Google Security Advisories · December 2023 — Google Security Advisories
592 advisories 351 CVEs 21 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2023-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 21 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

MGASA-2023-0355

Open SourceExploitedCISA KEV listedCRITICAL2023-12-26

New chromium-browser-stable 120.0.6099.129 fixes bugs and vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

DEBIAN-CVE-2023-7024

Open SourceExploitedCISA KEV listedCRITICAL2023-12-21

DEBIAN-CVE-2023-7024

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-5585-1

Open SourceExploitedCISA KEV listed2023-12-21

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2023-7024

GoogleExploitedCISA KEV listed2023-12-20

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-7024

Upstream advisory

CVE-2023-7024

GoogleExploitedCISA KEV listedCRITICAL2023-12-20

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-7024

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-7024

Project ZeroExploitedCISA KEV listed2023-12-20

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-7024

Upstream advisory

ASB-A-300941008

GoogleExploitedCISA KEV listed2023-12-01

ASB-A-300941008

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-299649795

GoogleExploitedCISA KEV listed2023-12-01

ASB-A-299649795

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-266568298

GoogleExploitedCISA KEV listed2023-12-01

ASB-A-266568298

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

GO-2023-2402

Open SourceExploitedVulnCheck KEV listed2023-12-18

Man-in-the-middle attacker can compromise integrity of secure channel in golang.org/x/crypto

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
actions-runner-controller affected wolfi actions-runner-controller
actions-runner-controller affected chainguard actions-runner-controller
amass affected chainguard amass
amass affected wolfi amass
apko affected chainguard apko
apko affected wolfi apko
argo-workflows affected wolfi argo-workflows
argo-workflows affected chainguard argo-workflows
atlantis affected chainguard atlantis
atlantis affected wolfi atlantis
atlantis-fips affected chainguard atlantis-fips
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bom affected wolfi bom
bom affected chainguard bom
boring-registry affected chainguard boring-registry
boring-registry affected wolfi boring-registry
buf affected chainguard buf
buf affected wolfi buf
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
caddy affected chainguard caddy
caddy affected wolfi caddy
cadvisor affected chainguard cadvisor
cadvisor affected wolfi cadvisor
certificate-transparency affected chainguard certificate-transparency
certificate-transparency affected wolfi certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cfssl affected wolfi cfssl
cfssl affected chainguard cfssl
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
cloudflared affected wolfi cloudflared
cloudflared affected chainguard cloudflared
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
conftest affected chainguard conftest
conftest affected wolfi conftest
conftest-fips affected chainguard conftest-fips
cortex affected wolfi cortex
cortex affected chainguard cortex
cosign affected chainguard cosign
cosign affected wolfi cosign
cosign-fips affected chainguard cosign-fips
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-azure affected wolfi crossplane-provider-azure
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure-authorization affected wolfi crossplane-provider-azure-authorization
crossplane-provider-azure-authorization affected chainguard crossplane-provider-azure-authorization
crossplane-provider-azure-managedidentity affected wolfi crossplane-provider-azure-managedidentity
crossplane-provider-azure-managedidentity affected chainguard crossplane-provider-azure-managedidentity
crossplane-provider-azure-sql affected chainguard crossplane-provider-azure-sql
crossplane-provider-azure-sql affected wolfi crossplane-provider-azure-sql
crossplane-provider-azure-storage affected chainguard crossplane-provider-azure-storage
crossplane-provider-azure-storage affected wolfi crossplane-provider-azure-storage
crossplane-provider-family-azure affected chainguard crossplane-provider-family-azure
crossplane-provider-family-azure affected wolfi crossplane-provider-family-azure
dex affected wolfi dex
dex affected chainguard dex
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
docker-credential-acr-env affected chainguard docker-credential-acr-env
docker-credential-acr-env affected wolfi docker-credential-acr-env
dockerize affected chainguard dockerize
dockerize affected wolfi dockerize
dockerize-fips affected chainguard dockerize-fips
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
eksctl affected wolfi eksctl
eksctl affected chainguard eksctl
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
ferretdb affected chainguard ferretdb
ferretdb affected wolfi ferretdb
flux affected wolfi flux
flux affected chainguard flux
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
fq affected wolfi fq
fq affected chainguard fq
frp affected chainguard frp
frp affected wolfi frp
fulcio affected wolfi fulcio
fulcio affected chainguard fulcio
fulcio-fips affected chainguard fulcio-fips
gh affected wolfi gh
gh affected chainguard gh
git-lfs affected wolfi git-lfs
git-lfs affected chainguard git-lfs
gitness affected chainguard gitness
gitness affected wolfi gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
gomplate affected wolfi gomplate
gomplate affected chainguard gomplate
grpc-health-probe affected wolfi grpc-health-probe
grpc-health-probe affected chainguard grpc-health-probe
grype affected chainguard grype
grype affected wolfi grype
haproxy-ingress affected chainguard haproxy-ingress
haproxy-ingress affected wolfi haproxy-ingress
helm affected chainguard helm
helm affected wolfi helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
hugo affected chainguard hugo
hugo affected wolfi hugo
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
kaf affected wolfi kaf
kaf affected chainguard kaf
kiam affected chainguard kiam
ko affected wolfi ko
ko affected chainguard ko
ko-fips affected chainguard ko-fips
kots affected wolfi kots
kots affected chainguard kots
kubeflow affected wolfi kubeflow
kubeflow affected chainguard kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-oidc-proxy affected chainguard kube-oidc-proxy
kube-rbac-proxy affected wolfi kube-rbac-proxy
kube-rbac-proxy affected chainguard kube-rbac-proxy
kubernetes-1.27 affected wolfi kubernetes-1.27
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-event-exporter affected wolfi kubernetes-event-exporter
kubernetes-event-exporter affected chainguard kubernetes-event-exporter
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubewatch affected chainguard kubewatch
kubewatch affected wolfi kubewatch
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
libssh affected wolfi libssh
libssh affected chainguard libssh
libssh2 affected wolfi libssh2
libssh2 affected chainguard libssh2
local-path-provisioner affected wolfi local-path-provisioner
local-path-provisioner affected chainguard local-path-provisioner
melange affected chainguard melange
melange affected wolfi melange
memcached-exporter affected wolfi memcached-exporter
memcached-exporter affected chainguard memcached-exporter
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
mongo-tools affected wolfi mongo-tools
mongo-tools affected chainguard mongo-tools
nats affected wolfi nats
nats affected chainguard nats
nats-server affected chainguard nats-server
nats-server affected wolfi nats-server
nerdctl affected chainguard nerdctl
nerdctl affected wolfi nerdctl
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nri-kafka affected chainguard nri-kafka
nri-kafka affected wolfi nri-kafka
nri-mssql affected wolfi nri-mssql
nri-mssql affected chainguard nri-mssql
nsc affected wolfi nsc
nsc affected chainguard nsc
oauth2-proxy affected chainguard oauth2-proxy
oauth2-proxy affected wolfi oauth2-proxy
ollama affected chainguard ollama
ollama affected wolfi ollama
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter-fips affected chainguard prometheus-elasticsearch-exporter-fips
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter-0.37 affected chainguard prometheus-mongodb-exporter-0.37
prometheus-mongodb-exporter-fips affected chainguard prometheus-mongodb-exporter-fips
prometheus-mongodb-exporter-fips-0.37 affected chainguard prometheus-mongodb-exporter-fips-0.37
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter-1.4 affected chainguard prometheus-node-exporter-1.4
prometheus-node-exporter-1.5 affected chainguard prometheus-node-exporter-1.5
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-postgres-exporter-fips affected chainguard prometheus-postgres-exporter-fips
prometheus-pushgateway-1.4 affected chainguard prometheus-pushgateway-1.4
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
prometheus-pushgateway-fips-1.4 affected chainguard prometheus-pushgateway-fips-1.4
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter-fips affected chainguard prometheus-statsd-exporter-fips
pulumi affected chainguard pulumi
pulumi affected wolfi pulumi
rekor affected chainguard rekor
rekor affected wolfi rekor
rekor-fips affected chainguard rekor-fips
rqlite affected wolfi rqlite
rqlite affected chainguard rqlite
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
sigstore-scaffolding affected wolfi sigstore-scaffolding
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding-fips affected chainguard sigstore-scaffolding-fips
skopeo affected chainguard skopeo
skopeo affected wolfi skopeo
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
sops affected wolfi sops
sops affected chainguard sops
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
spire-server affected wolfi spire-server
spire-server affected chainguard spire-server
spire-server-fips affected chainguard spire-server-fips
src affected wolfi src
src affected chainguard src
src-fingerprint affected chainguard src-fingerprint
src-fingerprint affected wolfi src-fingerprint
step affected chainguard step
step affected wolfi step
step-ca affected chainguard step-ca
step-ca affected wolfi step-ca
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
temporal affected wolfi temporal
temporal affected chainguard temporal
temporal-fips affected chainguard temporal-fips
temporal-server affected chainguard temporal-server
temporal-server affected wolfi temporal-server
temporal-server-fips affected chainguard temporal-server-fips
temporal-ui-server affected wolfi temporal-ui-server
temporal-ui-server affected chainguard temporal-ui-server
temporal-ui-server-fips affected chainguard temporal-ui-server-fips
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-docs affected chainguard terraform-docs
terraform-docs affected wolfi terraform-docs
terraform-provider-aws affected chainguard terraform-provider-aws
terraform-provider-aws affected wolfi terraform-provider-aws
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
tigera-operator-fips-1.29 affected chainguard tigera-operator-fips-1.29
timestamp-authority-fips affected chainguard timestamp-authority-fips
tkn affected wolfi tkn
tkn affected chainguard tkn
trillian affected wolfi trillian
trillian affected chainguard trillian
trillian-fips affected chainguard trillian-fips
trivy affected chainguard trivy
trivy affected wolfi trivy
up affected chainguard up
up affected wolfi up
vault-csi-provider affected chainguard vault-csi-provider
vault-k8s affected wolfi vault-k8s
vault-k8s affected chainguard vault-k8s
vault-k8s-fips affected chainguard vault-k8s-fips
vexctl affected wolfi vexctl
vexctl affected chainguard vexctl
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
weaviate affected wolfi weaviate
weaviate affected chainguard weaviate
wireguard-go affected wolfi wireguard-go
wireguard-go affected chainguard wireguard-go
x/crypto affected golang.org golang.org/x/crypto
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

GHSA-45x7-px36-x8w8

Open SourceExploitedVulnCheck KEV listedMEDIUM2023-12-18

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Affected products

ProductStatusVendorPackageEcosystem
paramiko affected PyPI paramiko
russh affected crates.io russh
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

