Advisories
Open SourceExploitedCISA KEV listedHIGH2024-01-23
Security Beta update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-boynux-squid_exporter |
affected |
SUSE:Manager Client Tools 12-BETA |
golang-github-boynux-squid_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Client Tools 12-BETA |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-prometheus-alertmanager |
affected |
SUSE:Manager Client Tools 12-BETA |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-node_exporter |
affected |
SUSE:Manager Client Tools 12-BETA |
golang-github-prometheus-node_exporter |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 12-BETA |
golang-github-prometheus-prometheus |
— |
| golang-github-prometheus-promu |
affected |
SUSE:Manager Client Tools 12-BETA |
golang-github-prometheus-promu |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Client Tools 12-BETA |
golang-github-QubitProducts-exporter_exporter |
— |
| grafana |
affected |
SUSE:Manager Client Tools 12-BETA |
grafana |
— |
| kiwi-desc-saltboot |
affected |
SUSE:Manager Client Tools 12-BETA |
kiwi-desc-saltboot |
— |
| mgr-push |
affected |
SUSE:Manager Client Tools 12-BETA |
mgr-push |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Client Tools 12-BETA |
prometheus-blackbox_exporter |
— |
| prometheus-postgres_exporter |
affected |
SUSE:Manager Client Tools 12-BETA |
prometheus-postgres_exporter |
— |
| python-hwdata |
affected |
SUSE:Manager Client Tools 12-BETA |
python-hwdata |
— |
| rhnlib |
affected |
SUSE:Manager Client Tools 12-BETA |
rhnlib |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 12-BETA |
spacecmd |
— |
| supportutils-plugin-salt |
affected |
SUSE:Manager Client Tools 12-BETA |
supportutils-plugin-salt |
— |
| supportutils-plugin-susemanager-client |
affected |
SUSE:Manager Client Tools 12-BETA |
supportutils-plugin-susemanager-client |
— |
| system-user-grafana |
affected |
SUSE:Manager Client Tools 12-BETA |
system-user-grafana |
— |
| system-user-prometheus |
affected |
SUSE:Manager Client Tools 12-BETA |
system-user-prometheus |
— |
| uyuni-common-libs |
affected |
SUSE:Manager Client Tools 12-BETA |
uyuni-common-libs |
— |
Open SourceExploitedCISA KEV listedMEDIUM2024-01-23
Security Beta update for SUSE Manager Client Tools and Salt
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ansible |
affected |
SUSE:Manager Client Tools 15-BETA |
ansible |
— |
| dracut-saltboot |
affected |
SUSE:Manager Client Tools Beta for SLE Micro 5 |
dracut-saltboot |
— |
| dracut-saltboot |
affected |
SUSE:Manager Client Tools 15-BETA |
dracut-saltboot |
— |
| golang-github-boynux-squid_exporter |
affected |
SUSE:Manager Client Tools 15-BETA |
golang-github-boynux-squid_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Client Tools 15-BETA |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 15-BETA |
golang-github-prometheus-prometheus |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Client Tools 15-BETA |
golang-github-QubitProducts-exporter_exporter |
— |
| golang-github-QubitProducts-exporter_exporter |
affected |
SUSE:Manager Client Tools Beta for SLE Micro 5 |
golang-github-QubitProducts-exporter_exporter |
— |
| grafana |
affected |
SUSE:Manager Client Tools 15-BETA |
grafana |
— |
| mgr-push |
affected |
SUSE:Manager Client Tools 15-BETA |
mgr-push |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Client Tools 15-BETA |
prometheus-blackbox_exporter |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Client Tools Beta for SLE Micro 5 |
prometheus-blackbox_exporter |
— |
| prometheus-postgres_exporter |
affected |
SUSE:Manager Client Tools 15-BETA |
prometheus-postgres_exporter |
— |
| python-hwdata |
affected |
SUSE:Manager Client Tools 15-BETA |
python-hwdata |
— |
| python-pyvmomi |
affected |
SUSE:Manager Client Tools 15-BETA |
python-pyvmomi |
— |
| rhnlib |
affected |
SUSE:Manager Client Tools 15-BETA |
rhnlib |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 15-BETA |
spacecmd |
— |
| spacewalk-client-tools |
affected |
SUSE:Manager Client Tools 15-BETA |
spacewalk-client-tools |
— |
| supportutils-plugin-salt |
affected |
SUSE:Manager Client Tools 15-BETA |
supportutils-plugin-salt |
— |
| supportutils-plugin-susemanager-client |
affected |
SUSE:Manager Client Tools 15-BETA |
supportutils-plugin-susemanager-client |
— |
| uyuni-common-libs |
affected |
SUSE:Manager Client Tools 15-BETA |
uyuni-common-libs |
— |
| uyuni-proxy-systemd-services |
affected |
SUSE:Manager Client Tools 15-BETA |
uyuni-proxy-systemd-services |
— |
| uyuni-proxy-systemd-services |
affected |
SUSE:Manager Client Tools Beta for SLE Micro 5 |
uyuni-proxy-systemd-services |
— |
Open SourceExploitedCISA KEV listedCRITICAL2024-01-16
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourceExploitedCISA KEV listedCRITICAL2024-01-25
Updated chromium-browser-stable packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:9 |
chromium-browser-stable |
— |
Open SourceExploitedCISA KEV listedCRITICAL2024-01-18
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP5 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.5 |
chromium |
— |
Open SourceExploitedCISA KEV listed2024-01-17
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceExploitedCISA KEV listedHIGH2024-01-31
runc vulnerable to container breakout through process.cwd trickery and leaked fds
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| cadvisor |
affected |
chainguard |
cadvisor |
— |
| cadvisor |
affected |
wolfi |
cadvisor |
— |
| ctop |
affected |
chainguard |
ctop |
— |
| ctop |
affected |
wolfi |
ctop |
— |
| datadog-agent |
affected |
chainguard |
datadog-agent |
— |
| datadog-agent |
affected |
wolfi |
datadog-agent |
— |
| datadog-agent-fips |
affected |
chainguard |
datadog-agent-fips |
— |
| docker |
affected |
wolfi |
docker |
— |
| docker |
affected |
chainguard |
docker |
— |
| grype |
affected |
wolfi |
grype |
— |
| grype |
affected |
chainguard |
grype |
— |
| ingress-nginx-controller |
affected |
chainguard |
ingress-nginx-controller |
— |
| ingress-nginx-controller |
affected |
wolfi |
ingress-nginx-controller |
— |
| ingress-nginx-controller-fips |
affected |
chainguard |
ingress-nginx-controller-fips |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| k9s |
affected |
wolfi |
k9s |
— |
| k9s |
affected |
chainguard |
k9s |
— |
| kaniko |
affected |
chainguard |
kaniko |
— |
| kaniko |
affected |
wolfi |
kaniko |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kots-compat |
affected |
chainguard |
kots-compat |
— |
| kubernetes-1.28 |
affected |
chainguard |
kubernetes-1.28 |
— |
| kubernetes-1.28 |
affected |
wolfi |
kubernetes-1.28 |
— |
| kubernetes-1.29 |
affected |
chainguard |
kubernetes-1.29 |
— |
| kubernetes-1.29 |
affected |
wolfi |
kubernetes-1.29 |
— |
| kubernetes-fips-1.27 |
affected |
chainguard |
kubernetes-fips-1.27 |
— |
| kubernetes-fips-1.28 |
affected |
chainguard |
kubernetes-fips-1.28 |
— |
| kubernetes-fips-1.29 |
affected |
chainguard |
kubernetes-fips-1.29 |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| nerdctl |
affected |
chainguard |
nerdctl |
— |
| nerdctl |
affected |
wolfi |
nerdctl |
— |
| newrelic-infrastructure-agent |
affected |
wolfi |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent |
affected |
chainguard |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent-1.43 |
affected |
chainguard |
newrelic-infrastructure-agent-1.43 |
— |
| opencontainers/runc |
affected |
github.com |
github.com/opencontainers/runc |
— |
| podman |
affected |
wolfi |
podman |
— |
| podman |
affected |
chainguard |
podman |
— |
| podman-fips |
affected |
chainguard |
podman-fips |
— |
| runc |
affected |
wolfi |
runc |
— |
| runc |
affected |
chainguard |
runc |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| skopeo |
affected |
chainguard |
skopeo |
— |
| skopeo |
affected |
wolfi |
skopeo |
— |
| syft |
affected |
chainguard |
syft |
— |
| syft |
affected |
wolfi |
syft |
— |
| telegraf-1.26 |
affected |
wolfi |
telegraf-1.26 |
— |
| telegraf-1.26 |
affected |
chainguard |
telegraf-1.26 |
— |
| telegraf-1.27 |
affected |
wolfi |
telegraf-1.27 |
— |
| telegraf-1.27 |
affected |
chainguard |
telegraf-1.27 |
— |
| telegraf-1.28 |
affected |
wolfi |
telegraf-1.28 |
— |
| telegraf-1.28 |
affected |
chainguard |
telegraf-1.28 |
— |
| trivy |
affected |
wolfi |
trivy |
— |
| trivy |
affected |
chainguard |
trivy |
— |
| wolfictl |
affected |
wolfi |
wolfictl |
— |
| wolfictl |
affected |
chainguard |
wolfictl |
— |
| zarf |
affected |
chainguard |
zarf |
— |
| zarf |
affected |
wolfi |
zarf |
— |
| zot |
affected |
chainguard |
zot |
— |
| zot |
affected |
wolfi |
zot |
— |
GoogleExploitedCISA KEV listedHIGH2024-01-31
runc vulnerable to container breakout through process.cwd trickery and leaked fds
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| opencontainers/runc |
affected |
github.com |
github.com/opencontainers/runc |
— |
Open SourceExploitedCISA KEV listedHIGH2024-01-31
