmap-reload | — |
| configmap-reload | affected | wolfi | configmap-reload | — |
| configmap-reload-fips | affected | chainguard | configmap-reload-fips | — |
| configmap-reload-fips-0.11 | affected | chainguard | configmap-reload-fips-0.11 | — |
| cortex | affected | chainguard | cortex | — |
| cortex | affected | wolfi | cortex | — |
| ctop | affected | chainguard | ctop | — |
| ctop | affected | wolfi | ctop | — |
| dgraph | affected | chainguard | dgraph | — |
| dgraph | affected | wolfi | dgraph | — |
| docker-cli | affected | chainguard | docker-cli | — |
| docker-cli | affected | wolfi | docker-cli | — |
| docker-credential-ecr-login | affected | wolfi | docker-credential-ecr-login | — |
| docker-credential-ecr-login | affected | chainguard | docker-credential-ecr-login | — |
| flannel-cni-plugin | affected | chainguard | flannel-cni-plugin | — |
| flannel-cni-plugin | affected | wolfi | flannel-cni-plugin | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| go-bindata | affected | chainguard | go-bindata | — |
| go-bindata | affected | wolfi | go-bindata | — |
| gobuster | affected | chainguard | gobuster | — |
| gobuster | affected | wolfi | gobuster | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-licenses | affected | wolfi | go-licenses | — |
| go-md2man | affected | chainguard | go-md2man | — |
| go-md2man | affected | wolfi | go-md2man | — |
| gops | affected | chainguard | gops | — |
| gops | affected | wolfi | gops | — |
| gosu | affected | wolfi | gosu | — |
| gosu | affected | chainguard | gosu | — |
| grpcurl | affected | chainguard | grpcurl | — |
| grpcurl | affected | wolfi | grpcurl | — |
| helm-push | affected | chainguard | helm-push | — |
| helm-push | affected | wolfi | helm-push | — |
| hey | affected | chainguard | hey | — |
| hey | affected | wolfi | hey | — |
| hubble-ui | affected | chainguard | hubble-ui | — |
| hubble-ui | affected | wolfi | hubble-ui | — |
| influx | affected | wolfi | influx | — |
| influx | affected | chainguard | influx | — |
| ip-masq-agent | affected | wolfi | ip-masq-agent | — |
| ip-masq-agent | affected | chainguard | ip-masq-agent | — |
| jsonnet-bundler | affected | chainguard | jsonnet-bundler | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| kind | affected | chainguard | kind | — |
| kind | affected | wolfi | kind | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kube-logging-logging-operator-4.1 | affected | chainguard | kube-logging-logging-operator-4.1 | — |
| kubernetes-csi-livenessprobe-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-2.10 | — |
| kubernetes-csi-livenessprobe-fips | affected | chainguard | kubernetes-csi-livenessprobe-fips | — |
| kubernetes-csi-livenessprobe-fips-2.10 | affected | chainguard | kubernetes-csi-livenessprobe-fips-2.10 | — |
| kubernetes-dashboard-metrics-scraper | affected | chainguard | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper | affected | wolfi | kubernetes-dashboard-metrics-scraper | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| mage | affected | chainguard | mage | — |
| mage | affected | wolfi | mage | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server | affected | chainguard | metrics-server | — |
| nats | affected | chainguard | nats | — |
| nats | affected | wolfi | nats | — |
| nri-discovery-kubernetes | affected | wolfi | nri-discovery-kubernetes | — |
| nri-discovery-kubernetes | affected | chainguard | nri-discovery-kubernetes | — |
| nsc | affected | wolfi | nsc | — |
| nsc | affected | chainguard | nsc | — |
| oras | affected | wolfi | oras | — |
| oras | affected | chainguard | oras | — |
| petname | affected | chainguard | petname | — |