GHSA-45x7-px36-x8w8

Open SourceExploitedVulnCheck KEV listedMEDIUM2023-12-18

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller affected wolfi actions-runner-controller
amass affected chainguard amass
amass affected wolfi amass
apko affected chainguard apko
apko affected wolfi apko
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.8 affected wolfi argo-cd-2.8
argo-cd-2.9 affected wolfi argo-cd-2.9
argo-cd-2.9 affected chainguard argo-cd-2.9
argo-workflows affected chainguard argo-workflows
argo-workflows affected wolfi argo-workflows
atlantis affected chainguard atlantis
atlantis affected wolfi atlantis
atlantis-fips affected chainguard atlantis-fips
azure-aad-pod-identity-mic affected chainguard azure-aad-pod-identity-mic
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
bank-vaults-fips affected chainguard bank-vaults-fips
bom affected wolfi bom
bom affected chainguard bom
boring-registry affected chainguard boring-registry
boring-registry affected wolfi boring-registry
buf affected wolfi buf
buf affected chainguard buf
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
caddy affected chainguard caddy
caddy affected wolfi caddy
cadvisor affected chainguard cadvisor
cadvisor affected wolfi cadvisor
calico affected wolfi calico
calico affected chainguard calico
calico-fips affected chainguard calico-fips
calico-fips-3.25 affected chainguard calico-fips-3.25
certificate-transparency affected wolfi certificate-transparency
certificate-transparency affected chainguard certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cert-manager-1.11 affected wolfi cert-manager-1.11
cert-manager-1.11 affected chainguard cert-manager-1.11
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.13 affected wolfi cert-manager-1.13
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-fips-1.12 affected chainguard cert-manager-fips-1.12
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
cfssl affected wolfi cfssl
cfssl affected chainguard cfssl
cilium-cli affected wolfi cilium-cli
cilium-cli affected chainguard cilium-cli
cloudflared affected wolfi cloudflared
cloudflared affected chainguard cloudflared
cloud-sql-proxy affected chainguard cloud-sql-proxy
cloud-sql-proxy affected wolfi cloud-sql-proxy
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
cluster-autoscaler-1.25 affected wolfi cluster-autoscaler-1.25
cluster-autoscaler-1.25 affected chainguard cluster-autoscaler-1.25
cluster-autoscaler-fips-1.25 affected chainguard cluster-autoscaler-fips-1.25
cluster-autoscaler-fips-1.26 affected chainguard cluster-autoscaler-fips-1.26
cluster-autoscaler-fips-1.27 affected chainguard cluster-autoscaler-fips-1.27
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
conftest affected wolfi conftest
conftest affected chainguard conftest
conftest-fips affected chainguard conftest-fips
consul-1.15 affected chainguard consul-1.15
consul-1.15 affected wolfi consul-1.15
consul-1.16 affected wolfi consul-1.16
consul-1.16 affected chainguard consul-1.16
containerd affected chainguard containerd
containerd affected wolfi containerd
coredns affected chainguard coredns
coredns affected wolfi coredns
cortex affected wolfi cortex
cortex affected chainguard cortex
cosign affected chainguard cosign
cosign affected wolfi cosign
cosign-fips affected wolfi cosign-fips
cosign-fips affected chainguard cosign-fips
crossplane affected chainguard crossplane
crossplane affected wolfi crossplane
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-azure affected chainguard crossplane-provider-azure
crossplane-provider-azure affected wolfi crossplane-provider-azure
crossplane-provider-azure-authorization affected chainguard crossplane-provider-azure-authorization
crossplane-provider-azure-authorization affected wolfi crossplane-provider-azure-authorization
crossplane-provider-azure-managedidentity affected wolfi crossplane-provider-azure-managedidentity
crossplane-provider-azure-managedidentity affected chainguard crossplane-provider-azure-managedidentity
crossplane-provider-azure-sql affected wolfi crossplane-provider-azure-sql
crossplane-provider-azure-sql affected chainguard crossplane-provider-azure-sql
crossplane-provider-azure-storage affected wolfi crossplane-provider-azure-storage
crossplane-provider-azure-storage affected chainguard crossplane-provider-azure-storage
crossplane-provider-family-azure affected wolfi crossplane-provider-family-azure
crossplane-provider-family-azure affected chainguard crossplane-provider-family-azure
dex affected chainguard dex
dex affected wolfi dex
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
docker-credential-acr-env affected chainguard docker-credential-acr-env
docker-credential-acr-env affected wolfi docker-credential-acr-env
dockerize affected chainguard dockerize
dockerize affected wolfi dockerize
dockerize-fips affected chainguard dockerize-fips
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
external-dns affected chainguard external-dns
external-dns affected wolfi external-dns
external-dns-0.13.5 affected chainguard external-dns-0.13.5
external-dns-fips affected chainguard external-dns-fips
external-secrets-0.7 affected chainguard external-secrets-0.7
external-secrets-operator affected chainguard external-secrets-operator
external-secrets-operator affected wolfi external-secrets-operator
falco affected chainguard falco
falco affected wolfi falco
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
ferretdb affected chainguard ferretdb
ferretdb affected wolfi ferretdb
flux affected chainguard flux
flux affected wolfi flux
flux-0 affected chainguard flux-0
flux-0.37 affected chainguard flux-0.37
flux-2.0 affected chainguard flux-2.0
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller-0 affected chainguard flux-helm-controller-0
flux-helm-controller-0.37 affected chainguard flux-helm-controller-0.37
flux-helm-controller-2.0 affected chainguard flux-helm-controller-2.0
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-image-reflector-controller-0 affected chainguard flux-image-reflector-controller-0
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller-0 affected chainguard flux-kustomize-controller-0
flux-kustomize-controller-0.37 affected chainguard flux-kustomize-controller-0.37
flux-kustomize-controller-2.0 affected chainguard flux-kustomize-controller-2.0
flux-notification-controller-0 affected chainguard flux-notification-controller-0
flux-notification-controller-0.37 affected chainguard flux-notification-controller-0.37
flux-notification-controller-2.0 affected chainguard flux-notification-controller-2.0
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller-0 affected chainguard flux-source-controller-0
flux-source-controller-0.37 affected chainguard flux-source-controller-0.37
flux-source-controller-2.0 affected chainguard flux-source-controller-2.0
fq affected chainguard fq
fq affected wolfi fq
frp affected wolfi frp
frp affected chainguard frp
fulcio affected wolfi fulcio
fulcio affected chainguard fulcio
fulcio-fips affected chainguard fulcio-fips
gatekeeper-3.12 affected wolfi gatekeeper-3.12
gatekeeper-3.12 affected chainguard gatekeeper-3.12
gatekeeper-3.13 affected wolfi gatekeeper-3.13
gatekeeper-3.13 affected chainguard gatekeeper-3.13
gatekeeper-3.14 affected wolfi gatekeeper-3.14
gatekeeper-3.14 affected chainguard gatekeeper-3.14
gatekeeper-fips-3.13 affected chainguard gatekeeper-fips-3.13
gatekeeper-fips-3.14 affected chainguard gatekeeper-fips-3.14
gh affected wolfi gh
gh affected chainguard gh
gitlab-kas affected chainguard gitlab-kas
gitlab-kas affected wolfi gitlab-kas
gitlab-pages affected chainguard gitlab-pages
gitlab-pages affected wolfi gitlab-pages
gitlab-runner affected wolfi gitlab-runner
gitlab-runner affected chainguard gitlab-runner
git-lfs affected wolfi git-lfs
git-lfs affected chainguard git-lfs
gitness affected wolfi gitness
gitness affected chainguard gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
golang.org/x/crypto affected Go golang.org/x/crypto
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
gomplate affected chainguard gomplate
gomplate affected wolfi gomplate
goreleaser-1.18 affected chainguard goreleaser-1.18
goreleaser-1.18 affected wolfi goreleaser-1.18
gpu-operator affected chainguard gpu-operator
grafana affected chainguard grafana
grafana affected wolfi grafana
grafana-7 affected chainguard grafana-7
grafana-9.3 affected chainguard grafana-9.3
grpc-health-probe affected chainguard grpc-health-probe
grpc-health-probe affected wolfi grpc-health-probe
grype affected chainguard grype
grype affected wolfi grype
haproxy-ingress affected wolfi haproxy-ingress
haproxy-ingress affected chainguard haproxy-ingress
helm affected wolfi helm
helm affected chainguard helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
hugo affected wolfi hugo
hugo affected chainguard hugo
influxd affected wolfi influxd
influxd affected chainguard influxd
ipfs affected chainguard ipfs
ipfs affected wolfi ipfs
istio-cni-1.19 affected wolfi istio-cni-1.19
istio-cni-1.19 affected chainguard istio-cni-1.19
istio-cni-fips-1.19 affected chainguard istio-cni-fips-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-fips-1.19 affected chainguard istio-operator-fips-1.19
istio-pilot-agent-1.18 affected chainguard istio-pilot-agent-1.18
istio-pilot-agent-1.18 affected wolfi istio-pilot-agent-1.18
istio-pilot-agent-1.19 affected wolfi istio-pilot-agent-1.19
istio-pilot-agent-1.19 affected chainguard istio-pilot-agent-1.19
istio-pilot-agent-1.20 affected chainguard istio-pilot-agent-1.20
istio-pilot-agent-1.20 affected wolfi istio-pilot-agent-1.20
istio-pilot-agent-fips-1.19 affected chainguard istio-pilot-agent-fips-1.19
istio-pilot-discovery-1.18 affected wolfi istio-pilot-discovery-1.18
istio-pilot-discovery-1.18 affected chainguard istio-pilot-discovery-1.18
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
istio-pilot-discovery-1.20 affected wolfi istio-pilot-discovery-1.20
istio-pilot-discovery-1.20 affected chainguard istio-pilot-discovery-1.20
istio-pilot-discovery-fips-1.19 affected chainguard istio-pilot-discovery-fips-1.19
k3d affected wolfi k3d
k3d affected chainguard k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
kaf affected wolfi kaf
kaf affected chainguard kaf
karpenter-0.23 affected chainguard karpenter-0.23
keda-2.8 affected chainguard keda-2.8
keda-2.9 affected chainguard keda-2.9
kiam affected chainguard kiam
ko affected wolfi ko
ko affected chainguard ko
ko-fips affected wolfi ko-fips
ko-fips affected chainguard ko-fips
kots affected chainguard kots
kots affected wolfi kots
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-pipelines affected chainguard kubeflow-pipelines
kubeflow-pipelines affected wolfi kubeflow-pipelines
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-fluentd-operator affected chainguard kube-fluentd-operator
kube-logging-logging-operator-3.17 affected chainguard kube-logging-logging-operator-3.17
kube-oidc-proxy affected chainguard kube-oidc-proxy
kube-rbac-proxy affected wolfi kube-rbac-proxy
kube-rbac-proxy affected chainguard kube-rbac-proxy
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dns-node-cache-1.17 affected chainguard kubernetes-dns-node-cache-1.17
kubernetes-event-exporter affected wolfi kubernetes-event-exporter
kubernetes-event-exporter affected chainguard kubernetes-event-exporter
kubernetes-fips-1.27 affected chainguard kubernetes-fips-1.27
kubernetes-fips-1.28 affected chainguard kubernetes-fips-1.28
kubernetes-fips-1.29 affected chainguard kubernetes-fips-1.29
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kube-state-metrics-2.2.0 affected chainguard kube-state-metrics-2.2.0
kube-state-metrics-2.6 affected chainguard kube-state-metrics-2.6
kube-state-metrics-fips affected chainguard kube-state-metrics-fips
kubewatch affected wolfi kubewatch
kubewatch affected chainguard kubewatch
kyverno affected chainguard kyverno
kyverno affected wolfi kyverno
kyverno-policy-reporter affected chainguard kyverno-policy-reporter
kyverno-policy-reporter affected wolfi kyverno-policy-reporter
libssh affected chainguard libssh
libssh affected wolfi libssh
libssh2 affected chainguard libssh2
libssh2 affected wolfi libssh2
local-path-provisioner affected chainguard local-path-provisioner
local-path-provisioner affected wolfi local-path-provisioner
loki affected chainguard loki
loki affected wolfi loki
melange affected wolfi melange
melange affected chainguard melange
memcached-exporter affected wolfi memcached-exporter
memcached-exporter affected chainguard memcached-exporter
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
mongo-tools affected wolfi mongo-tools
mongo-tools affected chainguard mongo-tools
nats affected wolfi nats
nats affected chainguard nats
nats-server affected wolfi nats-server
nats-server affected chainguard nats-server
nerdctl affected chainguard nerdctl
nerdctl affected wolfi nerdctl
nfs-subdir-external-provisioner affected wolfi nfs-subdir-external-provisioner
nfs-subdir-external-provisioner affected chainguard nfs-subdir-external-provisioner
nfs-subdir-external-provisioner-fips affected chainguard nfs-subdir-external-provisioner-fips
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
node-problem-detector-0.8 affected wolfi node-problem-detector-0.8
nri-kafka affected wolfi nri-kafka
nri-kafka affected chainguard nri-kafka
nri-mssql affected wolfi nri-mssql
nri-mssql affected chainguard nri-mssql
nsc affected chainguard nsc
nsc affected wolfi nsc
oauth2-proxy affected wolfi oauth2-proxy
oauth2-proxy affected chainguard oauth2-proxy
ollama affected wolfi ollama
ollama affected chainguard ollama
opentofu affected wolfi opentofu
opentofu affected chainguard opentofu
opentofu-1.6 affected chainguard opentofu-1.6
paramiko affected PyPI paramiko
paramiko affected PyPI paramiko
prometheus affected wolfi prometheus
prometheus affected chainguard prometheus
prometheus-2.38 affected chainguard prometheus-2.38
prometheus-adapter affected chainguard prometheus-adapter
prometheus-adapter affected wolfi prometheus-adapter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-adapter-fips affected chainguard prometheus-adapter-fips
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-alertmanager affected wolfi prometheus-alertmanager
prometheus-alertmanager affected chainguard prometheus-alertmanager
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-blackbox-exporter affected wolfi prometheus-blackbox-exporter
prometheus-blackbox-exporter affected chainguard prometheus-blackbox-exporter
prometheus-elasticsearch-exporter-fips affected chainguard prometheus-elasticsearch-exporter-fips
prometheus-fips affected chainguard prometheus-fips
prometheus-mongodb-exporter affected wolfi prometheus-mongodb-exporter
prometheus-mongodb-exporter affected chainguard prometheus-mongodb-exporter
prometheus-mongodb-exporter-0.37 affected chainguard prometheus-mongodb-exporter-0.37
prometheus-mongodb-exporter-fips affected chainguard prometheus-mongodb-exporter-fips
prometheus-mongodb-exporter-fips-0.37 affected chainguard prometheus-mongodb-exporter-fips-0.37
prometheus-mysqld-exporter affected chainguard prometheus-mysqld-exporter
prometheus-mysqld-exporter affected wolfi prometheus-mysqld-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-nats-exporter affected wolfi prometheus-nats-exporter
prometheus-node-exporter affected chainguard prometheus-node-exporter
prometheus-node-exporter affected wolfi prometheus-node-exporter
prometheus-node-exporter-1.4 affected chainguard prometheus-node-exporter-1.4
prometheus-node-exporter-1.5 affected chainguard prometheus-node-exporter-1.5
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-postgres-exporter affected wolfi prometheus-postgres-exporter
prometheus-postgres-exporter affected chainguard prometheus-postgres-exporter
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
prometheus-postgres-exporter-0.13 affected chainguard prometheus-postgres-exporter-0.13
prometheus-postgres-exporter-fips affected chainguard prometheus-postgres-exporter-fips
prometheus-pushgateway-1.4 affected chainguard prometheus-pushgateway-1.4
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
prometheus-pushgateway-fips-1.4 affected chainguard prometheus-pushgateway-fips-1.4
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter affected chainguard prometheus-statsd-exporter
prometheus-statsd-exporter affected wolfi prometheus-statsd-exporter
prometheus-statsd-exporter-fips affected chainguard prometheus-statsd-exporter-fips
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
rekor affected wolfi rekor
rekor affected chainguard rekor
rekor-fips affected chainguard rekor-fips
rqlite affected wolfi rqlite
rqlite affected chainguard rqlite
russh affected crates.io russh
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
secrets-store-csi-driver affected chainguard secrets-store-csi-driver
secrets-store-csi-driver affected wolfi secrets-store-csi-driver
secrets-store-csi-driver-provider-azure affected chainguard secrets-store-csi-driver-provider-azure
secrets-store-csi-driver-provider-azure affected wolfi secrets-store-csi-driver-provider-azure
sigstore-scaffolding affected chainguard sigstore-scaffolding
sigstore-scaffolding affected wolfi sigstore-scaffolding
sigstore-scaffolding-fips affected chainguard sigstore-scaffolding-fips
skopeo affected chainguard skopeo
skopeo affected wolfi skopeo
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
sops affected chainguard sops
sops affected wolfi sops
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
spire-server affected wolfi spire-server
spire-server affected chainguard spire-server
spire-server-fips affected chainguard spire-server-fips
src affected wolfi src
src affected chainguard src
src-fingerprint affected wolfi src-fingerprint
src-fingerprint affected chainguard src-fingerprint
step affected wolfi step
step affected chainguard step
step-ca affected chainguard step-ca
step-ca affected wolfi step-ca
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.26 affected wolfi telegraf-1.26
telegraf-1.27 affected chainguard telegraf-1.27
telegraf-1.27 affected wolfi telegraf-1.27
telegraf-1.28 affected chainguard telegraf-1.28
telegraf-1.28 affected wolfi telegraf-1.28
telegraf-1.29 affected wolfi telegraf-1.29
telegraf-1.29 affected chainguard telegraf-1.29
temporal affected wolfi temporal
temporal affected chainguard temporal
temporal-fips affected chainguard temporal-fips
temporal-server affected wolfi temporal-server
temporal-server affected chainguard temporal-server
temporal-server-fips affected chainguard temporal-server-fips
temporal-ui-server affected chainguard temporal-ui-server
temporal-ui-server affected wolfi temporal-ui-server
temporal-ui-server-fips affected chainguard temporal-ui-server-fips
terraform affected chainguard terraform
terraform affected wolfi terraform
terraform-docs affected wolfi terraform-docs
terraform-docs affected chainguard terraform-docs
terraform-fips-1.5 affected chainguard terraform-fips-1.5
terraform-provider-aws affected wolfi terraform-provider-aws
terraform-provider-aws affected chainguard terraform-provider-aws
terraform-provider-azurerm affected chainguard terraform-provider-azurerm
terraform-provider-azurerm affected wolfi terraform-provider-azurerm
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
terragrunt affected wolfi terragrunt
terragrunt affected chainguard terragrunt
thanos-0.31 affected wolfi thanos-0.31
thanos-0.31 affected chainguard thanos-0.31
thanos-0.32 affected chainguard thanos-0.32
thanos-0.32 affected wolfi thanos-0.32
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
tigera-operator-1.30 affected wolfi tigera-operator-1.30
tigera-operator-1.30 affected chainguard tigera-operator-1.30
tigera-operator-1.31 affected wolfi tigera-operator-1.31
tigera-operator-1.31 affected chainguard tigera-operator-1.31
tigera-operator-fips affected chainguard tigera-operator-fips
tigera-operator-fips-1.29 affected chainguard tigera-operator-fips-1.29
tigera-operator-fips-1.32 affected chainguard tigera-operator-fips-1.32
timestamp-authority-fips affected chainguard timestamp-authority-fips
tkn affected wolfi tkn
tkn affected chainguard tkn
traefik affected chainguard traefik
traefik affected wolfi traefik
trillian affected wolfi trillian
trillian affected chainguard trillian
trillian-fips affected chainguard trillian-fips
trivy affected wolfi trivy
trivy affected chainguard trivy
up affected wolfi up
up affected chainguard up
vault-1.13 affected wolfi vault-1.13
vault-1.13 affected chainguard vault-1.13
vault-csi-provider affected chainguard vault-csi-provider
vault-csi-provider affected wolfi vault-csi-provider
vault-fips-1.14 affected chainguard vault-fips-1.14
vault-k8s affected wolfi vault-k8s
vault-k8s affected chainguard vault-k8s
vault-k8s-fips affected chainguard vault-k8s-fips
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
weaviate affected wolfi weaviate
weaviate affected chainguard weaviate
wireguard-go affected chainguard wireguard-go
wireguard-go affected wolfi wireguard-go
x/crypto affected golang.org golang.org/x/crypto
x/crypto affected golang.org golang.org/x/crypto
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