CVE-2024-21626 affecting package kubernetes for versions less than 1.28.4-3
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Azure Linux:2 |
kubernetes |
— |
Open SourceExploitedCISA KEV listedHIGH2024-01-31
CVE-2024-21626 affecting package kubernetes for versions less than 1.30.1-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Azure Linux:3 |
kubernetes |
— |
GoogleExploitedCISA KEV listedHIGH2024-01-16
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0519
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| couchbase_server |
affected |
couchbase |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleExploitedCISA KEV listedHIGH2024-01-16
CVEs:CVE-2024-0519
GoogleExploitedCISA KEV listed2024-01-16
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0519
Open SourceExploitedCISA KEV listedHIGH2024-01-16
DEBIAN-CVE-2024-0519
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Project ZeroExploitedCISA KEV listed2024-01-16
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0519
Open SourceWeaponized exploitMEDIUM2024-01-24
DEBIAN-CVE-2024-0811
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceWeaponized exploit2024-01-24
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
GoogleWeaponized exploitMEDIUM2024-01-23
Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
CVEs:CVE-2024-0811
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleWeaponized exploitMEDIUM2024-01-23
CVEs:CVE-2024-0811
GoogleWeaponized exploit2024-01-23
Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
CVEs:CVE-2024-0811
GoogleWeaponized exploit2024-01-01
ASB-A-308188337
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleWeaponized exploitCRITICAL2024-01-02
CVEs:CVE-2023-48418
GoogleWeaponized exploitCRITICAL2024-01-02
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a
possible way to access adb before SUW completion due to an insecure default
value. This could lead to local escalation of privilege with no additional
execution pri...
CVEs:CVE-2023-48418
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| pixel_watch_firmware |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-25
CVEs:CVE-2024-21388
Open SourceActive exploitation (sightings)CRITICAL2024-01-09
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2024-21388
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-16
DEBIAN-CVE-2024-0517
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2024-01-16
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0517
GoogleActive exploitation (sightings)HIGH2024-01-16
CVEs:CVE-2024-0517
GoogleActive exploitation (sightings)CRITICAL2024-01-16
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0517
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)CRITICAL2024-01-25
CVEs:CVE-2024-21326
Open SourceActive exploitation (sightings)CRITICAL2024-01-09
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2024-21326
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-01-25
CVEs:CVE-2024-21385
Open SourceActive exploitation (sightings)CRITICAL2024-01-09
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2024-21385
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-30
DEBIAN-CVE-2024-1059
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2024-01-30
CVEs:CVE-2024-1059
GoogleActive exploitation (sightings)CRITICAL2024-01-30
Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1059
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-16
DEBIAN-CVE-2024-0518
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2024-01-16
CVEs:CVE-2024-0518
GoogleActive exploitation (sightings)2024-01-16
Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0518
GoogleActive exploitation (sightings)HIGH2024-01-16
Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0518
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-30
DEBIAN-CVE-2024-1077
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2024-01-30
Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
CVEs:CVE-2024-1077
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-01-30
CVEs:CVE-2024-1077
GoogleActive exploitation (sightings)MEDIUM2024-01-25
CVEs:CVE-2024-21382
Open SourceActive exploitation (sightings)HIGH2024-01-09
Microsoft Edge for Android Information Disclosure Vulnerability
CVEs:CVE-2024-21382
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-30
DEBIAN-CVE-2024-1060
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2024-01-30
CVEs:CVE-2024-1060
GoogleActive exploitation (sightings)CRITICAL2024-01-30
Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1060
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-01-09
Parsing JSON serialized payload without protected field can lead to segfault
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| lestrrat-go/jwx |
affected |
github.com |
github.com/lestrrat-go/jwx |
— |
| lestrrat-go/jwx/v2 |
affected |
github.com |
github.com/lestrrat-go/jwx/v2 |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-09
Parsing JSON serialized payload without protected field can lead to segfault
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| boring-registry |
affected |
wolfi |
boring-registry |
— |
| boring-registry |
affected |
chainguard |
boring-registry |
— |
| cosign-fips |
affected |
wolfi |
cosign-fips |
— |
| cosign-fips |
affected |
chainguard |
cosign-fips |
— |
| external-secrets-0.7 |
affected |
chainguard |
external-secrets-0.7 |
— |
| external-secrets-fips |
affected |
chainguard |
external-secrets-fips |
— |
| external-secrets-operator |
affected |
wolfi |
external-secrets-operator |
— |
| external-secrets-operator |
affected |
chainguard |
external-secrets-operator |
— |
| falco |
affected |
wolfi |
falco |
— |
| falco |
affected |
chainguard |
falco |
— |
| falcoctl |
affected |
chainguard |
falcoctl |
— |
| falcoctl |
affected |
wolfi |
falcoctl |
— |
| falcoctl-fips |
affected |
chainguard |
falcoctl-fips |
— |
| gitsign |
affected |
chainguard |
gitsign |
— |
| gitsign |
affected |
wolfi |
gitsign |
— |
| istio-cni-1.19 |
affected |
chainguard |
istio-cni-1.19 |
— |
| istio-cni-1.19 |
affected |
wolfi |
istio-cni-1.19 |
— |
| istio-cni-1.20 |
affected |
wolfi |
istio-cni-1.20 |
— |
| istio-cni-1.20 |
affected |
chainguard |
istio-cni-1.20 |
— |
| istio-cni-fips-1.19 |
affected |
chainguard |
istio-cni-fips-1.19 |
— |
| istio-operator-1.19 |
affected |
wolfi |
istio-operator-1.19 |
— |
| istio-operator-1.19 |
affected |
chainguard |
istio-operator-1.19 |
— |
| istio-operator-1.20 |
affected |
chainguard |
istio-operator-1.20 |
— |
| istio-operator-1.20 |
affected |
wolfi |
istio-operator-1.20 |
— |
| istio-operator-fips-1.19 |
affected |
chainguard |
istio-operator-fips-1.19 |
— |
| istio-pilot-agent-1.18 |
affected |
wolfi |
istio-pilot-agent-1.18 |
— |
| istio-pilot-agent-1.18 |
affected |
chainguard |
istio-pilot-agent-1.18 |
— |
| istio-pilot-agent-1.19 |
affected |
wolfi |
istio-pilot-agent-1.19 |
— |
| istio-pilot-agent-1.19 |
affected |
chainguard |
istio-pilot-agent-1.19 |
— |
| istio-pilot-agent-1.20 |
affected |
wolfi |
istio-pilot-agent-1.20 |
— |
| istio-pilot-agent-1.20 |
affected |
chainguard |
istio-pilot-agent-1.20 |
— |
| istio-pilot-agent-fips-1.19 |
affected |
chainguard |
istio-pilot-agent-fips-1.19 |
— |
| istio-pilot-discovery-1.18 |
affected |
chainguard |
istio-pilot-discovery-1.18 |
— |
| istio-pilot-discovery-1.18 |
affected |
wolfi |
istio-pilot-discovery-1.18 |
— |
| istio-pilot-discovery-1.19 |
affected |
wolfi |
istio-pilot-discovery-1.19 |
— |
| istio-pilot-discovery-1.19 |
affected |
chainguard |
istio-pilot-discovery-1.19 |
— |
| istio-pilot-discovery-1.20 |
affected |
chainguard |
istio-pilot-discovery-1.20 |
— |
| istio-pilot-discovery-1.20 |
affected |
wolfi |
istio-pilot-discovery-1.20 |
— |
| istio-pilot-discovery-fips-1.19 |
affected |
chainguard |
istio-pilot-discovery-fips-1.19 |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kyverno |
affected |
chainguard |
kyverno |
— |
| kyverno |
affected |
wolfi |
kyverno |
— |
| lestrrat-go/jwx |
affected |
github.com |
github.com/lestrrat-go/jwx |
— |
| lestrrat-go/jwx/v2 |
affected |
github.com |
github.com/lestrrat-go/jwx/v2 |
— |
| mc |
affected |
chainguard |
mc |
— |
| mc |
affected |
wolfi |
mc |
— |
| minio |
affected |
wolfi |
minio |
— |
| minio |
affected |
chainguard |
minio |
— |
| spire-server |
affected |
chainguard |
spire-server |
— |
| spire-server |
affected |
wolfi |
spire-server |
— |
| spire-server-fips |
affected |
chainguard |
spire-server-fips |
— |
| tekton-chains |
affected |
wolfi |
tekton-chains |
— |
| tekton-chains |
affected |
chainguard |
tekton-chains |
— |
| vexctl |
affected |
wolfi |
vexctl |
— |
| vexctl |
affected |
chainguard |
vexctl |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-25
CVEs:CVE-2024-21387
Open SourceActive exploitation (sightings)MEDIUM2024-01-09
Microsoft Edge for Android Spoofing Vulnerability
CVEs:CVE-2024-21387
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-12
CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared memory, which leads to out-of-bounds read ...