| petname | affected | wolfi | petname | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-beat-exporter-fips | affected | chainguard | prometheus-beat-exporter-fips | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter-fips-0.22 | affected | chainguard | prometheus-statsd-exporter-fips-0.22 | — |
| protoc-gen-go-grpc | affected | chainguard | protoc-gen-go-grpc | — |
| protoc-gen-go-grpc | affected | wolfi | protoc-gen-go-grpc | — |
| render-template | affected | wolfi | render-template | — |
| render-template | affected | chainguard | render-template | — |
| sbom-scorecard | affected | wolfi | sbom-scorecard | — |
| sbom-scorecard | affected | chainguard | sbom-scorecard | — |
| scorecard | affected | chainguard | scorecard | — |
| scorecard | affected | wolfi | scorecard | — |
| slsa-verifier | affected | wolfi | slsa-verifier | — |
| slsa-verifier | affected | chainguard | slsa-verifier | — |
| smarter-device-manager | affected | chainguard | smarter-device-manager | — |
| smarter-device-manager | affected | wolfi | smarter-device-manager | — |
| smarter-device-manager-fips | affected | chainguard | smarter-device-manager-fips | — |
| sonobuoy | affected | wolfi | sonobuoy | — |
| sonobuoy | affected | chainguard | sonobuoy | — |
| sops | affected | chainguard | sops | — |
| sops | affected | wolfi | sops | — |
| stakater-reloader-0.0.119 | affected | chainguard | stakater-reloader-0.0.119 | — |
| stakater-reloader-0.0.128 | affected | chainguard | stakater-reloader-0.0.128 | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| toolchain | affected | Go | toolchain | — |
| vertical-pod-autoscaler | affected | chainguard | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler | affected | wolfi | vertical-pod-autoscaler | — |
| wait-for-port | affected | chainguard | wait-for-port | — |
| wait-for-port | affected | wolfi | wait-for-port | — |
Fix CVE(s): CVE-2023-40217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:16.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:16.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:16.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:16.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:16.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:16.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:16.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:16.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:16.04 | python2.7-minimal | — |
Fix CVE(s): CVE-2023-40217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:18.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:18.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:18.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:18.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:18.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:18.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:18.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:18.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:18.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:18.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:18.04 | python2.7-minimal | — |
Maliciously crafted Git server replies can cause DoS on go-git clients
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go-git/go-git/v5 | affected | github.com | github.com/go-git/go-git/v5 | — |
| src-d/go-git.v4 | affected | gopkg.in | gopkg.in/src-d/go-git.v4 | — |
Maliciously crafted Git server replies can cause DoS on go-git clients
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| apko | affected | wolfi | apko | — |
| apko | affected | chainguard | apko | — |
| argo-cd-2.7 | affected | wolfi | argo-cd-2.7 | — |
| argo-cd-2.7 | affected | chainguard | argo-cd-2.7 | — |
| argo-cd-2.8 | affected | chainguard | argo-cd-2.8 | — |
| argo-cd-2.8 | affected | wolfi | argo-cd-2.8 | — |
| argo-cd-2.9 | affected | wolfi | argo-cd-2.9 | — |