AZL-32221

Open SourceExploitedVulnCheck KEV listedMEDIUM2023-12-18

CVE-2023-48795 affecting package kubernetes for versions less than 1.28.4-4

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:2 kubernetes
Upstream advisory

AZL-34901

Open SourceExploitedVulnCheck KEV listedMEDIUM2023-12-18

CVE-2023-48795 affecting package kubernetes for versions less than 1.30.1-1

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:3 kubernetes
Upstream advisory

DEBIAN-CVE-2023-48795

Open SourceExploitedVulnCheck KEV listedMEDIUM2023-12-18

DEBIAN-CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
dropbear affected Debian:13 dropbear
dropbear affected Debian:11 dropbear
dropbear affected Debian:12 dropbear
dropbear affected Debian:14 dropbear
erlang affected Debian:12 erlang
erlang affected Debian:14 erlang
erlang affected Debian:11 erlang
erlang affected Debian:13 erlang
filezilla affected Debian:12 filezilla
filezilla affected Debian:14 filezilla
filezilla affected Debian:11 filezilla
filezilla affected Debian:13 filezilla
golang-go.crypto affected Debian:12 golang-go.crypto
golang-go.crypto affected Debian:14 golang-go.crypto
golang-go.crypto affected Debian:11 golang-go.crypto
golang-go.crypto affected Debian:13 golang-go.crypto
libssh affected Debian:13 libssh
libssh affected Debian:12 libssh
libssh affected Debian:11 libssh
libssh affected Debian:14 libssh
libssh2 affected Debian:14 libssh2
libssh2 affected Debian:13 libssh2
openssh affected Debian:13 openssh
openssh affected Debian:14 openssh
openssh affected Debian:11 openssh
openssh affected Debian:12 openssh
paramiko affected Debian:14 paramiko
paramiko affected Debian:11 paramiko
paramiko affected Debian:12 paramiko
paramiko affected Debian:13 paramiko
php-phpseclib affected Debian:14 php-phpseclib
php-phpseclib affected Debian:13 php-phpseclib
php-phpseclib affected Debian:11 php-phpseclib
php-phpseclib affected Debian:12 php-phpseclib
php-phpseclib3 affected Debian:14 php-phpseclib3
php-phpseclib3 affected Debian:12 php-phpseclib3
php-phpseclib3 affected Debian:13 php-phpseclib3
phpseclib affected Debian:11 phpseclib
phpseclib affected Debian:12 phpseclib
phpseclib affected Debian:13 phpseclib
proftpd-dfsg affected Debian:13 proftpd-dfsg
proftpd-dfsg affected Debian:14 proftpd-dfsg
proftpd-dfsg affected Debian:11 proftpd-dfsg
proftpd-dfsg affected Debian:12 proftpd-dfsg
proftpd-mod-proxy affected Debian:14 proftpd-mod-proxy
proftpd-mod-proxy affected Debian:13 proftpd-mod-proxy
proftpd-mod-proxy affected Debian:12 proftpd-mod-proxy
proftpd-mod-proxy affected Debian:11 proftpd-mod-proxy
putty affected Debian:14 putty
putty affected Debian:11 putty
putty affected Debian:12 putty
putty affected Debian:13 putty
python-asyncssh affected Debian:14 python-asyncssh
python-asyncssh affected Debian:11 python-asyncssh
python-asyncssh affected Debian:12 python-asyncssh
python-asyncssh affected Debian:13 python-asyncssh
tinyssh affected Debian:14 tinyssh
tinyssh affected Debian:13 tinyssh
tinyssh affected Debian:11 tinyssh
tinyssh affected Debian:12 tinyssh
trilead-ssh2 affected Debian:14 trilead-ssh2
trilead-ssh2 affected Debian:11 trilead-ssh2
trilead-ssh2 affected Debian:12 trilead-ssh2
trilead-ssh2 affected Debian:13 trilead-ssh2
Upstream advisory

CVE-2023-48795

Open SourceExploitedVulnCheck KEV listedMEDIUM2023-12-18

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

CVEs:CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
paramiko affected PyPI paramiko
russh affected crates.io russh
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CVE-2023-48795

Open SourceExploitedVulnCheck KEV listedMEDIUM2023-12-18

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

CVEs:CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
paramiko affected PyPI paramiko
russh affected crates.io russh
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

CVE-2023-48795

GoogleExploitedVulnCheck KEV listedMEDIUM2023-12-18

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and...

CVEs:CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
advanced_cluster_security affected redhat
asyncssh affected asyncssh_project
ceph_storage affected redhat
cert-manager_operator_for_red_hat_openshift affected redhat
crushftp affected crushftp
crypto affected golang
cyclone_ssh affected oryx-embedded
debian_linux affected debian
discovery affected redhat
dropbear_ssh affected dropbear_ssh_project
enterprise_linux affected redhat
erlang\/otp affected erlang
fedora affected fedoraproject
filezilla_client affected filezilla-project
freebsd affected freebsd
jboss_enterprise_application_platform affected redhat
jsch affected matez
keycloak affected redhat
kitty affected 9bis
lanconfig affected lancom-systems
lcos affected lancom-systems
lcos_fx affected lancom-systems
lcos_lx affected lancom-systems
lcos_sx affected lancom-systems
libssh affected libssh
libssh2 affected libssh2
macos affected apple
maverick_synergy_java_ssh_api affected jadaptive
net-ssh affected net-ssh
nova affected panic
openshift_api_for_data_protection affected redhat
openshift_container_platform affected redhat
openshift_data_foundation affected redhat
openshift_developer_tools_and_services affected redhat
openshift_dev_spaces affected redhat
openshift_gitops affected redhat
openshift_pipelines affected redhat
openshift_serverless affected redhat
openshift_virtualization affected redhat
openssh affected openbsd
openstack_platform affected redhat
paramiko affected paramiko
pfsense_ce affected netgate
pfsense_plus affected netgate
pkixssh affected roumenpetrov
proftpd affected proftpd
putty affected putty
russh affected russh_project
securecrt affected vandyke
security affected gentoo
sftp_gateway_firmware affected thorntech
sftpgo affected sftpgo_project
single_sign-on affected redhat
ssh affected ssh
ssh2 affected ssh2_project
ssh2 affected trilead
ssh_client affected bitvise
sshd affected apache
sshj affected apache
sshlib affected connectbot
ssh_server affected bitvise
storage affected redhat
tera_term affected tera_term_project
thrussh affected crates
tinyssh affected tinyssh
transmit_5 affected panic
winscp affected winscp
xshell_7 affected netsarang
Upstream advisory

CVE-2023-40088

Open SourceExploitedVulnCheck KEV listedHIGH2023-12-04

In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. ...

CVEs:CVE-2023-40088

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2023-6702

Open SourceActive exploitation (sightings)HIGH2023-12-14

DEBIAN-CVE-2023-6702

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DSA-5577-1

Open SourceActive exploitation (sightings)2023-12-13

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2023-6702

GoogleActive exploitation (sightings)2023-12-12

Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6702

Upstream advisory

CVE-2023-6702

Open SourceActive exploitation (sightings)HIGH2023-12-12

Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6702

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
edge_chromium affected microsoft
fedora affected fedoraproject
Upstream advisory

CVE-2023-36880

Open SourceActive exploitation (sightings)HIGH2023-12-07

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVEs:CVE-2023-36880

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DSA-5573-1

Open SourceActive exploitation (sightings)2023-12-09

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2023-6512

Open SourceActive exploitation (sightings)MEDIUM2023-12-06

DEBIAN-CVE-2023-6512

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6512

GoogleActive exploitation (sightings)MEDIUM2023-12-05

Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-6512

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-6512

GoogleActive exploitation (sightings)2023-12-05

Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-6512

Upstream advisory

DEBIAN-CVE-2023-6508

Open SourceActive exploitation (sightings)CRITICAL2023-12-06

DEBIAN-CVE-2023-6508

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6508

GoogleActive exploitation (sightings)CRITICAL2023-12-05

Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6508

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2023-6508

GoogleActive exploitation (sightings)2023-12-05

Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6508

Upstream advisory

DEBIAN-CVE-2023-6510

Open SourceActive exploitation (sightings)CRITICAL2023-12-06

DEBIAN-CVE-2023-6510

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6510

GoogleActive exploitation (sightings)2023-12-05

Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)

CVEs:CVE-2023-6510

Upstream advisory

CVE-2023-6510

GoogleActive exploitation (sightings)CRITICAL2023-12-05

Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity:...

CVEs:CVE-2023-6510

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-6509

Open SourceActive exploitation (sightings)CRITICAL2023-12-06

DEBIAN-CVE-2023-6509

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6509

GoogleActive exploitation (sightings)2023-12-05

Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)

CVEs:CVE-2023-6509

Upstream advisory

CVE-2023-6509

GoogleActive exploitation (sightings)CRITICAL2023-12-05

Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security sever...

CVEs:CVE-2023-6509

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-6511

Open SourceActive exploitation (sightings)MEDIUM2023-12-06

DEBIAN-CVE-2023-6511

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6511

GoogleActive exploitation (sightings)2023-12-05

Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-6511

Upstream advisory

CVE-2023-6511

GoogleActive exploitation (sightings)MEDIUM2023-12-05

Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2023-6511

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2023-6705

Open SourceActive exploitation (sightings)CRITICAL2023-12-14

DEBIAN-CVE-2023-6705

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2023-6705

GoogleActive exploitation (sightings)CRITICAL2023-12-12

Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6705

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-6704

Open SourceActive exploitation (sightings)CRITICAL2023-12-14

DEBIAN-CVE-2023-6704

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
libavif affected Debian:13 libavif
libavif affected Debian:14 libavif
Upstream advisory

CVE-2023-6704

GoogleActive exploitation (sightings)CRITICAL2023-12-12

Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted image file. (Chromium security severity: High)

CVEs:CVE-2023-6704

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-6707

Open SourceActive exploitation (sightings)CRITICAL2023-12-14

DEBIAN-CVE-2023-6707

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2023-6707

GoogleActive exploitation (sightings)CRITICAL2023-12-12

Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2023-6707

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2023-6703

Open SourceActive exploitation (sightings)CRITICAL2023-12-14

DEBIAN-CVE-2023-6703

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2023-6706

Open SourceActive exploitation (sightings)CRITICAL2023-12-14

DEBIAN-CVE-2023-6706

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2023-6703

GoogleActive exploitation (sightings)CRITICAL2023-12-12

Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6703

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-6706

GoogleActive exploitation (sightings)CRITICAL2023-12-12

Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-6706

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-47548

GoogleActive exploitation (sightings)MEDIUM2023-12-07

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Goog...

CVEs:CVE-2023-47548

Affected products

ProductStatusVendorPackageEcosystem
integrate_google_drive affected softlabbd
Upstream advisory

CVE-2023-6181

GoogleActive exploitation (sightings)CRITICAL2023-12-11

An oversight in BCB handling of reboot reason that allows for persistent code execution

CVEs:CVE-2023-6181

Affected products

ProductStatusVendorPackageEcosystem
chromecast_firmware affected google
Upstream advisory

CVE-2023-51373

GoogleActive exploitation (sightings)CRITICAL2023-12-29

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ian Kennerley Google Photos Gallery with Shortcodes allows Reflected XSS.This issue affects Google Photos Gallery with Shortcodes: from n/a through 4....