CVEs:CVE-2024-21639
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium_embedded_framework |
affected |
chromiumembedded |
— |
— |
GoogleActive exploitation (sightings)2024-01-12
OOB Access in CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory
CVEs:CVE-2024-21639
GoogleActive exploitation (sightings)CRITICAL2024-01-08
CVEs:CVE-2023-6921
GoogleActive exploitation (sightings)CRITICAL2024-01-08
Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.
CVEs:CVE-2023-6921
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_integrator |
affected |
prestashow |
— |
— |
GoogleActive exploitation (sightings)2024-01-13
OOB Access in CefVideoConsumerOSR::OnFrameCaptured
CVEs:CVE-2024-21640
Open SourceActive exploitation (sightings)CRITICAL2024-01-13
Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.`CefVideoConsumerOSR::OnFrameCaptured` does not check `pixel_format` properly, which leads to out-of-bounds read out of the sandbox. Thi...
CVEs:CVE-2024-21640
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium_embedded_framework |
affected |
chromiumembedded |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-24
DEBIAN-CVE-2024-0808
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2024-01-23
CVEs:CVE-2024-0808
GoogleActive exploitation (sightings)2024-01-23
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
CVEs:CVE-2024-0808
GoogleActive exploitation (sightings)CRITICAL2024-01-23
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
CVEs:CVE-2024-0808
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-24
DEBIAN-CVE-2024-0804
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2024-01-23
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-0804
GoogleActive exploitation (sightings)CRITICAL2024-01-23
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-0804
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-01-23
CVEs:CVE-2024-0804
Open SourceActive exploitation (sightings)HIGH2024-01-24
DEBIAN-CVE-2024-0812
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2024-01-23
Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0812
GoogleActive exploitation (sightings)HIGH2024-01-23
CVEs:CVE-2024-0812
GoogleActive exploitation (sightings)HIGH2024-01-23
Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0812
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-24
DEBIAN-CVE-2024-0807
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2024-01-23
Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0807
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)2024-01-23
Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0807
GoogleActive exploitation (sightings)HIGH2024-01-23
CVEs:CVE-2024-0807
Open SourceActive exploitation (sightings)CRITICAL2024-01-24
DEBIAN-CVE-2024-0806
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2024-01-23
Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
CVEs:CVE-2024-0806
GoogleActive exploitation (sightings)HIGH2024-01-23
CVEs:CVE-2024-0806
GoogleActive exploitation (sightings)CRITICAL2024-01-23
Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
CVEs:CVE-2024-0806
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)2024-01-23
Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-3172
GoogleActive exploitation (sightings)CRITICAL2024-01-23
Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-3172
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-01-23
CVEs:CVE-2024-3172
GoogleActive exploitation (sightings)HIGH2024-01-02
CVEs:CVE-2023-32889
Open SourceActive exploitation (sightings)HIGH2024-01-02
In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY0116...
CVEs:CVE-2023-32889
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-01-24
DEBIAN-CVE-2024-0809
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2024-01-23
Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2024-0809
GoogleActive exploitation (sightings)MEDIUM2024-01-23
Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2024-0809
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-23
CVEs:CVE-2024-0809
GoogleActive exploitation (sightings)LOW2024-01-25
CVEs:CVE-2024-21383
Open SourceActive exploitation (sightings)LOW2024-01-09
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2024-21383
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-01-24
DEBIAN-CVE-2024-0805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-23
Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
CVEs:CVE-2024-0805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)2024-01-23
Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
CVEs:CVE-2024-0805
GoogleActive exploitation (sightings)MEDIUM2024-01-23
CVEs:CVE-2024-0805
Open SourceActive exploitation (sightings)HIGH2024-01-24
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apache-airflow |
affected |
PyPI |
apache-airflow |
— |
| apache-airflow |
affected |
PyPI |
apache-airflow |
— |
| apache-airflow-providers-cncf-kubernetes |
affected |
PyPI |
apache-airflow-providers-cncf-kubernetes |
— |
| apache-airflow-providers-cncf-kubernetes |
affected |
PyPI |
apache-airflow-providers-cncf-kubernetes |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-24
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apache-airflow |
affected |
PyPI |
apache-airflow |
— |
| apache-airflow-providers-cncf-kubernetes |
affected |
PyPI |
apache-airflow-providers-cncf-kubernetes |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-24
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without a...
CVEs:CVE-2023-51702
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| airflow |
affected |
apache |
— |
— |
| airflow_cncf_kubernetes |
affected |
apache |
— |
— |
| apache-airflow-providers-cncf-kubernetes |
affected |
apache |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-01-24
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
CVEs:CVE-2023-51702
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apache-airflow |
affected |
PyPI |
apache-airflow |
— |
| apache-airflow-providers-cncf-kubernetes |
affected |
PyPI |
apache-airflow-providers-cncf-kubernetes |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-24
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
CVEs:CVE-2023-51702
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apache-airflow |
affected |
PyPI |
apache-airflow |
— |
| apache-airflow-providers-cncf-kubernetes |
affected |
PyPI |
apache-airflow-providers-cncf-kubernetes |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-24
DEBIAN-CVE-2024-0813
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2024-01-23
CVEs:CVE-2024-0813
GoogleActive exploitation (sightings)2024-01-23
Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
CVEs:CVE-2024-0813
GoogleActive exploitation (sightings)CRITICAL2024-01-23
Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
CVEs:CVE-2024-0813
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-24
DEBIAN-CVE-2024-0810
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-23
CVEs:CVE-2024-0810
GoogleActive exploitation (sightings)CRITICAL2024-01-23
Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)
CVEs:CVE-2024-0810
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)2024-01-23
Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)
CVEs:CVE-2024-0810
GoogleActive exploitation (sightings)CRITICAL2024-01-30
Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-3169
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-01-30
CVEs:CVE-2024-3169
Open SourceActive exploitation (sightings)MEDIUM2024-01-24
DEBIAN-CVE-2024-0814
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2024-01-23
Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-0814
GoogleActive exploitation (sightings)MEDIUM2024-01-23
CVEs:CVE-2024-0814
GoogleActive exploitation (sightings)MEDIUM2024-01-23
Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-0814
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-08
CVEs:CVE-2023-52198
GoogleActive exploitation (sightings)CRITICAL2024-01-08
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125.
CVEs:CVE-2023-52198
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| private_google_calendars |
affected |
michielvaneerd |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-01-03
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
CVEs:CVE-2024-20803
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-03
CVEs:CVE-2024-20803
GoogleActive exploitation (sightings)2024-01-30
Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-2884
GoogleActive exploitation (sightings)MEDIUM2024-01-30
Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-2884
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-30
CVEs:CVE-2024-2884
GoogleActive exploitation (sightings)CRITICAL2024-01-02
CVEs:CVE-2023-48419
GoogleActive exploitation (sightings)CRITICAL2024-01-02
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
CVEs:CVE-2023-48419
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| home_firmware |
affected |
google |
— |
— |
| home_mini_firmware |
affected |
google |
— |
— |
| nest_audio_firmware |
affected |
google |
— |
— |
| nest_mini_firmware |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-03
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
CVEs:CVE-2024-20805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
| myfiles |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)LOW2024-01-03
CVEs:CVE-2024-20805
GoogleActive exploitation (sightings)CRITICAL2024-01-02
CVEs:CVE-2023-6339
GoogleActive exploitation (sightings)CRITICAL2024-01-02
Google Nest WiFi Pro root code-execution & user-data compromise
CVEs:CVE-2023-6339
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| nest_wifi_pro_firmware |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-03
CVEs:CVE-2024-20806
Open SourceActive exploitation (sightings)MEDIUM2024-01-03
Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.