| argo-cd-2.9 | affected | chainguard | argo-cd-2.9 | — |
| bom | affected | chainguard | bom | — |
| bom | affected | wolfi | bom | — |
| flux-0 | affected | chainguard | flux-0 | — |
| flux-0.37 | affected | chainguard | flux-0.37 | — |
| flux-2.0 | affected | chainguard | flux-2.0 | — |
| flux-kustomize-controller | affected | chainguard | flux-kustomize-controller | — |
| flux-kustomize-controller | affected | wolfi | flux-kustomize-controller | — |
| flux-kustomize-controller-2.0 | affected | chainguard | flux-kustomize-controller-2.0 | — |
| flux-source-controller-2.0 | affected | chainguard | flux-source-controller-2.0 | — |
| gitness | affected | wolfi | gitness | — |
| gitness | affected | chainguard | gitness | — |
| gitsign | affected | chainguard | gitsign | — |
| gitsign | affected | wolfi | gitsign | — |
| go-git/go-git/v5 | affected | github.com | github.com/go-git/go-git/v5 | — |
| go-licenses | affected | chainguard | go-licenses | — |
| go-licenses | affected | wolfi | go-licenses | — |
| gomplate | affected | chainguard | gomplate | — |
| gomplate | affected | wolfi | gomplate | — |
| goreleaser | affected | chainguard | goreleaser | — |
| goreleaser | affected | wolfi | goreleaser | — |
| goreleaser-1.18 | affected | wolfi | goreleaser-1.18 | — |
| goreleaser-1.18 | affected | chainguard | goreleaser-1.18 | — |
| grafana-10.1 | affected | chainguard | grafana-10.1 | — |
| grafana-9 | affected | chainguard | grafana-9 | — |
| grafana-9.3 | affected | chainguard | grafana-9.3 | — |
| kots | affected | wolfi | kots | — |
| kots | affected | chainguard | kots | — |
| kubevela | affected | wolfi | kubevela | — |
| kubevela | affected | chainguard | kubevela | — |
| nuclei | affected | chainguard | nuclei | — |
| nuclei | affected | wolfi | nuclei | — |
| pulumi | affected | wolfi | pulumi | — |
| pulumi | affected | chainguard | pulumi | — |
| pulumi-kubernetes-operator | affected | wolfi | pulumi-kubernetes-operator | — |
| pulumi-kubernetes-operator | affected | chainguard | pulumi-kubernetes-operator | — |
| pulumi-language-dotnet | affected | chainguard | pulumi-language-dotnet | — |
| pulumi-language-dotnet | affected | wolfi | pulumi-language-dotnet | — |
| pulumi-language-java | affected | wolfi | pulumi-language-java | — |
| pulumi-language-java | affected | chainguard | pulumi-language-java | — |
| pulumi-language-yaml | affected | wolfi | pulumi-language-yaml | — |
| pulumi-language-yaml | affected | chainguard | pulumi-language-yaml | — |
| scorecard | affected | wolfi | scorecard | — |
| scorecard | affected | chainguard | scorecard | — |
| src-d/go-git.v4 | affected | gopkg.in | gopkg.in/src-d/go-git.v4 | — |
| src-fingerprint | affected | wolfi | src-fingerprint | — |
| src-fingerprint | affected | chainguard | src-fingerprint | — |
| tekton-pipelines | affected | wolfi | tekton-pipelines | — |
| tekton-pipelines | affected | chainguard | tekton-pipelines | — |
| zot | affected | wolfi | zot | — |
| zot | affected | chainguard | zot | — |
CVEs:CVE-2023-45777
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to launch arbitrary activities using system privileges due to Parcel Mismatch. This could lead to local escalation of privilege with no additional execution privi...
CVEs:CVE-2023-45777
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In the APEX module framework of AOSP, there is a possible malicious update to platform components due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2023-45779
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-45779
ASB-A-301094654
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40084
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40084
CVEs:CVE-2023-48409
In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional e...