CVEs:CVE-2023-51373

Affected products

ProductStatusVendorPackageEcosystem
google_photos_gallery_with_shortcodes affected nakunakifi
Upstream advisory

CVE-2024-3173

GoogleActive exploitation (sightings)CRITICAL2023-12-05

Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

CVEs:CVE-2024-3173

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-3173

GoogleActive exploitation (sightings)2023-12-05

Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

CVEs:CVE-2024-3173

Upstream advisory

GHSA-4g6q-77j7-vvjc

GoogleActive exploitation (sightings)MEDIUM2023-12-04

Logging of the firestore key within nodejs-firestore

Affected products

ProductStatusVendorPackageEcosystem
firestore affected google-cloud @google-cloud/firestore
Upstream advisory

GHSA-4g6q-77j7-vvjc

GoogleActive exploitation (sightings)MEDIUM2023-12-04

Logging of the firestore key within nodejs-firestore

Affected products

ProductStatusVendorPackageEcosystem
firestore affected google-cloud @google-cloud/firestore
Upstream advisory

CVE-2023-6460

GoogleActive exploitation (sightings)MEDIUM2023-12-04

Logging of the firestore key within nodejs-firestore

CVEs:CVE-2023-6460

Affected products

ProductStatusVendorPackageEcosystem
firestore affected google-cloud @google-cloud/firestore
Upstream advisory

CVE-2023-6460

GoogleActive exploitation (sightings)MEDIUM2023-12-04

Logging of the firestore key within nodejs-firestore

CVEs:CVE-2023-6460

Affected products

ProductStatusVendorPackageEcosystem
firestore affected google-cloud @google-cloud/firestore
Upstream advisory

CVE-2023-6460

GoogleActive exploitation (sightings)MEDIUM2023-12-04

A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We reco...

CVEs:CVE-2023-6460

Affected products

ProductStatusVendorPackageEcosystem
cloud_firestore affected google
Upstream advisory

CVE-2023-32860

Open SourceActive exploitation (sightings)HIGH2023-12-04

In display, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929788; Is...

CVEs:CVE-2023-32860

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32859

Open SourceActive exploitation (sightings)HIGH2023-12-04

In meta, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08000473; Issue...

CVEs:CVE-2023-32859

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32870

Open SourceActive exploitation (sightings)MEDIUM2023-12-04

In display drm, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363740; Iss...

CVEs:CVE-2023-32870

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32869

Open SourceActive exploitation (sightings)HIGH2023-12-04

In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363632; Is...

CVEs:CVE-2023-32869

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32868

Open SourceActive exploitation (sightings)HIGH2023-12-04

In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363632; Is...

CVEs:CVE-2023-32868

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32867

Open SourceActive exploitation (sightings)HIGH2023-12-04

In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560793; Is...

CVEs:CVE-2023-32867

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32866

Open SourceActive exploitation (sightings)HIGH2023-12-04

In mmp, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342152; Issue ID:...

CVEs:CVE-2023-32866

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32865

Open SourceActive exploitation (sightings)HIGH2023-12-04

In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363456;...

CVEs:CVE-2023-32865

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32864

Open SourceActive exploitation (sightings)HIGH2023-12-04

In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292187;...

CVEs:CVE-2023-32864

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32863

Open SourceActive exploitation (sightings)MEDIUM2023-12-04

In display drm, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326314; Iss...

CVEs:CVE-2023-32863

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32862

Open SourceActive exploitation (sightings)MEDIUM2023-12-04

In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388762; Issu...

CVEs:CVE-2023-32862

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32861

Open SourceActive exploitation (sightings)MEDIUM2023-12-04

In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08059081; Issu...

CVEs:CVE-2023-32861

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32854

Open SourceActive exploitation (sightings)HIGH2023-12-04

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08240132; Issue ID: ...

CVEs:CVE-2023-32854

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32853

Open SourceActive exploitation (sightings)HIGH2023-12-04

In rpmb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648764; Issue ID:...

CVEs:CVE-2023-32853

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32857

Open SourceActive exploitation (sightings)MEDIUM2023-12-04

In display, there is a possible out of bounds read due to an incorrect status check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issue...

CVEs:CVE-2023-32857

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32856

Open SourceActive exploitation (sightings)MEDIUM2023-12-04

In display, there is a possible out of bounds read due to an incorrect status check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issue...

CVEs:CVE-2023-32856

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32852

Open SourceActive exploitation (sightings)MEDIUM2023-12-04

In cameraisp, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07670971;...

CVEs:CVE-2023-32852

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32858

Open SourceActive exploitation (sightings)MEDIUM2023-12-04

In GZ, there is a possible information disclosure due to a missing data erasing. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07806008; Issue ID:...

CVEs:CVE-2023-32858

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32855

Open SourceActive exploitation (sightings)MEDIUM2023-12-04

In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Is...

CVEs:CVE-2023-32855

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
yocto affected linuxfoundation
Upstream advisory

CVE-2023-32849

Open SourceActive exploitation (sightings)HIGH2023-12-04

In cmdq, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08161758; Issue ID: ALPS081...

CVEs:CVE-2023-32849

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45866

Open SourceCoalition ESS > 63%MEDIUM2023-12-04

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occu...

CVEs:CVE-2023-45866

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
fedora affected fedoraproject
ipados affected apple
iphone_os affected apple
macos affected apple
ubuntu_linux affected canonical
Upstream advisory

CVE-2023-45866

GoogleCoalition ESS > 63%2023-12-04

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

CVEs:CVE-2023-45866

Upstream advisory

MGASA-2023-0349

Open SourcePoC exploit2023-12-17

Updated golang packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
golang affected Mageia:9 golang
Upstream advisory

GHSA-3m87-5598-2v4f

GooglePoC exploitHIGH2023-12-18

Withdrawn Advisory: Prometheus XSS Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
prometheus/prometheus affected github.com github.com/prometheus/prometheus
Upstream advisory

GHSA-3m87-5598-2v4f

Open SourcePoC exploitHIGH2023-12-18

Withdrawn Advisory: Prometheus XSS Vulnerability

Affected products

ProductStatusVendorPackageEcosystem
agentbeat-fips affected chainguard agentbeat-fips
amazon-cloudwatch-agent affected wolfi amazon-cloudwatch-agent
amazon-cloudwatch-agent affected chainguard amazon-cloudwatch-agent
amazon-cloudwatch-agent-fips affected chainguard amazon-cloudwatch-agent-fips
amazon-cloudwatch-agent-operator affected chainguard amazon-cloudwatch-agent-operator
amazon-cloudwatch-agent-operator affected wolfi amazon-cloudwatch-agent-operator
amazon-cloudwatch-agent-operator-fips affected chainguard amazon-cloudwatch-agent-operator-fips
beats-7 affected chainguard beats-7
beats-8 affected chainguard beats-8
beats-fips-7 affected chainguard beats-fips-7
beats-fips-8 affected chainguard beats-fips-8
certificate-transparency affected chainguard certificate-transparency
certificate-transparency affected wolfi certificate-transparency
certificate-transparency-fips affected chainguard certificate-transparency-fips
cloud-sql-proxy affected chainguard cloud-sql-proxy
cloud-sql-proxy affected wolfi cloud-sql-proxy
cloud-sql-proxy-fips affected chainguard cloud-sql-proxy-fips
cortex affected chainguard cortex
cortex affected wolfi cortex
cortex-fips affected chainguard cortex-fips
elastic-agent-fips affected chainguard elastic-agent-fips
fluent-bit-plugin-loki affected chainguard fluent-bit-plugin-loki
fluent-bit-plugin-loki affected wolfi fluent-bit-plugin-loki
gatekeeper-3.12 affected wolfi gatekeeper-3.12
gatekeeper-3.12 affected chainguard gatekeeper-3.12
gatekeeper-3.13 affected wolfi gatekeeper-3.13
gatekeeper-3.13 affected chainguard gatekeeper-3.13
gatekeeper-3.14 affected wolfi gatekeeper-3.14
gatekeeper-3.14 affected chainguard gatekeeper-3.14
gcsfuse affected chainguard gcsfuse
gcsfuse affected wolfi gcsfuse
gitaly-17.2 affected wolfi gitaly-17.2
gitaly-17.2 affected chainguard gitaly-17.2
gitaly-17.3 affected chainguard gitaly-17.3
gitaly-17.3 affected wolfi gitaly-17.3
gitaly-17.4 affected chainguard gitaly-17.4
gitaly-17.4 affected wolfi gitaly-17.4
gitaly-17.5 affected chainguard gitaly-17.5
gitaly-17.5 affected wolfi gitaly-17.5
gitaly-17.6 affected wolfi gitaly-17.6
gitaly-17.6 affected chainguard gitaly-17.6
gitaly-17.7 affected wolfi gitaly-17.7
gitaly-17.7 affected chainguard gitaly-17.7
gitaly-17.8 affected chainguard gitaly-17.8
gitaly-17.8 affected wolfi gitaly-17.8
gitaly-17.9 affected chainguard gitaly-17.9
gitaly-17.9 affected wolfi gitaly-17.9
gitaly-fips-17.2 affected chainguard gitaly-fips-17.2
gitaly-fips-17.3 affected chainguard gitaly-fips-17.3
gitaly-fips-17.4 affected chainguard gitaly-fips-17.4
gitaly-fips-17.5 affected chainguard gitaly-fips-17.5
gitaly-fips-17.6 affected chainguard gitaly-fips-17.6
gitaly-fips-17.7 affected chainguard gitaly-fips-17.7
gitaly-fips-17.8 affected chainguard gitaly-fips-17.8
gitaly-fips-17.9 affected chainguard gitaly-fips-17.9
grafana affected chainguard grafana
grafana affected wolfi grafana
grafana-10.4 affected chainguard grafana-10.4
grafana-10.4 affected wolfi grafana-10.4
grafana-11.0 affected chainguard grafana-11.0
grafana-11.0 affected wolfi grafana-11.0
grafana-11.1 affected chainguard grafana-11.1
grafana-11.1 affected wolfi grafana-11.1
grafana-11.2 affected wolfi grafana-11.2
grafana-11.2 affected chainguard grafana-11.2
grafana-11.3 affected wolfi grafana-11.3
grafana-11.3 affected chainguard grafana-11.3
grafana-11.4 affected chainguard grafana-11.4
grafana-11.4 affected wolfi grafana-11.4
grafana-11.5 affected chainguard grafana-11.5
grafana-11.5 affected wolfi grafana-11.5
grafana-7 affected chainguard grafana-7
grafana-9.3 affected chainguard grafana-9.3
grafana-fips-10.4 affected chainguard grafana-fips-10.4
grafana-fips-11.0 affected chainguard grafana-fips-11.0
grafana-fips-11.1 affected chainguard grafana-fips-11.1
grafana-fips-11.2 affected chainguard grafana-fips-11.2
grafana-fips-11.3 affected chainguard grafana-fips-11.3
grafana-fips-11.4 affected chainguard grafana-fips-11.4
grafana-fips-11.5 affected chainguard grafana-fips-11.5
istio-1.24 affected wolfi istio-1.24
istio-1.24 affected chainguard istio-1.24
istio-1.25 affected wolfi istio-1.25
istio-1.25 affected chainguard istio-1.25
istio-fips-1.21 affected chainguard istio-fips-1.21
istio-fips-1.22 affected chainguard istio-fips-1.22
istio-fips-1.23 affected chainguard istio-fips-1.23
istio-fips-1.24 affected chainguard istio-fips-1.24
istio-fips-1.25 affected chainguard istio-fips-1.25
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-1.21 affected chainguard istio-operator-1.21
istio-operator-1.21 affected wolfi istio-operator-1.21
istio-operator-1.22 affected chainguard istio-operator-1.22
istio-operator-1.22 affected wolfi istio-operator-1.22
istio-operator-fips-1.19 affected chainguard istio-operator-fips-1.19
istio-pilot-agent-1.18 affected chainguard istio-pilot-agent-1.18
istio-pilot-agent-1.18 affected wolfi istio-pilot-agent-1.18
istio-pilot-agent-1.19 affected chainguard istio-pilot-agent-1.19
istio-pilot-agent-1.19 affected wolfi istio-pilot-agent-1.19
istio-pilot-agent-1.20 affected wolfi istio-pilot-agent-1.20
istio-pilot-agent-1.20 affected chainguard istio-pilot-agent-1.20
istio-pilot-agent-fips-1.19 affected chainguard istio-pilot-agent-fips-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.20 affected wolfi istio-pilot-discovery-1.20
istio-pilot-discovery-1.20 affected chainguard istio-pilot-discovery-1.20
istio-pilot-discovery-1.21 affected wolfi istio-pilot-discovery-1.21
istio-pilot-discovery-1.21 affected chainguard istio-pilot-discovery-1.21
istio-pilot-discovery-1.22 affected chainguard istio-pilot-discovery-1.22
istio-pilot-discovery-1.22 affected wolfi istio-pilot-discovery-1.22
istio-pilot-discovery-fips-1.19 affected chainguard istio-pilot-discovery-fips-1.19
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
keda-2.16 affected chainguard keda-2.16
keda-2.16 affected wolfi keda-2.16
keda-fips affected chainguard keda-fips
loki affected wolfi loki
loki affected chainguard loki
loki-3.2 affected chainguard loki-3.2
loki-3.2 affected wolfi loki-3.2
loki-3.3 affected chainguard loki-3.3
loki-3.3 affected wolfi loki-3.3
loki-3.4 affected wolfi loki-3.4
loki-3.4 affected chainguard loki-3.4
loki-fips-3.2 affected chainguard loki-fips-3.2
loki-fips-3.3 affected chainguard loki-fips-3.3
loki-fips-3.4 affected chainguard loki-fips-3.4
mc affected wolfi mc
mc affected chainguard mc
mc-fips affected chainguard mc-fips
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
metrics-server-fips affected chainguard metrics-server-fips
minio affected chainguard minio
minio affected wolfi minio
minio-fips affected chainguard minio-fips
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
node-problem-detector-0.8 affected wolfi node-problem-detector-0.8
node-problem-detector-fips-0.8 affected chainguard node-problem-detector-fips-0.8
opentelemetry-collector affected wolfi opentelemetry-collector
opentelemetry-collector affected chainguard opentelemetry-collector
opentelemetry-collector-contrib affected wolfi opentelemetry-collector-contrib
opentelemetry-collector-contrib affected chainguard opentelemetry-collector-contrib
opentelemetry-collector-contrib-fips affected chainguard opentelemetry-collector-contrib-fips
opentelemetry-collector-fips affected chainguard opentelemetry-collector-fips
opentelemetry-operator affected wolfi opentelemetry-operator
opentelemetry-operator affected chainguard opentelemetry-operator
opentelemetry-operator-fips affected chainguard opentelemetry-operator-fips
plutono affected chainguard plutono
plutono-fips affected chainguard plutono-fips
prometheus-2.51 affected wolfi prometheus-2.51
prometheus-2.51 affected chainguard prometheus-2.51
prometheus-2.53 affected wolfi prometheus-2.53
prometheus-2.53 affected chainguard prometheus-2.53
prometheus-2.54 affected wolfi prometheus-2.54
prometheus-2.54 affected chainguard prometheus-2.54
prometheus-2.55 affected chainguard prometheus-2.55
prometheus-2.55 affected wolfi prometheus-2.55
prometheus-3.0 affected wolfi prometheus-3.0
prometheus-3.0 affected chainguard prometheus-3.0
prometheus-3.2 affected wolfi prometheus-3.2
prometheus-3.2 affected chainguard prometheus-3.2
prometheus-operator affected wolfi prometheus-operator
prometheus-operator affected chainguard prometheus-operator
prometheus-operator-fips affected chainguard prometheus-operator-fips
prometheus/prometheus affected github.com github.com/prometheus/prometheus
prometheus-pushgateway affected chainguard prometheus-pushgateway
prometheus-pushgateway affected wolfi prometheus-pushgateway
prometheus-pushgateway-fips affected chainguard prometheus-pushgateway-fips
splunk-otel-collector affected wolfi splunk-otel-collector
splunk-otel-collector affected chainguard splunk-otel-collector
splunk-otel-collector-fips affected chainguard splunk-otel-collector-fips
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.26 affected wolfi telegraf-1.26
telegraf-1.27 affected wolfi telegraf-1.27
telegraf-1.27 affected chainguard telegraf-1.27
telegraf-1.29 affected chainguard telegraf-1.29
telegraf-1.29 affected wolfi telegraf-1.29
telegraf-1.31 affected wolfi telegraf-1.31
telegraf-1.31 affected chainguard telegraf-1.31
telegraf-1.32 affected chainguard telegraf-1.32
telegraf-1.32 affected wolfi telegraf-1.32
telegraf-1.33 affected wolfi telegraf-1.33
telegraf-1.33 affected chainguard telegraf-1.33
tempo affected chainguard tempo
tempo affected wolfi tempo
tempo-2.3 affected chainguard tempo-2.3
tempo-fips affected chainguard tempo-fips
thanos affected chainguard thanos
thanos affected wolfi thanos
thanos-0.31 affected wolfi thanos-0.31
thanos-0.31 affected chainguard thanos-0.31
thanos-0.32 affected wolfi thanos-0.32
thanos-0.32 affected chainguard thanos-0.32
thanos-fips affected chainguard thanos-fips
trillian affected chainguard trillian
trillian affected wolfi trillian
trillian-fips affected chainguard trillian-fips
wavefront-collector-for-kubernetes-1.12 affected chainguard wavefront-collector-for-kubernetes-1.12
wavefront-collector-for-kubernetes-1.13 affected chainguard wavefront-collector-for-kubernetes-1.13
Upstream advisory