CVEs:CVE-2024-20806
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32882
Open SourceActive exploitation (sightings)HIGH2024-01-02
In battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID...
CVEs:CVE-2023-32882
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32878
Open SourceActive exploitation (sightings)MEDIUM2024-01-02
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issu...
CVEs:CVE-2023-32878
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32883
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32884
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32885
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32891
Open SourceActive exploitation (sightings)HIGH2024-01-02
In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS079...
CVEs:CVE-2023-32891
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| lr13 |
affected |
mediatek |
— |
— |
| nr15 |
affected |
mediatek |
— |
— |
| nr16 |
affected |
mediatek |
— |
— |
| nr17 |
affected |
mediatek |
— |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-02
In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780685; Issu...
CVEs:CVE-2023-32885
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-01-02
In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944011...
CVEs:CVE-2023-32884
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-02
In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08282249; ...
CVEs:CVE-2023-32883
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32879
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32875
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32877
Open SourceActive exploitation (sightings)HIGH2024-01-02
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ...
CVEs:CVE-2023-32879
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-02
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ...
CVEs:CVE-2023-32877
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-01-02
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; I...
CVEs:CVE-2023-32875
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32876
Open SourceActive exploitation (sightings)MEDIUM2024-01-02
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308612; I...
CVEs:CVE-2023-32876
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32880
GoogleActive exploitation (sightings)MEDIUM2024-01-02
CVEs:CVE-2023-32881
Open SourceActive exploitation (sightings)HIGH2024-01-02
In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue I...
CVEs:CVE-2023-32881
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-01-02
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issu...
CVEs:CVE-2023-32880
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-18
CVEs:CVE-2023-48353
Open SourceActive exploitation (sightings)CRITICAL2024-01-18
In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-48353
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-18
CVEs:CVE-2023-48354
GoogleActive exploitation (sightings)MEDIUM2024-01-18
CVEs:CVE-2023-48355
GoogleActive exploitation (sightings)MEDIUM2024-01-18
CVEs:CVE-2023-48357
GoogleActive exploitation (sightings)MEDIUM2024-01-18
CVEs:CVE-2023-48358
GoogleActive exploitation (sightings)MEDIUM2024-01-18
CVEs:CVE-2023-48339
Open SourceActive exploitation (sightings)CRITICAL2024-01-18
In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-48358
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-18
In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed
CVEs:CVE-2023-48354
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-18
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-48355
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-01-18
In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-48357
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-18
In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
CVEs:CVE-2023-48339
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-01-18
CVEs:CVE-2023-48345
GoogleActive exploitation (sightings)MEDIUM2024-01-18
CVEs:CVE-2023-48346
Open SourceActive exploitation (sightings)HIGH2024-01-18
In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48346
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2024-01-18
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48345
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2024-01-23
Path traversal and RCE in github.com/go-git/go-git/v5 and gopkg.in/src-d/go-git.v4
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| bom |
affected |
chainguard |
bom |
— |
| bom |
affected |
wolfi |
bom |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitsign |
affected |
wolfi |
gitsign |
— |
| gitsign |
affected |
chainguard |
gitsign |
— |
| go-git/go-git/v5 |
affected |
github.com |
github.com/go-git/go-git/v5 |
— |
| go-licenses |
affected |
chainguard |
go-licenses |
— |
| go-licenses |
affected |
wolfi |
go-licenses |
— |
| goreleaser |
affected |
chainguard |
goreleaser |
— |
| goreleaser |
affected |
wolfi |
goreleaser |
— |
| nuclei |
affected |
chainguard |
nuclei |
— |
| nuclei |
affected |
wolfi |
nuclei |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| scorecard |
affected |
chainguard |
scorecard |
— |
| scorecard |
affected |
wolfi |
scorecard |
— |
| src-d/go-git.v4 |
affected |
gopkg.in |
gopkg.in/src-d/go-git.v4 |
— |
| src-fingerprint |
affected |
wolfi |
src-fingerprint |
— |
| src-fingerprint |
affected |
chainguard |
src-fingerprint |
— |
Open SourcePoC exploitCRITICAL2024-01-12
DEBIAN-CVE-2023-49569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-go-git-go-git |
affected |
Debian:12 |
golang-github-go-git-go-git |
— |
| golang-github-go-git-go-git |
affected |
Debian:13 |
golang-github-go-git-go-git |
— |
| golang-github-go-git-go-git |
affected |
Debian:14 |
golang-github-go-git-go-git |
— |
Open SourcePoC exploitCRITICAL2024-01-10
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| bom |
affected |
wolfi |
bom |
— |
| bom |
affected |
chainguard |
bom |
— |
| flux-2.0 |
affected |
chainguard |
flux-2.0 |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gitsign |
affected |
chainguard |
gitsign |
— |
| gitsign |
affected |
wolfi |
gitsign |
— |
| go-git/go-git/v5 |
affected |
github.com |
github.com/go-git/go-git/v5 |
— |
| go-licenses |
affected |
chainguard |
go-licenses |
— |
| go-licenses |
affected |
wolfi |
go-licenses |
— |
| goreleaser |
affected |
chainguard |
goreleaser |
— |
| goreleaser |
affected |
wolfi |
goreleaser |
— |
| goreleaser-1.18 |
affected |
wolfi |
goreleaser-1.18 |
— |
| goreleaser-1.18 |
affected |
chainguard |
goreleaser-1.18 |
— |
| grafana-9 |
affected |
chainguard |
grafana-9 |
— |
| nuclei |
affected |
chainguard |
nuclei |
— |
| nuclei |
affected |
wolfi |
nuclei |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| scorecard |
affected |
wolfi |
scorecard |
— |
| scorecard |
affected |
chainguard |
scorecard |
— |
| src-d/go-git.v4 |
affected |
gopkg.in |
gopkg.in/src-d/go-git.v4 |
— |
| src-fingerprint |
affected |
wolfi |
src-fingerprint |
— |
| src-fingerprint |
affected |
chainguard |
src-fingerprint |
— |
GooglePoC exploitCRITICAL2024-01-10
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go-git/go-git/v5 |
affected |
github.com |
github.com/go-git/go-git/v5 |
— |
| src-d/go-git.v4 |
affected |
gopkg.in |
gopkg.in/src-d/go-git.v4 |
— |
Open SourcePoC exploitMEDIUM2024-01-11
Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the...
CVEs:CVE-2024-20721
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| acrobat |
affected |
adobe |
— |
— |
| edge_chromium |
affected |
microsoft |
— |
— |
GooglePoC exploitMEDIUM2024-01-11
CVEs:CVE-2024-20721
Open SourcePoC exploitHIGH2024-01-23
Denial of service in github.com/go-git/go-git/v5 and gopkg.in/src-d/go-git.v4
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| apko |
affected |
wolfi |
apko |
— |
| apko |
affected |
chainguard |
apko |
— |
| bom |
affected |
wolfi |
bom |
— |
| bom |
affected |
chainguard |
bom |
— |
| flux-kustomize-controller |
affected |
wolfi |
flux-kustomize-controller |
— |
| flux-kustomize-controller |
affected |
chainguard |
flux-kustomize-controller |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitsign |
affected |
chainguard |
gitsign |
— |
| gitsign |
affected |
wolfi |
gitsign |
— |
| go-git/go-git/v5 |
affected |
github.com |
github.com/go-git/go-git/v5 |
— |
| go-licenses |
affected |
chainguard |
go-licenses |
— |
| go-licenses |
affected |
wolfi |
go-licenses |
— |
| gomplate |
affected |
chainguard |
gomplate |
— |
| gomplate |
affected |
wolfi |
gomplate |
— |
| goreleaser |
affected |
wolfi |
goreleaser |
— |
| goreleaser |
affected |
chainguard |
goreleaser |
— |
| kots |
affected |
wolfi |
kots |
— |
| kots |
affected |
chainguard |
kots |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| nuclei |
affected |
chainguard |
nuclei |
— |
| nuclei |
affected |
wolfi |
nuclei |
— |
| pulumi |
affected |
wolfi |
pulumi |
— |
| pulumi |
affected |
chainguard |
pulumi |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| pulumi-language-dotnet |
affected |
wolfi |
pulumi-language-dotnet |
— |
| pulumi-language-dotnet |
affected |
chainguard |
pulumi-language-dotnet |
— |
| pulumi-language-java |
affected |
wolfi |
pulumi-language-java |
— |
| pulumi-language-java |
affected |
chainguard |
pulumi-language-java |
— |
| pulumi-language-yaml |
affected |
chainguard |
pulumi-language-yaml |
— |
| pulumi-language-yaml |
affected |
wolfi |
pulumi-language-yaml |
— |
| scorecard |
affected |
chainguard |
scorecard |
— |
| scorecard |
affected |
wolfi |
scorecard |
— |
| src-d/go-git.v4 |
affected |
gopkg.in |
gopkg.in/src-d/go-git.v4 |
— |
| src-fingerprint |
affected |
wolfi |
src-fingerprint |
— |
| src-fingerprint |
affected |
chainguard |
src-fingerprint |
— |
| zot |
affected |
wolfi |
zot |
— |
| zot |
affected |
chainguard |
zot |
— |
Open SourcePoC exploitCRITICAL2024-01-12
DEBIAN-CVE-2023-49568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-go-git-go-git |
affected |
Debian:12 |
golang-github-go-git-go-git |
— |
| golang-github-go-git-go-git |
affected |
Debian:13 |
golang-github-go-git-go-git |
— |
| golang-github-go-git-go-git |
affected |
Debian:14 |
golang-github-go-git-go-git |
— |
Open SourcePoC exploitHIGH2024-01-03
In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2024-0023
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2024-01-03
CVEs:CVE-2024-0023
GooglePoC exploitHIGH2024-01-03
CVEs:CVE-2024-0015
Open SourcePoC exploitHIGH2024-01-03
In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not ...