CVEs:CVE-2023-48409
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-296984851
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-40077
In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40077
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-35618
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2023-35618
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2023-40076
In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVEs:CVE-2023-40076
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-38174
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVEs:CVE-2023-38174
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2023-36878
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVEs:CVE-2023-36878
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
lestrrat-go/jwx's malicious parameters in JWE can cause a DOS
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cosign-fips | affected | chainguard | cosign-fips | — |
| cosign-fips | affected | wolfi | cosign-fips | — |
| external-secrets-0.7 | affected | chainguard | external-secrets-0.7 | — |
| falco | affected | wolfi | falco | — |
| falco | affected | chainguard | falco | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| gitsign | affected | chainguard | gitsign | — |
| gitsign | affected | wolfi | gitsign | — |
| istio-cni-1.19 | affected | chainguard | istio-cni-1.19 | — |
| istio-cni-1.19 | affected | wolfi | istio-cni-1.19 | — |
| istio-cni-1.20 | affected | wolfi | istio-cni-1.20 | — |
| istio-cni-1.20 | affected | chainguard | istio-cni-1.20 | — |
| istio-cni-fips-1.19 | affected | chainguard | istio-cni-fips-1.19 | — |
| istio-operator-1.19 | affected | chainguard | istio-operator-1.19 | — |
| istio-operator-1.19 | affected | wolfi | istio-operator-1.19 | — |
| istio-operator-1.20 | affected | wolfi | istio-operator-1.20 | — |
| istio-operator-1.20 | affected | chainguard | istio-operator-1.20 | — |
| istio-operator-fips-1.19 | affected | chainguard | istio-operator-fips-1.19 | — |
| istio-pilot-agent-1.18 | affected | wolfi | istio-pilot-agent-1.18 | — |
| istio-pilot-agent-1.18 | affected | chainguard | istio-pilot-agent-1.18 | — |
| istio-pilot-agent-1.19 | affected | chainguard | istio-pilot-agent-1.19 | — |
| istio-pilot-agent-1.19 | affected | wolfi | istio-pilot-agent-1.19 | — |
| istio-pilot-agent-1.20 | affected | wolfi | istio-pilot-agent-1.20 | — |
| istio-pilot-agent-1.20 | affected | chainguard | istio-pilot-agent-1.20 | — |
| istio-pilot-agent-fips-1.19 | affected | chainguard | istio-pilot-agent-fips-1.19 | — |
| istio-pilot-discovery-1.18 | affected | chainguard | istio-pilot-discovery-1.18 | — |
| istio-pilot-discovery-1.18 | affected | wolfi | istio-pilot-discovery-1.18 | — |
| istio-pilot-discovery-1.19 | affected | chainguard | istio-pilot-discovery-1.19 | — |
| istio-pilot-discovery-1.19 | affected | wolfi | istio-pilot-discovery-1.19 | — |
| istio-pilot-discovery-1.20 | affected | wolfi | istio-pilot-discovery-1.20 | — |
| istio-pilot-discovery-1.20 | affected | chainguard | istio-pilot-discovery-1.20 | — |
| istio-pilot-discovery-fips-1.19 | affected | chainguard | istio-pilot-discovery-fips-1.19 | — |
| kubescape | affected | wolfi | kubescape | — |
| kubescape | affected | chainguard | kubescape | — |
| kyverno | affected | wolfi | kyverno | — |
| kyverno | affected | chainguard | kyverno | — |
| lestrrat-go/jwx | affected | github.com | github.com/lestrrat-go/jwx | — |
| lestrrat-go/jwx/v2 | affected | github.com | github.com/lestrrat-go/jwx/v2 | — |
| tekton-chains | affected | wolfi | tekton-chains | — |
| tekton-chains | affected | chainguard | tekton-chains | — |
| vexctl | affected | chainguard | vexctl | — |
| vexctl | affected | wolfi | vexctl | — |
lestrrat-go/jwx's malicious parameters in JWE can cause a DOS
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| lestrrat-go/jwx | affected | github.com | github.com/lestrrat-go/jwx | — |
| lestrrat-go/jwx/v2 | affected | github.com | github.com/lestrrat-go/jwx/v2 | — |
CVEs:CVE-2022-44589
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA , Two Factor, OTP SMS and Email | Passwordless login.This issue affects miniOrange'...
CVEs:CVE-2022-44589
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_authenticator | affected | miniorange | — | — |
CVEs:CVE-2023-40082
In modify_for_next_stage of fdt.rs, there is a possible way to render KASLR ineffective due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-40082
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-292004859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-40090
In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interacti...
CVEs:CVE-2023-40090
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40078
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. Us...