CLSA-2023-1702573728

Open SourcePoC exploitHIGH2023-12-14

Fix CVE(s): CVE-2022-48560

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:18.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:18.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:18.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:18.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:18.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:18.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:18.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:18.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:18.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:18.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:18.04 python2.7-minimal
Upstream advisory

CLSA-2023-1702573269

Open SourcePoC exploitHIGH2023-12-14

Fix CVE(s): CVE-2022-48560

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

CLSA-2023-1703611827

Open SourcePoC exploitHIGH2023-12-26

Fix CVE(s): CVE-2022-48564, CVE-2023-40217

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

CLSA-2023-1701971140

Open SourcePoC exploitHIGH2023-12-07

Fix CVE(s): CVE-2022-48564, CVE-2023-40217

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.6 affected TuxCare:Ubuntu:18.04 idle-python3.6
libpython3.6 affected TuxCare:Ubuntu:18.04 libpython3.6
libpython3.6-dev affected TuxCare:Ubuntu:18.04 libpython3.6-dev
libpython3.6-minimal affected TuxCare:Ubuntu:18.04 libpython3.6-minimal
libpython3.6-stdlib affected TuxCare:Ubuntu:18.04 libpython3.6-stdlib
libpython3.6-testsuite affected TuxCare:Ubuntu:18.04 libpython3.6-testsuite
python3.6 affected TuxCare:Ubuntu:18.04 python3.6
python3.6-dev affected TuxCare:Ubuntu:18.04 python3.6-dev
python3.6-doc affected TuxCare:Ubuntu:18.04 python3.6-doc
python3.6-examples affected TuxCare:Ubuntu:18.04 python3.6-examples
python3.6-minimal affected TuxCare:Ubuntu:18.04 python3.6-minimal
python3.6-venv affected TuxCare:Ubuntu:18.04 python3.6-venv
Upstream advisory

AZL-32100

Open SourcePoC exploitHIGH2023-12-05

CVE-2023-45287 affecting package golang for versions less than 1.20.0-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-32123

Open SourcePoC exploitHIGH2023-12-05

CVE-2023-45287 affecting package msft-golang for versions less than 1.20.0-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-34764

Open SourcePoC exploitHIGH2023-12-05

CVE-2023-45287 affecting package golang for versions less than 1.20.0-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-37310

Open SourcePoC exploitHIGH2023-12-05

CVE-2023-45287 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37380

Open SourcePoC exploitHIGH2023-12-05

CVE-2023-45287 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79088

Open SourcePoC exploitHIGH2023-12-05

CVE-2023-45287 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-45287

Open SourcePoC exploitHIGH2023-12-05

DEBIAN-CVE-2023-45287

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2023-45287

GooglePoC exploit2023-12-05

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

CVEs:CVE-2023-45287

Upstream advisory

CVE-2023-45287

GooglePoC exploitHIGH2023-12-05

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the rem...

CVEs:CVE-2023-45287

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2023-2375

Open SourcePoC exploitHIGH2023-12-05

Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

OESA-2023-1935

Open SourcePoC exploitNONE2023-12-22

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP1 golang
golang affected openEuler:20.03-LTS-SP3 golang
golang affected openEuler:20.03-LTS-SP4 golang
golang affected openEuler:22.03-LTS golang
golang affected openEuler:22.03-LTS-SP1 golang
golang affected openEuler:22.03-LTS-SP2 golang
Upstream advisory

GHSA-9f76-wg39-x86h

Open SourcePoC exploitMEDIUM2023-12-06

GHSA-9f76-wg39-x86h

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
amass affected wolfi amass
amass affected chainguard amass
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-load-balancer-controller-2.4.5 affected chainguard aws-load-balancer-controller-2.4.5
aws-load-balancer-controller-2.5 affected chainguard aws-load-balancer-controller-2.5
bank-vaults-fips affected chainguard bank-vaults-fips
calico-fips-3.25 affected chainguard calico-fips-3.25
cass-operator affected wolfi cass-operator
cass-operator affected chainguard cass-operator
cass-operator-fips affected chainguard cass-operator-fips
cilium-envoy affected chainguard cilium-envoy
cilium-envoy affected wolfi cilium-envoy
cluster-autoscaler-1.24 affected chainguard cluster-autoscaler-1.24
cluster-autoscaler-fips-1.25 affected chainguard cluster-autoscaler-fips-1.25
cni-plugins affected chainguard cni-plugins
cni-plugins affected wolfi cni-plugins
cni-plugins-fips affected chainguard cni-plugins-fips
configmap-reload affected wolfi configmap-reload
configmap-reload affected chainguard configmap-reload
configmap-reload-fips affected chainguard configmap-reload-fips
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
cortex affected wolfi cortex
cortex affected chainguard cortex
ctop affected chainguard ctop
ctop affected wolfi ctop
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
docker-cli affected wolfi docker-cli
docker-cli affected chainguard docker-cli
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
falco affected chainguard falco
falco affected wolfi falco
flannel-cni-plugin affected chainguard flannel-cni-plugin
flannel-cni-plugin affected wolfi flannel-cni-plugin
fulcio-fips affected chainguard fulcio-fips
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
go-bindata affected wolfi go-bindata
go-bindata affected chainguard go-bindata
gobuster affected wolfi gobuster
gobuster affected chainguard gobuster
go-licenses affected wolfi go-licenses
go-licenses affected chainguard go-licenses
go-md2man affected wolfi go-md2man
go-md2man affected chainguard go-md2man
gops affected wolfi gops
gops affected chainguard gops
goreleaser-1.18 affected wolfi goreleaser-1.18
goreleaser-1.18 affected chainguard goreleaser-1.18
gosu affected chainguard gosu
gosu affected wolfi gosu
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
hey affected chainguard hey
hey affected wolfi hey
hubble-ui affected wolfi hubble-ui
hubble-ui affected chainguard hubble-ui
hubble-ui-backend affected chainguard hubble-ui-backend
influx affected chainguard influx
influx affected wolfi influx
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
jsonnet-bundler affected chainguard jsonnet-bundler
k3d affected wolfi k3d
k3d affected chainguard k3d
kind affected wolfi kind
kind affected chainguard kind
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kubernetes-csi-external-resizer-1.8 affected chainguard kubernetes-csi-external-resizer-1.8
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-csi-node-driver-registrar-fips-2.8 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.8
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kyverno-1.8 affected chainguard kyverno-1.8
kyverno-policy-reporter-2.11 affected chainguard kyverno-policy-reporter-2.11
kyverno-policy-reporter-kyverno-plugin-1.5 affected chainguard kyverno-policy-reporter-kyverno-plugin-1.5
kyverno-policy-reporter-ui-1.7 affected chainguard kyverno-policy-reporter-ui-1.7
local-path-provisioner affected wolfi local-path-provisioner
local-path-provisioner affected chainguard local-path-provisioner
mage affected chainguard mage
mage affected wolfi mage
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
nats affected chainguard nats
nats affected wolfi nats
newrelic-nri-kube-events-1.9 affected chainguard newrelic-nri-kube-events-1.9
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nsc affected chainguard nsc
nsc affected wolfi nsc
oras affected chainguard oras
oras affected wolfi oras
petname affected wolfi petname
petname affected chainguard petname
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-beat-exporter-fips affected chainguard prometheus-beat-exporter-fips
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-fips-2.38 affected chainguard prometheus-fips-2.38
prometheus-redis-exporter-fips-1.44 affected chainguard prometheus-redis-exporter-fips-1.44
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter-0.22 affected chainguard prometheus-statsd-exporter-0.22
prometheus-statsd-exporter-fips-0.22 affected chainguard prometheus-statsd-exporter-fips-0.22
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
render-template affected wolfi render-template
render-template affected chainguard render-template
sbom-scorecard affected wolfi sbom-scorecard
sbom-scorecard affected chainguard sbom-scorecard
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
sonobuoy affected wolfi sonobuoy
sonobuoy affected chainguard sonobuoy
sops affected wolfi sops
sops affected chainguard sops
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
wait-for-port affected chainguard wait-for-port
wait-for-port affected wolfi wait-for-port
Upstream advisory

AZL-32102

Open SourcePoC exploitMEDIUM2023-12-06

CVE-2023-39326 affecting package golang for versions less than 1.21.5-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-32124

Open SourcePoC exploitMEDIUM2023-12-06

CVE-2023-39326 affecting package msft-golang for versions less than 1.21.5-1

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37446

Open SourcePoC exploitMEDIUM2023-12-06

CVE-2023-39326 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37452

Open SourcePoC exploitMEDIUM2023-12-06

CVE-2023-39326 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79114

Open SourcePoC exploitMEDIUM2023-12-06

CVE-2023-39326 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-39326

Open SourcePoC exploitMEDIUM2023-12-06

DEBIAN-CVE-2023-39326

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GO-2023-2382

Open SourcePoC exploitHIGH2023-12-06

Denial of service via chunk extensions in net/http

Affected products

ProductStatusVendorPackageEcosystem
aactl affected wolfi aactl
aactl affected chainguard aactl
amass affected wolfi amass
amass affected chainguard amass
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis affected wolfi aws-flb-kinesis
bank-vaults-fips affected chainguard bank-vaults-fips
cass-operator affected wolfi cass-operator
cass-operator affected chainguard cass-operator
cass-operator-fips affected chainguard cass-operator-fips
cni-plugins affected wolfi cni-plugins
cni-plugins affected chainguard cni-plugins
cni-plugins-fips affected chainguard cni-plugins-fips
configmap-reload affected wolfi configmap-reload
configmap-reload affected chainguard configmap-reload
configmap-reload-fips affected chainguard configmap-reload-fips
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
cortex affected chainguard cortex
cortex affected wolfi cortex
ctop affected wolfi ctop
ctop affected chainguard ctop
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
docker-cli affected wolfi docker-cli
docker-cli affected chainguard docker-cli
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
flannel-cni-plugin affected chainguard flannel-cni-plugin
flannel-cni-plugin affected wolfi flannel-cni-plugin
fulcio-fips affected chainguard fulcio-fips
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
go-bindata affected wolfi go-bindata
go-bindata affected chainguard go-bindata
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
go-md2man affected wolfi go-md2man
go-md2man affected chainguard go-md2man
gops affected chainguard gops
gops affected wolfi gops
gosu affected chainguard gosu
gosu affected wolfi gosu
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
hey affected chainguard hey
hey affected wolfi hey
hubble-ui affected chainguard hubble-ui
hubble-ui affected wolfi hubble-ui
influx affected wolfi influx
influx affected chainguard influx
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
jsonnet-bundler affected chainguard jsonnet-bundler
k3d affected wolfi k3d
k3d affected chainguard k3d
kind affected wolfi kind
kind affected chainguard kind
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
local-path-provisioner affected chainguard local-path-provisioner
local-path-provisioner affected wolfi local-path-provisioner
mage affected chainguard mage
mage affected wolfi mage
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
nats affected chainguard nats
nats affected wolfi nats
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nsc affected wolfi nsc
nsc affected chainguard nsc
oras affected chainguard oras
oras affected wolfi oras
petname affected wolfi petname
petname affected chainguard petname
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-beat-exporter-fips affected chainguard prometheus-beat-exporter-fips
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter-fips-0.22 affected chainguard prometheus-statsd-exporter-fips-0.22
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
render-template affected wolfi render-template
render-template affected chainguard render-template
sbom-scorecard affected chainguard sbom-scorecard
sbom-scorecard affected wolfi sbom-scorecard
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
sonobuoy affected chainguard sonobuoy
sonobuoy affected wolfi sonobuoy
sops affected wolfi sops
sops affected chainguard sops
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
stdlib affected Go stdlib
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
wait-for-port affected wolfi wait-for-port
wait-for-port affected chainguard wait-for-port
Upstream advisory