CVEs:CVE-2024-0015
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%2024-01-14
Updated chromium-browser-stable packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:9 |
chromium-browser-stable |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-01-04
DEBIAN-CVE-2024-0223
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%2024-01-04
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2024-01-03
CVEs:CVE-2024-0223
GoogleCoalition ESS < 30%CRITICAL2024-01-03
Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0223
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%HIGH2024-01-23
Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/kube-state-metrics |
affected |
github.com |
github.com/kubernetes/kube-state-metrics |
— |
| kube-state-metrics |
affected |
k8s.io |
k8s.io/kube-state-metrics |
— |
Open SourceCoalition ESS < 30%HIGH2024-01-23
Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes/kube-state-metrics |
affected |
github.com |
github.com/kubernetes/kube-state-metrics |
— |
| kube-state-metrics |
affected |
k8s.io |
k8s.io/kube-state-metrics |
— |
Open SourceCoalition ESS < 30%HIGH2024-01-10
DEBIAN-CVE-2023-49295
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-lucas-clemente-quic-go |
affected |
Debian:11 |
golang-github-lucas-clemente-quic-go |
— |
| golang-github-lucas-clemente-quic-go |
affected |
Debian:12 |
golang-github-lucas-clemente-quic-go |
— |
| golang-github-lucas-clemente-quic-go |
affected |
Debian:13 |
golang-github-lucas-clemente-quic-go |
— |
| golang-github-lucas-clemente-quic-go |
affected |
Debian:14 |
golang-github-lucas-clemente-quic-go |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-01-04
DEBIAN-CVE-2024-0222
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2024-01-03
CVEs:CVE-2024-0222
GoogleCoalition ESS < 30%CRITICAL2024-01-03
Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0222
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-309364195
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-01-04
DEBIAN-CVE-2024-0224
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2024-01-03
CVEs:CVE-2024-0224
GoogleCoalition ESS < 30%CRITICAL2024-01-03
Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0224
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-01-04
DEBIAN-CVE-2024-0225
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2024-01-03
CVEs:CVE-2024-0225
GoogleCoalition ESS < 30%CRITICAL2024-01-03
Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0225
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-11
CVEs:CVE-2024-20709
Open SourceCoalition ESS < 30%MEDIUM2024-01-11
Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the...
CVEs:CVE-2024-20709
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| acrobat |
affected |
adobe |
— |
— |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%LOW2024-01-25
CVEs:CVE-2024-21336
Open SourceCoalition ESS < 30%LOW2024-01-09
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2024-21336
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2024-01-16
The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ...
CVEs:CVE-2023-0094
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| upqode_google_maps |
affected |
qoders |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-16
CVEs:CVE-2023-0094
GoogleCoalition ESS < 30%MEDIUM2024-01-11
CVEs:CVE-2024-20675
Open SourceCoalition ESS < 30%MEDIUM2024-01-09
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVEs:CVE-2024-20675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2024-01-10
DEBIAN-CVE-2024-0333
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%2024-01-10
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-09
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-0333
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-09
CVEs:CVE-2024-0333
GoogleCoalition ESS < 30%MEDIUM2024-01-11
CVEs:CVE-2024-21337
Open SourceCoalition ESS < 30%CRITICAL2024-01-09
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2024-21337
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-09
CVEs:CVE-2023-36629
GoogleCoalition ESS < 30%2024-01-09
The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.
CVEs:CVE-2023-36629
Open SourceCoalition ESS < 30%MEDIUM2024-01-09
The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.
CVEs:CVE-2023-36629
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| st54-android-packages-apps-nfc |
affected |
st |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2024-01-25
Red Hat Security Advisory: protobuf-c security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf-c |
affected |
Red Hat:rhel_eus:8.6::appstream |
protobuf-c |
— |
| protobuf-c-compiler |
affected |
Red Hat:rhel_eus:8.6::appstream |
protobuf-c-compiler |
— |
| protobuf-c-compiler-debuginfo |
affected |
Red Hat:rhel_eus:8.6::appstream |
protobuf-c-compiler-debuginfo |
— |
| protobuf-c-debuginfo |
affected |
Red Hat:rhel_eus:8.6::appstream |
protobuf-c-debuginfo |
— |
| protobuf-c-debugsource |
affected |
Red Hat:rhel_eus:8.6::appstream |
protobuf-c-debugsource |
— |
| protobuf-c-devel |
affected |
Red Hat:rhel_eus:8.6::appstream |
protobuf-c-devel |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-275619408
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2024-0016
Open SourceCoalition ESS < 30%MEDIUM2024-01-03
In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-0016
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2024-20804
Open SourceCoalition ESS < 30%HIGH2024-01-03
Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
CVEs:CVE-2024-20804
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
| myfiles |
affected |
samsung |
— |
— |
GoogleCoalition ESS < 30%HIGH2024-01-03
CVEs:CVE-2024-0021
Open SourceCoalition ESS < 30%HIGH2024-01-03
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no addit...
CVEs:CVE-2024-0021
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2024-01-03
CVEs:CVE-2024-0018
Open SourceCoalition ESS < 30%HIGH2024-01-03
In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2024-0018
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-295908146
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
| vendor/qcom/opensource/graphics-kernel |
affected |
platform |
platform/vendor/qcom/opensource/graphics-kernel |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-303101495
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-303101624
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-303101664
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-303101067
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-303101456
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%2024-01-01
PUB-A-303107435
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2024-01-03
In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional exe...
CVEs:CVE-2024-0020
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2024-0020
Open SourceCoalition ESS < 30%MEDIUM2024-01-03
In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
CVEs:CVE-2024-0017
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2024-0017
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2024-0019
Open SourceCoalition ESS < 30%MEDIUM2024-01-03
In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional executio...
CVEs:CVE-2024-0019
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-02
CVEs:CVE-2023-32872
Open SourceCoalition ESS < 30%HIGH2024-01-02
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Iss...
CVEs:CVE-2023-32872
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-309367791
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%LOW2024-01-03
CVEs:CVE-2023-40085
Open SourceCoalition ESS < 30%MEDIUM2024-01-03
In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2023-40085
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2024-01-03
In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not nee...
CVEs:CVE-2023-21165
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2024-01-03
CVEs:CVE-2023-21165
GoogleCoalition ESS < 30%HIGH2024-01-01
ASB-A-292001469
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-01-03
In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-48342
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2023-48342
Open SourceCoalition ESS < 30%HIGH2024-01-02
There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional execution privileges needed.