CVEs:CVE-2023-40078
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48423
In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48423
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-294560448
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-48416
In multiple locations, there is a possible null dereference due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48416
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-244500020
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
CVEs:CVE-2023-42716
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42716
CVEs:CVE-2023-42717
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
CVEs:CVE-2023-42717
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48397
In Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48397
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48413
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48413
PUB-A-286709510
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-293719047
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-21162
In RGXUnbackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2023-21162
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21163
In PMR_ReadBytes of pmr.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2023-21163
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21164
In DevmemIntMapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2023-21164
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21166
In RGXBackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-21166
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In DevmemIntAcquireRemoteCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is...
CVEs:CVE-2023-21215
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21215
In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-21217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21217
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interacti...
CVEs:CVE-2023-21218
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21218
CVEs:CVE-2023-21228
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interacti...
CVEs:CVE-2023-21228
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21263
In OSMMapPMRGeneric of pmr_os.c, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-21263
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21401
In DevmemIntChangeSparse of devicemem_server.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2023-21401
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21402
In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2023-21402
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21403
In RGXDestroyZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not need...
CVEs:CVE-2023-21403
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-35690
In RGXDestroyHWRTData of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2023-35690
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-291982610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-291999439
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-292000190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-292002163
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-292002918
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-292003338
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-292004168
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-292087506
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-305091236
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-305093885
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-305095406
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-305095935
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-305096969
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-48403
In sms_DecodeCodedTpMsg of sms_PduCodec.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure if the attacker is able to observe the behavior of the subsequent switch conditional with ...
CVEs:CVE-2023-48403
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-285435372
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In ProtocolMiscCarrierConfigSimInfoIndAdapter of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User intera...
CVEs:CVE-2023-48404
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48404
CVEs:CVE-2023-48410
In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48410
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-289563789
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-299427380
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction i...
CVEs:CVE-2023-21216
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21216
ASB-A-291999952
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-48425
U-Boot vulnerability resulting in persistent Code Execution
CVEs:CVE-2023-48425
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromecast_firmware | affected | — | — |
CVEs:CVE-2023-42561
Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.
CVEs:CVE-2023-42561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
ASB-A-296910715
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVE-2023-49292 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-49292 affecting package golang for versions less than 1.21.6-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2023-49292 affecting package golang for versions less than 1.20.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVE-2023-49292 affecting package golang 1.25.7-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
CVEs:CVE-2023-48398
In ProtocolNetAcBarringInfo::ProtocolNetAcBarringInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User i...
CVEs:CVE-2023-48398
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-286055426
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-42559
Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.
CVEs:CVE-2023-42559
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
U-Boot shell vulnerability resulting in Privilege escalation in a production device
CVEs:CVE-2023-48424
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromecast_firmware | affected | — | — |
CVEs:CVE-2023-48424
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
CVEs:CVE-2023-48417
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromecast_firmware | affected | — | — |
CVEs:CVE-2023-48417
In HTBLogKM of htbserver.c, there is a possible information disclosure due to log information disclosure. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2023-21227
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-21227
ASB-A-291998937
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-42557
Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.
CVEs:CVE-2023-42557
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-49769
Cross-Site Request Forgery (CSRF) vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.4.
CVEs:CVE-2023-49769
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| integrate_google_drive | affected | softlabbd | — | — |
CVEs:CVE-2023-42566
Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.
CVEs:CVE-2023-42566
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-42567
Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.
CVEs:CVE-2023-42567
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
ASB-A-272772567
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In transcodeQ*ToFloat of btif_avrcp_audio_track.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not ...
CVEs:CVE-2023-40087
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40087
Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.
CVEs:CVE-2023-42556
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-42556
CVEs:CVE-2023-42560
Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.
CVEs:CVE-2023-42560
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-42558
Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.
CVEs:CVE-2023-42558
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-42565
Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.