GHSA-5f94-vhjq-rpg8

Open SourcePoC exploitHIGH2023-12-06

GHSA-5f94-vhjq-rpg8

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
amass affected wolfi amass
amass affected chainguard amass
aws-ebs-csi-driver-1.18 affected chainguard aws-ebs-csi-driver-1.18
aws-ebs-csi-driver-1.19 affected chainguard aws-ebs-csi-driver-1.19
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis affected wolfi aws-flb-kinesis
aws-load-balancer-controller-2.4.5 affected chainguard aws-load-balancer-controller-2.4.5
aws-load-balancer-controller-2.5 affected chainguard aws-load-balancer-controller-2.5
bank-vaults-fips affected chainguard bank-vaults-fips
calico-fips-3.25 affected chainguard calico-fips-3.25
cass-operator affected wolfi cass-operator
cass-operator affected chainguard cass-operator
cass-operator-fips affected chainguard cass-operator-fips
cilium-envoy affected wolfi cilium-envoy
cilium-envoy affected chainguard cilium-envoy
cluster-autoscaler-1.24 affected chainguard cluster-autoscaler-1.24
cluster-autoscaler-fips-1.25 affected chainguard cluster-autoscaler-fips-1.25
cni-plugins affected chainguard cni-plugins
cni-plugins affected wolfi cni-plugins
cni-plugins-fips affected chainguard cni-plugins-fips
configmap-reload affected wolfi configmap-reload
configmap-reload affected chainguard configmap-reload
configmap-reload-fips affected chainguard configmap-reload-fips
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
cortex affected wolfi cortex
cortex affected chainguard cortex
ctop affected chainguard ctop
ctop affected wolfi ctop
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
docker-cli affected wolfi docker-cli
docker-cli affected chainguard docker-cli
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
falco affected wolfi falco
falco affected chainguard falco
flannel-cni-plugin affected wolfi flannel-cni-plugin
flannel-cni-plugin affected chainguard flannel-cni-plugin
fulcio-fips affected chainguard fulcio-fips
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
go-bindata affected chainguard go-bindata
go-bindata affected wolfi go-bindata
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
go-md2man affected wolfi go-md2man
go-md2man affected chainguard go-md2man
gops affected chainguard gops
gops affected wolfi gops
goreleaser-1.18 affected wolfi goreleaser-1.18
goreleaser-1.18 affected chainguard goreleaser-1.18
gosu affected wolfi gosu
gosu affected chainguard gosu
grpcurl affected wolfi grpcurl
grpcurl affected chainguard grpcurl
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
hey affected chainguard hey
hey affected wolfi hey
hubble-ui affected wolfi hubble-ui
hubble-ui affected chainguard hubble-ui
hubble-ui-backend affected chainguard hubble-ui-backend
influx affected chainguard influx
influx affected wolfi influx
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
jsonnet-bundler affected chainguard jsonnet-bundler
k3d affected wolfi k3d
k3d affected chainguard k3d
kind affected wolfi kind
kind affected chainguard kind
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kubernetes-csi-external-resizer-1.8 affected chainguard kubernetes-csi-external-resizer-1.8
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-csi-node-driver-registrar-fips-2.8 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.8
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kyverno-1.8 affected chainguard kyverno-1.8
kyverno-policy-reporter-2.11 affected chainguard kyverno-policy-reporter-2.11
kyverno-policy-reporter-kyverno-plugin-1.5 affected chainguard kyverno-policy-reporter-kyverno-plugin-1.5
kyverno-policy-reporter-ui-1.7 affected chainguard kyverno-policy-reporter-ui-1.7
local-path-provisioner affected wolfi local-path-provisioner
local-path-provisioner affected chainguard local-path-provisioner
mage affected wolfi mage
mage affected chainguard mage
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
nats affected chainguard nats
nats affected wolfi nats
newrelic-nri-kube-events-1.9 affected chainguard newrelic-nri-kube-events-1.9
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nsc affected wolfi nsc
nsc affected chainguard nsc
oras affected wolfi oras
oras affected chainguard oras
petname affected wolfi petname
petname affected chainguard petname
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-beat-exporter-fips affected chainguard prometheus-beat-exporter-fips
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-fips-2.38 affected chainguard prometheus-fips-2.38
prometheus-redis-exporter-fips-1.44 affected chainguard prometheus-redis-exporter-fips-1.44
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-stackdriver-exporter affected wolfi prometheus-stackdriver-exporter
prometheus-statsd-exporter-0.22 affected chainguard prometheus-statsd-exporter-0.22
prometheus-statsd-exporter-fips-0.22 affected chainguard prometheus-statsd-exporter-fips-0.22
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
render-template affected chainguard render-template
render-template affected wolfi render-template
sbom-scorecard affected wolfi sbom-scorecard
sbom-scorecard affected chainguard sbom-scorecard
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
sonobuoy affected chainguard sonobuoy
sonobuoy affected wolfi sonobuoy
sops affected wolfi sops
sops affected chainguard sops
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
wait-for-port affected wolfi wait-for-port
wait-for-port affected chainguard wait-for-port
Upstream advisory

AZL-32101

Open SourcePoC exploitHIGH2023-12-06

CVE-2023-45285 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-32103

Open SourcePoC exploitHIGH2023-12-06

CVE-2023-45285 affecting package msft-golang for versions less than 1.22.3-1.

Affected products

ProductStatusVendorPackageEcosystem
msft-golang affected Azure Linux:2 msft-golang
Upstream advisory

AZL-37323

Open SourcePoC exploitHIGH2023-12-06

CVE-2023-45285 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37438

Open SourcePoC exploitHIGH2023-12-06

CVE-2023-45285 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79014

Open SourcePoC exploitHIGH2023-12-06

CVE-2023-45285 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2023-45285

Open SourcePoC exploitHIGH2023-12-06

DEBIAN-CVE-2023-45285

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

GO-2023-2383

Open SourcePoC exploit2023-12-06

Command 'go get' may unexpectedly fallback to insecure git in cmd/go

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
amass affected chainguard amass
amass affected wolfi amass
aws-flb-cloudwatch affected wolfi aws-flb-cloudwatch
aws-flb-cloudwatch affected chainguard aws-flb-cloudwatch
aws-flb-firehose affected wolfi aws-flb-firehose
aws-flb-firehose affected chainguard aws-flb-firehose
aws-flb-kinesis affected chainguard aws-flb-kinesis
aws-flb-kinesis affected wolfi aws-flb-kinesis
bank-vaults-fips affected chainguard bank-vaults-fips
cass-operator affected wolfi cass-operator
cass-operator affected chainguard cass-operator
cass-operator-fips affected chainguard cass-operator-fips
cni-plugins affected chainguard cni-plugins
cni-plugins affected wolfi cni-plugins
cni-plugins-fips affected chainguard cni-plugins-fips
configmap-reload affected chainguard configmap-reload
configmap-reload affected wolfi configmap-reload
configmap-reload-fips affected chainguard configmap-reload-fips
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
cortex affected chainguard cortex
cortex affected wolfi cortex
ctop affected chainguard ctop
ctop affected wolfi ctop
dgraph affected chainguard dgraph
dgraph affected wolfi dgraph
docker-cli affected chainguard docker-cli
docker-cli affected wolfi docker-cli
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
flannel-cni-plugin affected chainguard flannel-cni-plugin
flannel-cni-plugin affected wolfi flannel-cni-plugin
fulcio-fips affected chainguard fulcio-fips
gke-gcloud-auth-plugin affected wolfi gke-gcloud-auth-plugin
gke-gcloud-auth-plugin affected chainguard gke-gcloud-auth-plugin
go-bindata affected chainguard go-bindata
go-bindata affected wolfi go-bindata
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
go-md2man affected chainguard go-md2man
go-md2man affected wolfi go-md2man
gops affected chainguard gops
gops affected wolfi gops
gosu affected wolfi gosu
gosu affected chainguard gosu
grpcurl affected chainguard grpcurl
grpcurl affected wolfi grpcurl
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
hey affected chainguard hey
hey affected wolfi hey
hubble-ui affected chainguard hubble-ui
hubble-ui affected wolfi hubble-ui
influx affected wolfi influx
influx affected chainguard influx
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
jsonnet-bundler affected chainguard jsonnet-bundler
k3d affected chainguard k3d
k3d affected wolfi k3d
kind affected chainguard kind
kind affected wolfi kind
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kube-logging-logging-operator-4.1 affected chainguard kube-logging-logging-operator-4.1
kubernetes-csi-livenessprobe-2.10 affected chainguard kubernetes-csi-livenessprobe-2.10
kubernetes-csi-livenessprobe-fips affected chainguard kubernetes-csi-livenessprobe-fips
kubernetes-csi-livenessprobe-fips-2.10 affected chainguard kubernetes-csi-livenessprobe-fips-2.10
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
local-path-provisioner affected chainguard local-path-provisioner
local-path-provisioner affected wolfi local-path-provisioner
mage affected chainguard mage
mage affected wolfi mage
metrics-server affected wolfi metrics-server
metrics-server affected chainguard metrics-server
nats affected chainguard nats
nats affected wolfi nats
nri-discovery-kubernetes affected wolfi nri-discovery-kubernetes
nri-discovery-kubernetes affected chainguard nri-discovery-kubernetes
nsc affected wolfi nsc
nsc affected chainguard nsc
oras affected wolfi oras
oras affected chainguard oras
petname affected chainguard petname
petname affected wolfi petname
prometheus-adapter-fips-0.10 affected chainguard prometheus-adapter-fips-0.10
prometheus-beat-exporter-fips affected chainguard prometheus-beat-exporter-fips
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-stackdriver-exporter affected chainguard prometheus-stackdriver-exporter
prometheus-statsd-exporter-fips-0.22 affected chainguard prometheus-statsd-exporter-fips-0.22
protoc-gen-go-grpc affected chainguard protoc-gen-go-grpc
protoc-gen-go-grpc affected wolfi protoc-gen-go-grpc
render-template affected wolfi render-template
render-template affected chainguard render-template
sbom-scorecard affected wolfi sbom-scorecard
sbom-scorecard affected chainguard sbom-scorecard
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
smarter-device-manager affected chainguard smarter-device-manager
smarter-device-manager affected wolfi smarter-device-manager
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
sonobuoy affected wolfi sonobuoy
sonobuoy affected chainguard sonobuoy
sops affected chainguard sops
sops affected wolfi sops
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
tigera-operator-1.28 affected chainguard tigera-operator-1.28
tigera-operator-1.29 affected chainguard tigera-operator-1.29
toolchain affected Go toolchain
vertical-pod-autoscaler affected chainguard vertical-pod-autoscaler
vertical-pod-autoscaler affected wolfi vertical-pod-autoscaler
wait-for-port affected chainguard wait-for-port
wait-for-port affected wolfi wait-for-port
Upstream advisory

CLSA-2023-1701971295

Open SourcePoC exploit2023-12-07

Fix CVE(s): CVE-2023-40217

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

CLSA-2023-1701971229

Open SourcePoC exploit2023-12-07

Fix CVE(s): CVE-2023-40217

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:18.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:18.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:18.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:18.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:18.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:18.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:18.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:18.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:18.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:18.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:18.04 python2.7-minimal
Upstream advisory

GHSA-mw99-9chc-xw7r

GooglePoC exploitCRITICAL2023-12-27

Maliciously crafted Git server replies can cause DoS on go-git clients

Affected products

ProductStatusVendorPackageEcosystem
go-git/go-git/v5 affected github.com github.com/go-git/go-git/v5
src-d/go-git.v4 affected gopkg.in gopkg.in/src-d/go-git.v4
Upstream advisory

GHSA-mw99-9chc-xw7r

Open SourcePoC exploitCRITICAL2023-12-27

Maliciously crafted Git server replies can cause DoS on go-git clients

Affected products

ProductStatusVendorPackageEcosystem
apko affected wolfi apko
apko affected chainguard apko
argo-cd-2.7 affected wolfi argo-cd-2.7
argo-cd-2.7 affected chainguard argo-cd-2.7
argo-cd-2.8 affected chainguard argo-cd-2.8
argo-cd-2.8 affected wolfi argo-cd-2.8
argo-cd-2.9 affected wolfi argo-cd-2.9
argo-cd-2.9 affected chainguard argo-cd-2.9
bom affected chainguard bom
bom affected wolfi bom
flux-0 affected chainguard flux-0
flux-0.37 affected chainguard flux-0.37
flux-2.0 affected chainguard flux-2.0
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller-2.0 affected chainguard flux-kustomize-controller-2.0
flux-source-controller-2.0 affected chainguard flux-source-controller-2.0
gitness affected wolfi gitness
gitness affected chainguard gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
go-git/go-git/v5 affected github.com github.com/go-git/go-git/v5
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
gomplate affected chainguard gomplate
gomplate affected wolfi gomplate
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
goreleaser-1.18 affected wolfi goreleaser-1.18
goreleaser-1.18 affected chainguard goreleaser-1.18
grafana-10.1 affected chainguard grafana-10.1
grafana-9 affected chainguard grafana-9
grafana-9.3 affected chainguard grafana-9.3
kots affected wolfi kots
kots affected chainguard kots
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-yaml affected wolfi pulumi-language-yaml
pulumi-language-yaml affected chainguard pulumi-language-yaml
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
src-d/go-git.v4 affected gopkg.in gopkg.in/src-d/go-git.v4
src-fingerprint affected wolfi src-fingerprint
src-fingerprint affected chainguard src-fingerprint
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

CVE-2023-45777

Open SourcePoC exploitHIGH2023-12-04

In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to launch arbitrary activities using system privileges due to Parcel Mismatch. This could lead to local escalation of privilege with no additional execution privi...