CVEs:CVE-2023-4164
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2024-01-02
CVEs:CVE-2023-4164
GoogleCoalition ESS < 30%2024-01-01
ASB-A-311288747
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-311290653
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-18
CVEs:CVE-2023-48356
Open SourceCoalition ESS < 30%CRITICAL2024-01-18
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-48356
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-01-18
In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed
CVEs:CVE-2023-48359
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-18
CVEs:CVE-2023-48359
GoogleCoalition ESS < 30%MEDIUM2024-01-18
CVEs:CVE-2023-48347
Open SourceCoalition ESS < 30%HIGH2024-01-18
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48347
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-01-03
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48340
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2023-48340
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2023-48341
Open SourceCoalition ESS < 30%HIGH2024-01-03
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48341
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-01-03
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48343
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2023-48343
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2023-48344
Open SourceCoalition ESS < 30%HIGH2024-01-03
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48344
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-01-03
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48348
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2023-48348
Open SourceCoalition ESS < 30%CRITICAL2024-01-03
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48349
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2023-48349
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2023-48350
Open SourceCoalition ESS < 30%CRITICAL2024-01-03
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48350
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-01-03
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48351
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2023-48351
Open SourceCoalition ESS < 30%CRITICAL2024-01-03
In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVEs:CVE-2023-48352
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-01-03
CVEs:CVE-2023-48352
GoogleCoalition ESS < 30%2024-01-01
ASB-A-311273933
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-311273934
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-311279652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-311279655
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-311279656
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-311282174
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-311288752
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-311290655
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-01-01
ASB-A-303101147
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
Open SourceAll remaining2024-01-18
Timing side channel in github.com/cloudflare/circl
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aactl |
affected |
chainguard |
aactl |
— |
| aactl |
affected |
wolfi |
aactl |
— |
| actions-runner-controller |
affected |
chainguard |
actions-runner-controller |
— |
| actions-runner-controller |
affected |
wolfi |
actions-runner-controller |
— |
| apko |
affected |
chainguard |
apko |
— |
| apko |
affected |
wolfi |
apko |
— |
| argo-workflows |
affected |
chainguard |
argo-workflows |
— |
| argo-workflows |
affected |
wolfi |
argo-workflows |
— |
| boring-registry |
affected |
wolfi |
boring-registry |
— |
| boring-registry |
affected |
chainguard |
boring-registry |
— |
| cloudflare/circl |
affected |
github.com |
github.com/cloudflare/circl |
— |
| cosign |
affected |
wolfi |
cosign |
— |
| cosign |
affected |
chainguard |
cosign |
— |
| cosign-fips |
affected |
chainguard |
cosign-fips |
— |
| crossplane |
affected |
wolfi |
crossplane |
— |
| crossplane |
affected |
chainguard |
crossplane |
— |
| crossplane-provider-aws |
affected |
chainguard |
crossplane-provider-aws |
— |
| crossplane-provider-aws |
affected |
wolfi |
crossplane-provider-aws |
— |
| crossplane-provider-aws-cloudformation |
affected |
chainguard |
crossplane-provider-aws-cloudformation |
— |
| crossplane-provider-aws-cloudformation |
affected |
wolfi |
crossplane-provider-aws-cloudformation |
— |
| crossplane-provider-aws-cloudfront |
affected |
chainguard |
crossplane-provider-aws-cloudfront |
— |
| crossplane-provider-aws-cloudfront |
affected |
wolfi |
crossplane-provider-aws-cloudfront |
— |
| crossplane-provider-aws-cloudwatchlogs |
affected |
wolfi |
crossplane-provider-aws-cloudwatchlogs |
— |
| crossplane-provider-aws-cloudwatchlogs |
affected |
chainguard |
crossplane-provider-aws-cloudwatchlogs |
— |
| crossplane-provider-aws-dynamodb |
affected |
chainguard |
crossplane-provider-aws-dynamodb |
— |
| crossplane-provider-aws-dynamodb |
affected |
wolfi |
crossplane-provider-aws-dynamodb |
— |
| crossplane-provider-aws-ec2 |
affected |
wolfi |
crossplane-provider-aws-ec2 |
— |
| crossplane-provider-aws-ec2 |
affected |
chainguard |
crossplane-provider-aws-ec2 |
— |
| crossplane-provider-aws-eks |
affected |
chainguard |
crossplane-provider-aws-eks |
— |
| crossplane-provider-aws-eks |
affected |
wolfi |
crossplane-provider-aws-eks |
— |
| crossplane-provider-aws-elasticache |
affected |
chainguard |
crossplane-provider-aws-elasticache |
— |
| crossplane-provider-aws-elasticache |
affected |
wolfi |
crossplane-provider-aws-elasticache |
— |
| crossplane-provider-aws-firehose |
affected |
chainguard |
crossplane-provider-aws-firehose |
— |
| crossplane-provider-aws-firehose |
affected |
wolfi |
crossplane-provider-aws-firehose |
— |
| crossplane-provider-aws-iam |
affected |
wolfi |
crossplane-provider-aws-iam |
— |
| crossplane-provider-aws-iam |
affected |
chainguard |
crossplane-provider-aws-iam |
— |
| crossplane-provider-aws-kinesis |
affected |
wolfi |
crossplane-provider-aws-kinesis |
— |
| crossplane-provider-aws-kinesis |
affected |
chainguard |
crossplane-provider-aws-kinesis |
— |
| crossplane-provider-aws-kms |
affected |
wolfi |
crossplane-provider-aws-kms |
— |
| crossplane-provider-aws-kms |
affected |
chainguard |
crossplane-provider-aws-kms |
— |
| crossplane-provider-aws-lambda |
affected |
wolfi |
crossplane-provider-aws-lambda |
— |
| crossplane-provider-aws-lambda |
affected |
chainguard |
crossplane-provider-aws-lambda |
— |
| crossplane-provider-aws-memorydb |
affected |
chainguard |
crossplane-provider-aws-memorydb |
— |
| crossplane-provider-aws-memorydb |
affected |
wolfi |
crossplane-provider-aws-memorydb |
— |
| crossplane-provider-aws-rds |
affected |
chainguard |
crossplane-provider-aws-rds |
— |
| crossplane-provider-aws-rds |
affected |
wolfi |
crossplane-provider-aws-rds |
— |
| crossplane-provider-aws-route53 |
affected |
chainguard |
crossplane-provider-aws-route53 |
— |
| crossplane-provider-aws-route53 |
affected |
wolfi |
crossplane-provider-aws-route53 |
— |
| crossplane-provider-aws-s3 |
affected |
chainguard |
crossplane-provider-aws-s3 |
— |
| crossplane-provider-aws-s3 |
affected |
wolfi |
crossplane-provider-aws-s3 |
— |
| crossplane-provider-aws-sns |
affected |
wolfi |
crossplane-provider-aws-sns |
— |
| crossplane-provider-aws-sns |
affected |
chainguard |
crossplane-provider-aws-sns |
— |
| crossplane-provider-aws-sqs |
affected |
wolfi |
crossplane-provider-aws-sqs |
— |
| crossplane-provider-aws-sqs |
affected |
chainguard |
crossplane-provider-aws-sqs |
— |
| crossplane-provider-family-aws |
affected |
chainguard |
crossplane-provider-family-aws |
— |
| crossplane-provider-family-aws |
affected |
wolfi |
crossplane-provider-family-aws |
— |
| falcoctl-fips |
affected |
chainguard |
falcoctl-fips |
— |
| flux |
affected |
chainguard |
flux |
— |
| flux |
affected |
wolfi |