CVEs:CVE-2023-42565
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-42568
Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
CVEs:CVE-2023-42568
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-3742
Insufficient policy enforcement in ADB in Google Chrome on ChromeOS prior to 114.0.5735.90 allowed a local attacker to bypass device policy restrictions via physical access to the device. (Chromium security severity: High)
CVEs:CVE-2023-3742
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2023-42563
Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
CVEs:CVE-2023-42563
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-42569
Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.
CVEs:CVE-2023-42569
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.
CVEs:CVE-2023-42570
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-42570
Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
CVEs:CVE-2023-42564
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2023-42564
In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audio from the background due to a missing flag. This could lead to local escalation of privilege with User execution privileges needed. User interaction is...
CVEs:CVE-2023-40096
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40096
CVEs:CVE-2023-42562
Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
CVEs:CVE-2023-42562
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
ASB-A-295942985
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40103
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40103
ASB-A-299146464
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-299146536
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-299146326
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40083
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40083
PUB-A-258533280
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-35668
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-35668
CVEs:CVE-2023-40074
In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40074
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40073
In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40073
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42724
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42724
In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...
CVEs:CVE-2023-40094
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40094
CVEs:CVE-2023-40080
In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2023-40080
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-45781
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-45781
CVEs:CVE-2023-40079
In injectSendIntentSender of ShortcutService.java, there is a possible background activity launch due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...
CVEs:CVE-2023-40079
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In onTransact of IncidentService.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-40091
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40091
In createDontSendToRestrictedAppsBundle of PendingIntentUtils.java, there is a possible background activity launch due to a missing check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...
CVEs:CVE-2023-40095
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40095
CVEs:CVE-2023-40097
In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for ex...
CVEs:CVE-2023-40097
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-45773
In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-45773
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-45774
In fixUpIncomingShortcutInfo of ShortcutService.java, there is a possible way to view another user's image due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...
CVEs:CVE-2023-45774
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2023-45775
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-45775
In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2023-45776
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-45776
CVEs:CVE-2023-40098
In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. U...
CVEs:CVE-2023-40098
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-300376910
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction ...
CVEs:CVE-2023-40081
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40081
CVEs:CVE-2023-40092
In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ...
CVEs:CVE-2023-40092
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40089
In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalation of privilege with no addition...
CVEs:CVE-2023-40089
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-40075
In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges ...
CVEs:CVE-2023-40075
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-32847
In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08241940; Issue...
CVEs:CVE-2023-32847
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In decoder, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08016659; Issue ...
CVEs:CVE-2023-32850
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-32850
CVEs:CVE-2023-32851
In decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08016652; Iss...
CVEs:CVE-2023-32851
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-302982512
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-302983201
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-302986375
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-42722
In camera service, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed
CVEs:CVE-2023-42722
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48407
there is a possible DCK won't be deleted after factory reset due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48407
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-282081424
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
there is a possible way for the secure world to write to NS memory due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48405
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48405
In the Pixel Camera Driver, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48414
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48414
PUB-A-288366554
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-293298397
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-48421
In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no...
CVEs:CVE-2023-48421
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-300681900
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48406
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48406
CVEs:CVE-2023-48412
In private_handle_t of mali_gralloc_buffer.h, there is a possible information leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2023-48412
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-213170949
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-269274102
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-32848
In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896; Issue ID: ALPS081...
CVEs:CVE-2023-32848
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-302982513
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In gnss service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42751
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42751
In TeleService, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42726
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42726
In gpu driver, there is a possible out of bounds write due to a incorrect bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42727
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42727
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42729
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42729
In Gnss service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42731
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42731
In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42725
In gsp driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42684
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42684
CVEs:CVE-2023-42679
In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42679
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42680
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42680
CVEs:CVE-2023-42682
In gsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42682
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In gsp driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-42683
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42683
CVEs:CVE-2023-42715
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42715
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42718
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42718
CVEs:CVE-2023-48399
In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is no...