CVEs:CVE-2023-45777

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45779

Open SourcePoC exploitHIGH2023-12-04

In the APEX module framework of AOSP, there is a possible malicious update to platform components due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2023-45779

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-301094654

GooglePoC exploitNONE2023-12-01

ASB-A-301094654

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-40084

Open SourcePoC exploitHIGH2023-12-04

In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40084

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48409

Open SourcePoC exploitHIGH2023-12-06

In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional e...

CVEs:CVE-2023-48409

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-296984851

GooglePoC exploitHIGH2023-12-01

PUB-A-296984851

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-40077

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40077

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35618

Open SourceCoalition ESS < 30%CRITICAL2023-12-07

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2023-35618

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-40076

Open SourceCoalition ESS < 30%MEDIUM2023-12-04

In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2023-40076

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-38174

Open SourceCoalition ESS < 30%HIGH2023-12-07

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVEs:CVE-2023-38174

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-36878

Open SourceCoalition ESS < 30%MEDIUM2023-12-12

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVEs:CVE-2023-36878

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-7f9x-gw85-8grf

Open SourceCoalition ESS < 30%CRITICAL2023-12-05

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

Affected products

ProductStatusVendorPackageEcosystem
cosign-fips affected chainguard cosign-fips
cosign-fips affected wolfi cosign-fips
external-secrets-0.7 affected chainguard external-secrets-0.7
falco affected wolfi falco
falco affected chainguard falco
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
istio-cni-1.19 affected chainguard istio-cni-1.19
istio-cni-1.19 affected wolfi istio-cni-1.19
istio-cni-1.20 affected wolfi istio-cni-1.20
istio-cni-1.20 affected chainguard istio-cni-1.20
istio-cni-fips-1.19 affected chainguard istio-cni-fips-1.19
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-fips-1.19 affected chainguard istio-operator-fips-1.19
istio-pilot-agent-1.18 affected wolfi istio-pilot-agent-1.18
istio-pilot-agent-1.18 affected chainguard istio-pilot-agent-1.18
istio-pilot-agent-1.19 affected chainguard istio-pilot-agent-1.19
istio-pilot-agent-1.19 affected wolfi istio-pilot-agent-1.19
istio-pilot-agent-1.20 affected wolfi istio-pilot-agent-1.20
istio-pilot-agent-1.20 affected chainguard istio-pilot-agent-1.20
istio-pilot-agent-fips-1.19 affected chainguard istio-pilot-agent-fips-1.19
istio-pilot-discovery-1.18 affected chainguard istio-pilot-discovery-1.18
istio-pilot-discovery-1.18 affected wolfi istio-pilot-discovery-1.18
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
istio-pilot-discovery-1.20 affected wolfi istio-pilot-discovery-1.20
istio-pilot-discovery-1.20 affected chainguard istio-pilot-discovery-1.20
istio-pilot-discovery-fips-1.19 affected chainguard istio-pilot-discovery-fips-1.19
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kyverno affected wolfi kyverno
kyverno affected chainguard kyverno
lestrrat-go/jwx affected github.com github.com/lestrrat-go/jwx
lestrrat-go/jwx/v2 affected github.com github.com/lestrrat-go/jwx/v2
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
Upstream advisory

GHSA-7f9x-gw85-8grf

GoogleCoalition ESS < 30%CRITICAL2023-12-05

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

Affected products

ProductStatusVendorPackageEcosystem
lestrrat-go/jwx affected github.com github.com/lestrrat-go/jwx
lestrrat-go/jwx/v2 affected github.com github.com/lestrrat-go/jwx/v2
Upstream advisory

CVE-2022-44589

GoogleCoalition ESS < 30%HIGH2023-12-29

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA , Two Factor, OTP SMS and Email | Passwordless login.This issue affects miniOrange'...

CVEs:CVE-2022-44589

Affected products

ProductStatusVendorPackageEcosystem
google_authenticator affected miniorange
Upstream advisory

CVE-2023-40082

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In modify_for_next_stage of fdt.rs, there is a possible way to render KASLR ineffective due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-40082

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-292004859

GoogleCoalition ESS < 30%HIGH2023-12-01

PUB-A-292004859

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-40090

Open SourceCoalition ESS < 30%MEDIUM2023-12-04

In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2023-40090

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40078

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. Us...

CVEs:CVE-2023-40078

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48423

Open SourceCoalition ESS < 30%CRITICAL2023-12-06

In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48423

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-294560448

GoogleCoalition ESS < 30%HIGH2023-12-01

PUB-A-294560448

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48416

Open SourceCoalition ESS < 30%HIGH2023-12-06

In multiple locations, there is a possible null dereference due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48416

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-244500020

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-244500020

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-42716

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed

CVEs:CVE-2023-42716

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42717

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed

CVEs:CVE-2023-42717

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48397

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

In Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48397

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48413

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48413

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-286709510

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-286709510

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-293719047

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-293719047

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21162

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In RGXUnbackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2023-21162

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21163

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In PMR_ReadBytes of pmr.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2023-21163

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21164

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In DevmemIntMapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2023-21164

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21166

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In RGXBackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-21166

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21215

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In DevmemIntAcquireRemoteCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is...

CVEs:CVE-2023-21215

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21217

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-21217

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21218

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interacti...

CVEs:CVE-2023-21218

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21228

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interacti...

CVEs:CVE-2023-21228

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21263

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In OSMMapPMRGeneric of pmr_os.c, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-21263

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21401

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In DevmemIntChangeSparse of devicemem_server.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2023-21401

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21402

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2023-21402

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21403

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In RGXDestroyZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2023-21403

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35690

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In RGXDestroyHWRTData of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2023-35690

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-291982610

GoogleCoalition ESS < 30%HIGH2023-12-01

ASB-A-291982610

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-291999439

GoogleCoalition ESS < 30%MEDIUM2023-12-01

ASB-A-291999439

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-292000190

GoogleCoalition ESS < 30%MEDIUM2023-12-01

ASB-A-292000190

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-292002163

GoogleCoalition ESS < 30%CRITICAL2023-12-01

ASB-A-292002163

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-292002918

GoogleCoalition ESS < 30%CRITICAL2023-12-01

ASB-A-292002918

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-292003338

GoogleCoalition ESS < 30%HIGH2023-12-01

ASB-A-292003338

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-292004168

GoogleCoalition ESS < 30%CRITICAL2023-12-01

ASB-A-292004168

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-292087506

GoogleCoalition ESS < 30%HIGH2023-12-01

ASB-A-292087506

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-305091236

GoogleCoalition ESS < 30%HIGH2023-12-01

ASB-A-305091236

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-305093885

GoogleCoalition ESS < 30%2023-12-01

ASB-A-305093885

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-305095406

GoogleCoalition ESS < 30%CRITICAL2023-12-01

ASB-A-305095406

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-305095935

GoogleCoalition ESS < 30%HIGH2023-12-01

ASB-A-305095935

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-305096969

GoogleCoalition ESS < 30%HIGH2023-12-01

ASB-A-305096969

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48403

Open SourceCoalition ESS < 30%HIGH2023-12-06

In sms_DecodeCodedTpMsg of sms_PduCodec.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure if the attacker is able to observe the behavior of the subsequent switch conditional with ...

CVEs:CVE-2023-48403

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-285435372

GoogleCoalition ESS < 30%HIGH2023-12-01

PUB-A-285435372

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48404

Open SourceCoalition ESS < 30%HIGH2023-12-06

In ProtocolMiscCarrierConfigSimInfoIndAdapter of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User intera...

CVEs:CVE-2023-48404

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48410

Open SourceCoalition ESS < 30%HIGH2023-12-06

In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48410

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-289563789

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-289563789

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-299427380

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-299427380

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-21216

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction i...

CVEs:CVE-2023-21216

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-291999952

GoogleCoalition ESS < 30%HIGH2023-12-01

ASB-A-291999952

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48425

GoogleCoalition ESS < 30%CRITICAL2023-12-11

U-Boot vulnerability resulting in persistent Code Execution 

CVEs:CVE-2023-48425

Affected products

ProductStatusVendorPackageEcosystem
chromecast_firmware affected google
Upstream advisory

CVE-2023-42561

Open SourceCoalition ESS < 30%CRITICAL2023-12-05

Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.

CVEs:CVE-2023-42561

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-296910715

GoogleCoalition ESS < 30%2023-12-01

ASB-A-296910715

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

AZL-37343

Open SourceCoalition ESS < 30%MEDIUM2023-12-05

CVE-2023-49292 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37392

Open SourceCoalition ESS < 30%MEDIUM2023-12-05

CVE-2023-49292 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-58246

Open SourceCoalition ESS < 30%MEDIUM2023-12-05

CVE-2023-49292 affecting package golang for versions less than 1.20.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-78898

Open SourceCoalition ESS < 30%MEDIUM2023-12-05

CVE-2023-49292 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2023-48398

Open SourceCoalition ESS < 30%HIGH2023-12-06

In ProtocolNetAcBarringInfo::ProtocolNetAcBarringInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User i...

CVEs:CVE-2023-48398

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-286055426

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-286055426

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-42559

Open SourceCoalition ESS < 30%HIGH2023-12-05

Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.

CVEs:CVE-2023-42559

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-48424

GoogleCoalition ESS < 30%CRITICAL2023-12-11

U-Boot shell vulnerability resulting in Privilege escalation in a production device

CVEs:CVE-2023-48424

Affected products

ProductStatusVendorPackageEcosystem
chromecast_firmware affected google
Upstream advisory

CVE-2023-48417

GoogleCoalition ESS < 30%CRITICAL2023-12-11

Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application

CVEs:CVE-2023-48417

Affected products

ProductStatusVendorPackageEcosystem
chromecast_firmware affected google
Upstream advisory

CVE-2023-21227

Open SourceCoalition ESS < 30%HIGH2023-12-04

In HTBLogKM of htbserver.c, there is a possible information disclosure due to log information disclosure. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-21227

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-291998937

GoogleCoalition ESS < 30%MEDIUM2023-12-01

ASB-A-291998937

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-42557

Open SourceCoalition ESS < 30%CRITICAL2023-12-05

Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.

CVEs:CVE-2023-42557

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-49769

GoogleCoalition ESS < 30%HIGH2023-12-17

Cross-Site Request Forgery (CSRF) vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.4.

CVEs:CVE-2023-49769

Affected products

ProductStatusVendorPackageEcosystem
integrate_google_drive affected softlabbd
Upstream advisory

CVE-2023-42566

Open SourceCoalition ESS < 30%HIGH2023-12-05

Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.

CVEs:CVE-2023-42566

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42567

Open SourceCoalition ESS < 30%CRITICAL2023-12-05

Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.

CVEs:CVE-2023-42567

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-272772567

GoogleCoalition ESS < 30%2023-12-01

ASB-A-272772567

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-40087

Open SourceCoalition ESS < 30%HIGH2023-12-04

In transcodeQ*ToFloat of btif_avrcp_audio_track.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2023-40087

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42556

Open SourceCoalition ESS < 30%HIGH2023-12-05

Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.

CVEs:CVE-2023-42556

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42560

Open SourceCoalition ESS < 30%CRITICAL2023-12-05

Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.

CVEs:CVE-2023-42560

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42558

Open SourceCoalition ESS < 30%CRITICAL2023-12-05

Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.

CVEs:CVE-2023-42558

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42565

Open SourceCoalition ESS < 30%HIGH2023-12-05

Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.

CVEs:CVE-2023-42565

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42568

Open SourceCoalition ESS < 30%HIGH2023-12-05

Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.

CVEs:CVE-2023-42568

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-3742

GoogleCoalition ESS < 30%HIGH2023-12-20

Insufficient policy enforcement in ADB in Google Chrome on ChromeOS prior to 114.0.5735.90 allowed a local attacker to bypass device policy restrictions via physical access to the device. (Chromium security severity: High)

CVEs:CVE-2023-3742

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-42563

Open SourceCoalition ESS < 30%CRITICAL2023-12-05

Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.

CVEs:CVE-2023-42563

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42569

Open SourceCoalition ESS < 30%MEDIUM2023-12-05

Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.

CVEs:CVE-2023-42569

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42570

Open SourceCoalition ESS < 30%MEDIUM2023-12-05

Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.

CVEs:CVE-2023-42570

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-42564

Open SourceCoalition ESS < 30%MEDIUM2023-12-05

Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.

CVEs:CVE-2023-42564

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-40096

Open SourceCoalition ESS < 30%HIGH2023-12-04

In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audio from the background due to a missing flag. This could lead to local escalation of privilege with User execution privileges needed. User interaction is...

CVEs:CVE-2023-40096

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42562

Open SourceCoalition ESS < 30%CRITICAL2023-12-05

Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.