flux |
— |
| flux-image-automation-controller |
affected |
wolfi |
flux-image-automation-controller |
— |
| flux-image-automation-controller |
affected |
chainguard |
flux-image-automation-controller |
— |
| flux-kustomize-controller |
affected |
chainguard |
flux-kustomize-controller |
— |
| flux-kustomize-controller |
affected |
wolfi |
flux-kustomize-controller |
— |
| flux-notification-controller |
affected |
wolfi |
flux-notification-controller |
— |
| flux-notification-controller |
affected |
chainguard |
flux-notification-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gitsign |
affected |
wolfi |
gitsign |
— |
| gitsign |
affected |
chainguard |
gitsign |
— |
| gomplate |
affected |
chainguard |
gomplate |
— |
| gomplate |
affected |
wolfi |
gomplate |
— |
| goreleaser |
affected |
chainguard |
goreleaser |
— |
| goreleaser |
affected |
wolfi |
goreleaser |
— |
| grype |
affected |
wolfi |
grype |
— |
| grype |
affected |
chainguard |
grype |
— |
| kaniko |
affected |
chainguard |
kaniko |
— |
| kaniko |
affected |
wolfi |
kaniko |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| melange |
affected |
wolfi |
melange |
— |
| melange |
affected |
chainguard |
melange |
— |
| policy-controller |
affected |
chainguard |
policy-controller |
— |
| policy-controller |
affected |
wolfi |
policy-controller |
— |
| pulumi |
affected |
wolfi |
pulumi |
— |
| pulumi |
affected |
chainguard |
pulumi |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| pulumi-language-dotnet |
affected |
chainguard |
pulumi-language-dotnet |
— |
| pulumi-language-dotnet |
affected |
wolfi |
pulumi-language-dotnet |
— |
| pulumi-language-java |
affected |
chainguard |
pulumi-language-java |
— |
| pulumi-language-java |
affected |
wolfi |
pulumi-language-java |
— |
| pulumi-language-yaml |
affected |
chainguard |
pulumi-language-yaml |
— |
| pulumi-language-yaml |
affected |
wolfi |
pulumi-language-yaml |
— |
| rclone |
affected |
wolfi |
rclone |
— |
| rclone |
affected |
chainguard |
rclone |
— |
| scorecard |
affected |
wolfi |
scorecard |
— |
| scorecard |
affected |
chainguard |
scorecard |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| sops |
affected |
chainguard |
sops |
— |
| sops |
affected |
wolfi |
sops |
— |
| spire-server |
affected |
chainguard |
spire-server |
— |
| spire-server |
affected |
wolfi |
spire-server |
— |
| spire-server-fips |
affected |
chainguard |
spire-server-fips |
— |
| syft |
affected |
chainguard |
syft |
— |
| syft |
affected |
wolfi |
syft |
— |
| tekton-chains |
affected |
wolfi |
tekton-chains |
— |
| tekton-chains |
affected |
chainguard |
tekton-chains |
— |
| terraform-provider-google |
affected |
wolfi |
terraform-provider-google |
— |
| terraform-provider-google |
affected |
chainguard |
terraform-provider-google |
— |
| terragrunt |
affected |
chainguard |
terragrunt |
— |
| terragrunt |
affected |
wolfi |
terragrunt |
— |
| tkn |
affected |
wolfi |
tkn |
— |
| tkn |
affected |
chainguard |
tkn |
— |
| vexctl |
affected |
chainguard |
vexctl |
— |
| vexctl |
affected |
wolfi |
vexctl |
— |
| wolfictl |
affected |
chainguard |
wolfictl |
— |
| wolfictl |
affected |
wolfi |
wolfictl |
— |
| zarf |
affected |
wolfi |
zarf |
— |
| zarf |
affected |
chainguard |
zarf |
— |
| zot |
affected |
chainguard |
zot |
— |
| zot |
affected |
wolfi |
zot |
— |
GoogleAll remaining2024-01-08
CIRCL's Kyber: timing side-channel (kyberslash2)
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cloudflare/circl |
affected |
github.com |
github.com/cloudflare/circl |
— |
Open SourceAll remainingHIGH2024-01-08
CIRCL's Kyber: timing side-channel (kyberslash2)
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aactl |
affected |
chainguard |
aactl |
— |
| aactl |
affected |
wolfi |
aactl |
— |
| actions-runner-controller |
affected |
chainguard |
actions-runner-controller |
— |
| actions-runner-controller |
affected |
wolfi |
actions-runner-controller |
— |
| apko |
affected |
wolfi |
apko |
— |
| apko |
affected |
chainguard |
apko |
— |
| argo-cd-2.9 |
affected |
wolfi |
argo-cd-2.9 |
— |
| argo-cd-2.9 |
affected |
chainguard |
argo-cd-2.9 |
— |
| argo-workflows |
affected |
wolfi |
argo-workflows |
— |
| argo-workflows |
affected |
chainguard |
argo-workflows |
— |
| boring-registry |
affected |
chainguard |
boring-registry |
— |
| boring-registry |
affected |
wolfi |
boring-registry |
— |
| cloudflare/circl |
affected |
github.com |
github.com/cloudflare/circl |
— |
| cloudflare/circl |
affected |
github.com |
github.com/cloudflare/circl |
— |
| cloudflare/circl |
affected |
github.com |
— |
— |
| cosign |
affected |
wolfi |
cosign |
— |
| cosign |
affected |
chainguard |
cosign |
— |
| cosign-fips |
affected |
chainguard |
cosign-fips |
— |
| cosign-fips |
affected |
wolfi |
cosign-fips |
— |
| crossplane |
affected |
chainguard |
crossplane |
— |
| crossplane |
affected |
wolfi |
crossplane |
— |
| crossplane-provider-aws |
affected |
wolfi |
crossplane-provider-aws |
— |
| crossplane-provider-aws |
affected |
chainguard |
crossplane-provider-aws |
— |
| crossplane-provider-aws-cloudformation |
affected |
wolfi |
crossplane-provider-aws-cloudformation |
— |
| crossplane-provider-aws-cloudformation |
affected |
chainguard |
crossplane-provider-aws-cloudformation |
— |
| crossplane-provider-aws-cloudfront |
affected |
wolfi |
crossplane-provider-aws-cloudfront |
— |
| crossplane-provider-aws-cloudfront |
affected |
chainguard |
crossplane-provider-aws-cloudfront |
— |
| crossplane-provider-aws-cloudwatchlogs |
affected |
chainguard |
crossplane-provider-aws-cloudwatchlogs |
— |
| crossplane-provider-aws-cloudwatchlogs |
affected |
wolfi |
crossplane-provider-aws-cloudwatchlogs |
— |
| crossplane-provider-aws-dynamodb |
affected |
wolfi |
crossplane-provider-aws-dynamodb |
— |
| crossplane-provider-aws-dynamodb |
affected |
chainguard |
crossplane-provider-aws-dynamodb |
— |
| crossplane-provider-aws-ec2 |
affected |
wolfi |
crossplane-provider-aws-ec2 |
— |
| crossplane-provider-aws-ec2 |
affected |
chainguard |
crossplane-provider-aws-ec2 |
— |
| crossplane-provider-aws-eks |
affected |
chainguard |
crossplane-provider-aws-eks |
— |
| crossplane-provider-aws-eks |
affected |
wolfi |
crossplane-provider-aws-eks |
— |
| crossplane-provider-aws-elasticache |
affected |
chainguard |
crossplane-provider-aws-elasticache |
— |
| crossplane-provider-aws-elasticache |
affected |
wolfi |
crossplane-provider-aws-elasticache |
— |
| crossplane-provider-aws-firehose |
affected |
wolfi |
crossplane-provider-aws-firehose |
— |
| crossplane-provider-aws-firehose |
affected |
chainguard |
crossplane-provider-aws-firehose |
— |
| crossplane-provider-aws-iam |
affected |
wolfi |
crossplane-provider-aws-iam |
— |
| crossplane-provider-aws-iam |
affected |
chainguard |
crossplane-provider-aws-iam |
— |
| crossplane-provider-aws-kinesis |
affected |
wolfi |
crossplane-provider-aws-kinesis |
— |
| crossplane-provider-aws-kinesis |
affected |
chainguard |
crossplane-provider-aws-kinesis |
— |
| crossplane-provider-aws-kms |
affected |
chainguard |
crossplane-provider-aws-kms |
— |
| crossplane-provider-aws-kms |
affected |
wolfi |
crossplane-provider-aws-kms |
— |
| crossplane-provider-aws-lambda |
affected |
wolfi |
crossplane-provider-aws-lambda |
— |
| crossplane-provider-aws-lambda |
affected |
chainguard |
crossplane-provider-aws-lambda |
— |
| crossplane-provider-aws-memorydb |
affected |
chainguard |
crossplane-provider-aws-memorydb |
— |
| crossplane-provider-aws-memorydb |
affected |
wolfi |
crossplane-provider-aws-memorydb |
— |
| crossplane-provider-aws-rds |
affected |
wolfi |
crossplane-provider-aws-rds |
— |
| crossplane-provider-aws-rds |
affected |
chainguard |
crossplane-provider-aws-rds |
— |
| crossplane-provider-aws-route53 |
affected |
chainguard |
crossplane-provider-aws-route53 |
— |
| crossplane-provider-aws-route53 |
affected |
wolfi |
crossplane-provider-aws-route53 |
— |
| crossplane-provider-aws-s3 |