CVEs:CVE-2023-48399
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In GetSizeOfEenlRecords of protocoladapter.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2023-48401
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48401
In ProtocolNetSimFileInfoAdapter() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not need...
CVEs:CVE-2023-48408
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48408
CVEs:CVE-2023-48411
In SignalStrengthAdapter::FillGsmSignalStrength() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interac...
CVEs:CVE-2023-48411
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48415
In Init of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48415
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48422
In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48422
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42735
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
CVEs:CVE-2023-42735
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-291424409
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-295653694
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-296748229
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-299025883
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-300554928
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-300595972
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-42728
In phasecheckserver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-42728
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42719
In video service, there is a possible out of bounds read due to a incorrect bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-42719
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42720
In video service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-42720
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42721
In flv extractor, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-42721
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In camera service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-42723
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42723
CVEs:CVE-2022-48462
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2022-48462
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2022-48463
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2022-48463
CVEs:CVE-2022-48464
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2022-48464
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42685
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42685
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42686
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42686
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42687
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42687
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42688
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42688
CVEs:CVE-2023-42689
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42689
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42690
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42690
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42691
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42691
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42692
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42692
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42693
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42693
CVEs:CVE-2023-42694
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42694
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42695
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42695
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42696
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42696
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42681
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42681
In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48402
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48402
CVEs:CVE-2023-42748
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42748
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42736
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42736
In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42738
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42738
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42739
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42739
CVEs:CVE-2023-42740
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42740
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42743
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42743
CVEs:CVE-2023-42745
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42745
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42746
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42746
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVEs:CVE-2023-42747
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42747
PUB-A-244398863
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2023-42730
In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42730
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42732
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42732
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42733
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42733
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42734
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42734
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42705
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42705
CVEs:CVE-2023-42706
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42706
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42707
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42707
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42708
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42708
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42709
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42709
CVEs:CVE-2023-42710
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42710
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42711
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42711
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42712
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42712
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42713
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42713
CVEs:CVE-2023-42714
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42714
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42697
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42697
In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42698
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42698
CVEs:CVE-2023-42699
In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42699
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42700
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42700
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42701
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42701
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42702