CVEs:CVE-2023-42562

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-295942985

GoogleCoalition ESS < 30%2023-12-01

ASB-A-295942985

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-40103

Open SourceCoalition ESS < 30%HIGH2023-12-04

In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40103

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-299146464

GoogleCoalition ESS < 30%2023-12-01

ASB-A-299146464

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-299146536

GoogleCoalition ESS < 30%2023-12-01

ASB-A-299146536

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-299146326

GoogleCoalition ESS < 30%2023-12-01

ASB-A-299146326

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2023-40083

Open SourceCoalition ESS < 30%MEDIUM2023-12-04

In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40083

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-258533280

GoogleCoalition ESS < 30%2023-12-01

PUB-A-258533280

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-35668

Open SourceCoalition ESS < 30%MEDIUM2023-12-04

In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-35668

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40074

Open SourceCoalition ESS < 30%MEDIUM2023-12-04

In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40074

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40073

Open SourceCoalition ESS < 30%MEDIUM2023-12-04

In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40073

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42724

Open SourceCoalition ESS < 30%HIGH2023-12-04

In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42724

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40094

Open SourceCoalition ESS < 30%HIGH2023-12-04

In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2023-40094

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40080

Open SourceCoalition ESS < 30%HIGH2023-12-04

In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2023-40080

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45781

Open SourceCoalition ESS < 30%MEDIUM2023-12-04

In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-45781

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40079

Open SourceCoalition ESS < 30%HIGH2023-12-04

In injectSendIntentSender of ShortcutService.java, there is a possible background activity launch due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2023-40079

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40091

Open SourceCoalition ESS < 30%HIGH2023-12-04

In onTransact of IncidentService.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-40091

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40095

Open SourceCoalition ESS < 30%HIGH2023-12-04

In createDontSendToRestrictedAppsBundle of PendingIntentUtils.java, there is a possible background activity launch due to a missing check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...

CVEs:CVE-2023-40095

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40097

Open SourceCoalition ESS < 30%HIGH2023-12-04

In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for ex...

CVEs:CVE-2023-40097

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45773

Open SourceCoalition ESS < 30%HIGH2023-12-04

In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-45773

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45774

Open SourceCoalition ESS < 30%HIGH2023-12-04

In fixUpIncomingShortcutInfo of ShortcutService.java, there is a possible way to view another user's image due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...

CVEs:CVE-2023-45774

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45775

Open SourceCoalition ESS < 30%HIGH2023-12-04

In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2023-45775

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-45776

Open SourceCoalition ESS < 30%HIGH2023-12-04

In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2023-45776

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40098

Open SourceCoalition ESS < 30%MEDIUM2023-12-04

In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. U...

CVEs:CVE-2023-40098

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-300376910

GoogleCoalition ESS < 30%2023-12-01

ASB-A-300376910

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-40081

Open SourceCoalition ESS < 30%MEDIUM2023-12-04

In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction ...

CVEs:CVE-2023-40081

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40092

Open SourceCoalition ESS < 30%MEDIUM2023-12-04

In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2023-40092

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40089

Open SourceCoalition ESS < 30%HIGH2023-12-04

In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalation of privilege with no addition...

CVEs:CVE-2023-40089

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40075

Open SourceCoalition ESS < 30%HIGH2023-12-04

In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges ...

CVEs:CVE-2023-40075

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32847

Open SourceCoalition ESS < 30%HIGH2023-12-04

In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08241940; Issue...

CVEs:CVE-2023-32847

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32850

Open SourceCoalition ESS < 30%HIGH2023-12-04

In decoder, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08016659; Issue ...

CVEs:CVE-2023-32850

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32851

Open SourceCoalition ESS < 30%HIGH2023-12-04

In decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08016652; Iss...

CVEs:CVE-2023-32851

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-302982512

GoogleCoalition ESS < 30%2023-12-01

ASB-A-302982512

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-302983201

GoogleCoalition ESS < 30%2023-12-01

ASB-A-302983201

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-302986375

GoogleCoalition ESS < 30%2023-12-01

ASB-A-302986375

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-42722

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In camera service, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed

CVEs:CVE-2023-42722

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48407

Open SourceCoalition ESS < 30%HIGH2023-12-06

there is a possible DCK won't be deleted after factory reset due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48407

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-282081424

GoogleCoalition ESS < 30%NONE2023-12-01

PUB-A-282081424

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48405

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

there is a possible way for the secure world to write to NS memory due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48405

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48414

Open SourceCoalition ESS < 30%HIGH2023-12-06

In the Pixel Camera Driver, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48414

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-288366554

GoogleCoalition ESS < 30%HIGH2023-12-01

PUB-A-288366554

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-293298397

GoogleCoalition ESS < 30%NONE2023-12-01

PUB-A-293298397

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48421

Open SourceCoalition ESS < 30%HIGH2023-12-06

In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no...

CVEs:CVE-2023-48421

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-300681900

GoogleCoalition ESS < 30%HIGH2023-12-01

PUB-A-300681900

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48406

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48406

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48412

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

In private_handle_t of mali_gralloc_buffer.h, there is a possible information leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2023-48412

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-213170949

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-213170949

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-269274102

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-269274102

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-32848

Open SourceCoalition ESS < 30%HIGH2023-12-04

In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896; Issue ID: ALPS081...

CVEs:CVE-2023-32848

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-302982513

GoogleCoalition ESS < 30%2023-12-01

ASB-A-302982513

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-42751

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In gnss service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42751

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42726

Open SourceCoalition ESS < 30%HIGH2023-12-04

In TeleService, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42726

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42727

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In gpu driver, there is a possible out of bounds write due to a incorrect bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42727

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42729

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42729

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42731

Open SourceCoalition ESS < 30%HIGH2023-12-04

In Gnss service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42731

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42725

Open SourceCoalition ESS < 30%HIGH2023-12-04

In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42725

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42684

Open SourceCoalition ESS < 30%HIGH2023-12-04

In gsp driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42684

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42679

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42679

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42680

Open SourceCoalition ESS < 30%HIGH2023-12-04

In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42680

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42682

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In gsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42682

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42683

Open SourceCoalition ESS < 30%HIGH2023-12-04

In gsp driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-42683

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42715

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42715

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42718

Open SourceCoalition ESS < 30%HIGH2023-12-04

In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42718

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48399

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is no...

CVEs:CVE-2023-48399

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48401

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

In GetSizeOfEenlRecords of protocoladapter.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2023-48401

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48408

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

In ProtocolNetSimFileInfoAdapter() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not need...

CVEs:CVE-2023-48408

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48411

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

In SignalStrengthAdapter::FillGsmSignalStrength() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interac...

CVEs:CVE-2023-48411

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48415

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

In Init of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48415

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48422

Open SourceCoalition ESS < 30%MEDIUM2023-12-06

In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48422

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42735

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

CVEs:CVE-2023-42735

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-291424409

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-291424409

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-295653694

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-295653694

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-296748229

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-296748229

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-299025883

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-299025883

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-300554928

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-300554928

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-300595972

GoogleCoalition ESS < 30%MEDIUM2023-12-01

PUB-A-300595972

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-42728

Open SourceCoalition ESS < 30%HIGH2023-12-04

In phasecheckserver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-42728

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42719

Open SourceCoalition ESS < 30%HIGH2023-12-04

In video service, there is a possible out of bounds read due to a incorrect bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-42719

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42720

Open SourceCoalition ESS < 30%HIGH2023-12-04

In video service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-42720

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42721

Open SourceCoalition ESS < 30%HIGH2023-12-04

In flv extractor, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-42721

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42723

Open SourceCoalition ESS < 30%HIGH2023-12-04

In camera service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-42723

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48462

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2022-48462

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48463

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2022-48463

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-48464

Open SourceCoalition ESS < 30%CRITICAL2023-12-04

In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2022-48464

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42685

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42685

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42686

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42686

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42687

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42687

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42688

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42688

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42689

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42690

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42690

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42691

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42691

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42692

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42692

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42693

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42693

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42694

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42694

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42695

Open SourceCoalition ESS < 30%HIGH2023-12-04

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42695

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42696

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42696

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42681

Open SourceCoalition ESS < 30%HIGH2023-12-04

In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42681

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48402

Open SourceCoalition ESS < 30%HIGH2023-12-06

In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48402

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42748

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42748

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42736

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42736

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42738

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42738

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42739

Open SourceCoalition ESS < 30%HIGH2023-12-04

In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42739

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42740

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42740

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42743

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42743

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42745

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42745

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42746

Open SourceCoalition ESS < 30%HIGH2023-12-04

In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42746

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42747

Open SourceCoalition ESS < 30%HIGH2023-12-04

In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVEs:CVE-2023-42747

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-244398863

GoogleCoalition ESS < 30%NONE2023-12-01

PUB-A-244398863

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-42730

Open SourceCoalition ESS < 30%HIGH2023-12-04

In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42730

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42732

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42732

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42733

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42733

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42734

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42734

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42705

Open SourceCoalition ESS < 30%HIGH2023-12-04

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42705

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42706

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42706

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42707

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42707

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42708

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42708

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42709

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42709

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42710

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42710

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42711

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42711

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42712

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42712

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42713

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42713

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42714

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42714

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42697

Open SourceCoalition ESS < 30%HIGH2023-12-04

In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42697

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42698

Open SourceCoalition ESS < 30%HIGH2023-12-04

In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42698

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42699

Open SourceCoalition ESS < 30%HIGH2023-12-04

In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42699

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42700

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42700

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42701

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42701

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42702

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42702

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42703

Open SourceCoalition ESS < 30%HIGH2023-12-04

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42703

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42704

Open SourceCoalition ESS < 30%HIGH2023-12-04

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42704

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42671

Open SourceCoalition ESS < 30%HIGH2023-12-04

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42671

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42672

Open SourceCoalition ESS < 30%HIGH2023-12-04

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42672

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42673

Open SourceCoalition ESS < 30%HIGH2023-12-04

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42673

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42674

Open SourceCoalition ESS < 30%HIGH2023-12-04

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42674

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42675

Open SourceCoalition ESS < 30%HIGH2023-12-04

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42675

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42676

Open SourceCoalition ESS < 30%HIGH2023-12-04

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42676

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42677

Open SourceCoalition ESS < 30%HIGH2023-12-04

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42677

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42678

Open SourceCoalition ESS < 30%HIGH2023-12-04

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42678

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42749

Open SourceCoalition ESS < 30%HIGH2023-12-04

In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42749

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42737

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42737

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42741

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-42741

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42742

Open SourceCoalition ESS < 30%HIGH2023-12-04

In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-42742

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-42744

Open SourceCoalition ESS < 30%HIGH2023-12-04

In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-42744

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-294770901

GoogleCoalition ESS < 30%2023-12-01

ASB-A-294770901

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-300368868

GoogleCoalition ESS < 30%2023-12-01

ASB-A-300368868

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-300368872

GoogleCoalition ESS < 30%2023-12-01

ASB-A-300368872

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-300368874

GoogleCoalition ESS < 30%2023-12-01

ASB-A-300368874

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-300368875

GoogleCoalition ESS < 30%2023-12-01

ASB-A-300368875

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-300382178

GoogleCoalition ESS < 30%2023-12-01

ASB-A-300382178

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-300385151

GoogleCoalition ESS < 30%2023-12-01

ASB-A-300385151

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48420

Open SourceCoalition ESS < 30%HIGH2023-12-06

there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-48420

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-269968522

GoogleCoalition ESS < 30%HIGH2023-12-01

PUB-A-269968522

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-285915779

GoogleEPSS <= 49%2023-12-01

PUB-A-285915779

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-285915800

GoogleEPSS <= 49%2023-12-01

PUB-A-285915800

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-276762552

GoogleEPSS <= 49%2023-12-01

PUB-A-276762552

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-283319108

GoogleEPSS <= 49%2023-12-01

PUB-A-283319108

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-297030670

GoogleEPSS <= 49%MEDIUM2023-12-01

PUB-A-297030670

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-7ww5-4wqc-m92c

GoogleAll remainingNONE2023-12-19

containerd allows RAPL to be accessible to a container

Affected products

ProductStatusVendorPackageEcosystem
containerd/containerd affected github.com github.com/containerd/containerd
Upstream advisory

GHSA-7ww5-4wqc-m92c

Open SourceAll remainingNONE2023-12-19

containerd allows RAPL to be accessible to a container

Affected products

ProductStatusVendorPackageEcosystem
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
cert-manager-1.11 affected chainguard cert-manager-1.11
cert-manager-1.11 affected wolfi cert-manager-1.11
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-1.13 affected wolfi cert-manager-1.13
cert-manager-fips-1.12 affected chainguard cert-manager-fips-1.12
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
containerd/containerd affected github.com github.com/containerd/containerd
containerd/containerd affected github.com github.com/containerd/containerd
ctop affected chainguard ctop
ctop affected wolfi ctop
eksctl affected wolfi eksctl
eksctl affected chainguard eksctl
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller-0 affected chainguard flux-helm-controller-0
flux-helm-controller-0.37 affected chainguard flux-helm-controller-0.37
flux-helm-controller-2.0 affected chainguard flux-helm-controller-2.0
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller-0 affected chainguard flux-source-controller-0
flux-source-controller-0.37 affected chainguard flux-source-controller-0.37
flux-source-controller-2.0 affected chainguard flux-source-controller-2.0
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
github.com/containerd/containerd affected Go github.com/containerd/containerd
gitness affected wolfi gitness
gitness affected chainguard gitness
grype affected wolfi grype
grype affected chainguard grype
helm affected wolfi helm
helm affected chainguard helm
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
k3d affected chainguard k3d
k3d affected wolfi k3d
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
kots affected wolfi kots
kots affected chainguard kots
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
melange affected wolfi melange
melange affected chainguard melange
neuvector-agent affected wolfi neuvector-agent
neuvector-agent affected chainguard neuvector-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
rancher-agent-2.8 affected chainguard rancher-agent-2.8
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
tekton-pipelines affected chainguard tekton-pipelines
tekton-pipelines affected wolfi tekton-pipelines
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.26 affected wolfi telegraf-1.26
telegraf-1.27 affected chainguard telegraf-1.27
telegraf-1.27 affected wolfi telegraf-1.27
telegraf-1.28 affected wolfi telegraf-1.28
telegraf-1.28 affected chainguard telegraf-1.28
telegraf-1.29 affected chainguard telegraf-1.29
telegraf-1.29 affected wolfi telegraf-1.29
trivy affected wolfi trivy
trivy affected chainguard trivy
up affected chainguard up
up affected wolfi up
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.