affected |
wolfi |
crossplane-provider-aws-s3 |
— |
| crossplane-provider-aws-s3 |
affected |
chainguard |
crossplane-provider-aws-s3 |
— |
| crossplane-provider-aws-sns |
affected |
wolfi |
crossplane-provider-aws-sns |
— |
| crossplane-provider-aws-sns |
affected |
chainguard |
crossplane-provider-aws-sns |
— |
| crossplane-provider-aws-sqs |
affected |
chainguard |
crossplane-provider-aws-sqs |
— |
| crossplane-provider-aws-sqs |
affected |
wolfi |
crossplane-provider-aws-sqs |
— |
| crossplane-provider-family-aws |
affected |
wolfi |
crossplane-provider-family-aws |
— |
| crossplane-provider-family-aws |
affected |
chainguard |
crossplane-provider-family-aws |
— |
| falco |
affected |
wolfi |
falco |
— |
| falco |
affected |
chainguard |
falco |
— |
| falcoctl-fips |
affected |
chainguard |
falcoctl-fips |
— |
| flux |
affected |
wolfi |
flux |
— |
| flux |
affected |
chainguard |
flux |
— |
| flux-0 |
affected |
chainguard |
flux-0 |
— |
| flux-0.37 |
affected |
chainguard |
flux-0.37 |
— |
| flux-2.0 |
affected |
chainguard |
flux-2.0 |
— |
| flux-image-automation-controller |
affected |
wolfi |
flux-image-automation-controller |
— |
| flux-image-automation-controller |
affected |
chainguard |
flux-image-automation-controller |
— |
| flux-image-automation-controller-0 |
affected |
chainguard |
flux-image-automation-controller-0 |
— |
| flux-kustomize-controller |
affected |
wolfi |
flux-kustomize-controller |
— |
| flux-kustomize-controller |
affected |
chainguard |
flux-kustomize-controller |
— |
| flux-kustomize-controller-2.0 |
affected |
chainguard |
flux-kustomize-controller-2.0 |
— |
| flux-notification-controller |
affected |
chainguard |
flux-notification-controller |
— |
| flux-notification-controller |
affected |
wolfi |
flux-notification-controller |
— |
| flux-notification-controller-0 |
affected |
chainguard |
flux-notification-controller-0 |
— |
| flux-notification-controller-2.0 |
affected |
chainguard |
flux-notification-controller-2.0 |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| flux-source-controller-0 |
affected |
chainguard |
flux-source-controller-0 |
— |
| flux-source-controller-0.37 |
affected |
chainguard |
flux-source-controller-0.37 |
— |
| flux-source-controller-2.0 |
affected |
chainguard |
flux-source-controller-2.0 |
— |
| github.com/cloudflare/circl |
affected |
Go |
github.com/cloudflare/circl |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| gitsign |
affected |
wolfi |
gitsign |
— |
| gitsign |
affected |
chainguard |
gitsign |
— |
| gomplate |
affected |
wolfi |
gomplate |
— |
| gomplate |
affected |
chainguard |
gomplate |
— |
| goreleaser |
affected |
chainguard |
goreleaser |
— |
| goreleaser |
affected |
wolfi |
goreleaser |
— |
| grafana |
affected |
chainguard |
grafana |
— |
| grafana |
affected |
wolfi |
grafana |
— |
| grafana-10.1 |
affected |
chainguard |
grafana-10.1 |
— |
| grafana-7 |
affected |
chainguard |
grafana-7 |
— |
| grafana-9.3 |
affected |
chainguard |
grafana-9.3 |
— |
| grype |
affected |
wolfi |
grype |
— |
| grype |
affected |
chainguard |
grype |
— |
| kaniko |
affected |
chainguard |
kaniko |
— |
| kaniko |
affected |
wolfi |
kaniko |
— |
| keda-2.11 |
affected |
chainguard |
keda-2.11 |
— |
| keda-2.11 |
affected |
wolfi |
keda-2.11 |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| melange |
affected |
chainguard |
melange |
— |
| melange |
affected |
wolfi |
melange |
— |
| opentofu |
affected |
wolfi |
opentofu |
— |
| opentofu |
affected |
chainguard |
opentofu |
— |
| opentofu-1.6 |
affected |
chainguard |
opentofu-1.6 |
— |
| policy-controller |
affected |
chainguard |
policy-controller |
— |
| policy-controller |
affected |
wolfi |
policy-controller |
— |
| pulumi |
affected |
wolfi |
pulumi |
— |
| pulumi |
affected |
chainguard |
pulumi |
— |
| pulumi-kubernetes-operator |
affected |
chainguard |
pulumi-kubernetes-operator |
— |
| pulumi-kubernetes-operator |
affected |
wolfi |
pulumi-kubernetes-operator |
— |
| pulumi-language-dotnet |
affected |
chainguard |
pulumi-language-dotnet |
— |
| pulumi-language-dotnet |
affected |
wolfi |
pulumi-language-dotnet |
— |
| pulumi-language-java |
affected |
chainguard |
pulumi-language-java |
— |
| pulumi-language-java |
affected |
wolfi |
pulumi-language-java |
— |
| pulumi-language-yaml |
affected |
wolfi |
pulumi-language-yaml |
— |
| pulumi-language-yaml |
affected |
chainguard |
pulumi-language-yaml |
— |
| rclone |
affected |
wolfi |
rclone |
— |
| rclone |
affected |
chainguard |
rclone |
— |
| scorecard |
affected |
wolfi |
scorecard |
— |
| scorecard |
affected |
chainguard |
scorecard |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| sops |
affected |
wolfi |
sops |
— |
| sops |
affected |
chainguard |
sops |
— |
| spire-server |
affected |
wolfi |
spire-server |
— |
| spire-server |
affected |
chainguard |
spire-server |
— |
| spire-server-fips |
affected |
chainguard |
spire-server-fips |
— |
| syft |
affected |
wolfi |
syft |
— |
| syft |
affected |
chainguard |
syft |
— |
| tekton-chains |
affected |
wolfi |
tekton-chains |
— |
| tekton-chains |
affected |
chainguard |
tekton-chains |
— |
| tekton-pipelines |
affected |
wolfi |
tekton-pipelines |
— |
| tekton-pipelines |
affected |
chainguard |
tekton-pipelines |
— |
| terraform-provider-google |
affected |
wolfi |
terraform-provider-google |
— |
| terraform-provider-google |
affected |
chainguard |
terraform-provider-google |
— |
| terragrunt |
affected |
chainguard |
terragrunt |
— |
| terragrunt |
affected |
wolfi |
terragrunt |
— |
| tkn |
affected |
wolfi |
tkn |
— |
| tkn |
affected |
chainguard |
tkn |
— |
| vault-1.13 |
affected |
chainguard |
vault-1.13 |
— |
| vault-1.13 |
affected |
wolfi |
vault-1.13 |
— |
| vault-fips-1.14 |
affected |
chainguard |
vault-fips-1.14 |
— |
| vexctl |
affected |
chainguard |
vexctl |
— |
| vexctl |
affected |
wolfi |
vexctl |
— |
| wolfictl |
affected |
chainguard |
wolfictl |
— |
| wolfictl |
affected |
wolfi |
wolfictl |
— |
| zarf |
affected |
chainguard |
zarf |
— |
| zarf |
affected |
wolfi |
zarf |
— |
| zot |
affected |
wolfi |
zot |
— |
| zot |
affected |
chainguard |
zot |
— |
Open SourceAll remaining2024-01-02
RAPL accessibility in github.com/containerd/containerd
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| cilium-cli |
affected |
chainguard |
cilium-cli |
— |
| cilium-cli |
affected |
wolfi |
cilium-cli |
— |
| containerd/containerd |
affected |
github.com |
github.com/containerd/containerd |
— |
| ctop |
affected |
wolfi |
ctop |
— |
| ctop |
affected |
chainguard |
ctop |
— |
| eksctl |
affected |
wolfi |
eksctl |
— |
| eksctl |
affected |
chainguard |
eksctl |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| fuse-overlayfs-snapshotter |
affected |
chainguard |
fuse-overlayfs-snapshotter |
— |
| fuse-overlayfs-snapshotter |
affected |
wolfi |
fuse-overlayfs-snapshotter |
— |
| gitness |
affected |
chainguard |
gitness |
— |
| gitness |
affected |
wolfi |
gitness |
— |
| grype |
affected |
chainguard |
grype |
— |
| grype |
affected |
wolfi |
grype |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm-push |
affected |
chainguard |
helm-push |
— |
| helm-push |
affected |
wolfi |
helm-push |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| kaniko |
affected |
chainguard |
kaniko |
— |
| kaniko |
affected |
wolfi |
kaniko |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| melange |
affected |
chainguard |
melange |
— |
| melange |
affected |
wolfi |
melange |
— |
| newrelic-infrastructure-agent |
affected |
wolfi |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent |
affected |
chainguard |
newrelic-infrastructure-agent |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| trivy |
affected |
chainguard |
trivy |
— |
| trivy |
affected |
wolfi |
trivy |
— |
| up |
affected |
chainguard |
up |
— |
| up |
affected |
wolfi |
up |
— |
| zot |
affected |
chainguard |
zot |
— |
| zot |
affected |
wolfi |
zot |
— |