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42702
CVEs:CVE-2023-42703
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42703
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42704
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42704
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42671
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42671
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42672
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42672
CVEs:CVE-2023-42673
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42673
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42674
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42674
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42675
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42675
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42676
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42676
CVEs:CVE-2023-42677
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42677
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42678
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42678
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42749
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42749
CVEs:CVE-2023-42737
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-42741
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42741
In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-42742
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42742
In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-42744
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-42744
ASB-A-294770901
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-300368868
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-300368872
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-300368874
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-300368875
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-300382178
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-300385151
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-48420
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2023-48420
PUB-A-269968522
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-285915779
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-285915800
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-276762552
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-283319108
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-297030670
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
containerd allows RAPL to be accessible to a container
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| containerd/containerd | affected | github.com | github.com/containerd/containerd | — |
containerd allows RAPL to be accessible to a container
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| buildkitd | affected | chainguard | buildkitd | — |
| buildkitd | affected | wolfi | buildkitd | — |
| cert-manager-1.11 | affected | chainguard | cert-manager-1.11 | — |
| cert-manager-1.11 | affected | wolfi | cert-manager-1.11 | — |
| cert-manager-1.12 | affected | wolfi | cert-manager-1.12 | — |
| cert-manager-1.12 | affected | chainguard | cert-manager-1.12 | — |
| cert-manager-1.13 | affected | chainguard | cert-manager-1.13 | — |
| cert-manager-1.13 | affected | wolfi | cert-manager-1.13 | — |
| cert-manager-fips-1.12 | affected | chainguard | cert-manager-fips-1.12 | — |
| cert-manager-fips-1.13 | affected | chainguard | cert-manager-fips-1.13 | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| containerd/containerd | affected | github.com | github.com/containerd/containerd | — |
| containerd/containerd | affected | github.com | github.com/containerd/containerd | — |
| ctop | affected | chainguard | ctop | — |
| ctop | affected | wolfi | ctop | — |
| eksctl | affected | wolfi | eksctl | — |
| eksctl | affected | chainguard | eksctl | — |
| flux-helm-controller | affected | chainguard | flux-helm-controller | — |
| flux-helm-controller | affected | wolfi | flux-helm-controller | — |
| flux-helm-controller-0 | affected | chainguard | flux-helm-controller-0 | — |
| flux-helm-controller-0.37 | affected | chainguard | flux-helm-controller-0.37 | — |
| flux-helm-controller-2.0 | affected | chainguard | flux-helm-controller-2.0 | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flux-source-controller-0 | affected | chainguard | flux-source-controller-0 | — |
| flux-source-controller-0.37 | affected | chainguard | flux-source-controller-0.37 | — |
| flux-source-controller-2.0 | affected | chainguard | flux-source-controller-2.0 | — |
| fuse-overlayfs-snapshotter | affected | wolfi | fuse-overlayfs-snapshotter | — |
| fuse-overlayfs-snapshotter | affected | chainguard | fuse-overlayfs-snapshotter | — |
| github.com/containerd/containerd | affected | Go | github.com/containerd/containerd | — |
| gitness | affected | wolfi | gitness | — |
| gitness | affected | chainguard | gitness | — |
| grype | affected | wolfi | grype | — |
| grype | affected | chainguard | grype | — |
| helm | affected | wolfi | helm | — |
| helm | affected | chainguard | helm | — |
| helm-push | affected | wolfi | helm-push | — |
| helm-push | affected | chainguard | helm-push | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| kaniko | affected | chainguard | kaniko | — |
| kaniko | affected | wolfi | kaniko | — |
| kots | affected | wolfi | kots | — |
| kots | affected | chainguard | kots | — |
| kubescape | affected | wolfi | kubescape | — |
| kubescape | affected | chainguard | kubescape | — |
| kubevela | affected | chainguard | kubevela | — |
| kubevela | affected | wolfi | kubevela | — |
| melange | affected | wolfi | melange | — |
| melange | affected | chainguard | melange | — |
| neuvector-agent | affected | wolfi | neuvector-agent | — |
| neuvector-agent | affected | chainguard | neuvector-agent | — |
| newrelic-infrastructure-agent | affected | chainguard | newrelic-infrastructure-agent | — |
| newrelic-infrastructure-agent | affected | wolfi | newrelic-infrastructure-agent | — |
| rancher-agent-2.8 | affected | chainguard | rancher-agent-2.8 | — |
| skaffold | affected | chainguard | skaffold | — |
| skaffold | affected | wolfi | skaffold | — |
| tekton-pipelines | affected | chainguard | tekton-pipelines | — |
| tekton-pipelines | affected | wolfi | tekton-pipelines | — |
| telegraf-1.26 | affected | chainguard | telegraf-1.26 | — |
| telegraf-1.26 | affected | wolfi | telegraf-1.26 | — |
| telegraf-1.27 | affected | chainguard | telegraf-1.27 | — |
| telegraf-1.27 | affected | wolfi | telegraf-1.27 | — |
| telegraf-1.28 | affected | wolfi | telegraf-1.28 | — |
| telegraf-1.28 | affected | chainguard | telegraf-1.28 | — |
| telegraf-1.29 | affected | chainguard | telegraf-1.29 | — |
| telegraf-1.29 | affected | wolfi | telegraf-1.29 | — |
| trivy | affected | wolfi | trivy | — |
| trivy | affected | chainguard | trivy | — |
| up | affected | chainguard | up | — |
| up | affected | wolfi | up | — |
| zot | affected | chainguard | zot | — |
| zot | affected | wolfi | zot | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.