Google Security Advisories · January 2024 — Google Security Advisories
288 advisories 167 CVEs 15 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2024-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 15 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

SUSE-SU-2024:0191-1

Open SourceExploitedCISA KEV listedHIGH2024-01-23

Security Beta update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-boynux-squid_exporter affected SUSE:Manager Client Tools 12-BETA golang-github-boynux-squid_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Client Tools 12-BETA golang-github-lusitaniae-apache_exporter
golang-github-prometheus-alertmanager affected SUSE:Manager Client Tools 12-BETA golang-github-prometheus-alertmanager
golang-github-prometheus-node_exporter affected SUSE:Manager Client Tools 12-BETA golang-github-prometheus-node_exporter
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 12-BETA golang-github-prometheus-prometheus
golang-github-prometheus-promu affected SUSE:Manager Client Tools 12-BETA golang-github-prometheus-promu
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Client Tools 12-BETA golang-github-QubitProducts-exporter_exporter
grafana affected SUSE:Manager Client Tools 12-BETA grafana
kiwi-desc-saltboot affected SUSE:Manager Client Tools 12-BETA kiwi-desc-saltboot
mgr-push affected SUSE:Manager Client Tools 12-BETA mgr-push
prometheus-blackbox_exporter affected SUSE:Manager Client Tools 12-BETA prometheus-blackbox_exporter
prometheus-postgres_exporter affected SUSE:Manager Client Tools 12-BETA prometheus-postgres_exporter
python-hwdata affected SUSE:Manager Client Tools 12-BETA python-hwdata
rhnlib affected SUSE:Manager Client Tools 12-BETA rhnlib
spacecmd affected SUSE:Manager Client Tools 12-BETA spacecmd
supportutils-plugin-salt affected SUSE:Manager Client Tools 12-BETA supportutils-plugin-salt
supportutils-plugin-susemanager-client affected SUSE:Manager Client Tools 12-BETA supportutils-plugin-susemanager-client
system-user-grafana affected SUSE:Manager Client Tools 12-BETA system-user-grafana
system-user-prometheus affected SUSE:Manager Client Tools 12-BETA system-user-prometheus
uyuni-common-libs affected SUSE:Manager Client Tools 12-BETA uyuni-common-libs
Upstream advisory

SUSE-SU-2024:0196-1

Open SourceExploitedCISA KEV listedMEDIUM2024-01-23

Security Beta update for SUSE Manager Client Tools and Salt

Affected products

ProductStatusVendorPackageEcosystem
ansible affected SUSE:Manager Client Tools 15-BETA ansible
dracut-saltboot affected SUSE:Manager Client Tools Beta for SLE Micro 5 dracut-saltboot
dracut-saltboot affected SUSE:Manager Client Tools 15-BETA dracut-saltboot
golang-github-boynux-squid_exporter affected SUSE:Manager Client Tools 15-BETA golang-github-boynux-squid_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Client Tools 15-BETA golang-github-lusitaniae-apache_exporter
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 15-BETA golang-github-prometheus-prometheus
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Client Tools 15-BETA golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter affected SUSE:Manager Client Tools Beta for SLE Micro 5 golang-github-QubitProducts-exporter_exporter
grafana affected SUSE:Manager Client Tools 15-BETA grafana
mgr-push affected SUSE:Manager Client Tools 15-BETA mgr-push
prometheus-blackbox_exporter affected SUSE:Manager Client Tools 15-BETA prometheus-blackbox_exporter
prometheus-blackbox_exporter affected SUSE:Manager Client Tools Beta for SLE Micro 5 prometheus-blackbox_exporter
prometheus-postgres_exporter affected SUSE:Manager Client Tools 15-BETA prometheus-postgres_exporter
python-hwdata affected SUSE:Manager Client Tools 15-BETA python-hwdata
python-pyvmomi affected SUSE:Manager Client Tools 15-BETA python-pyvmomi
rhnlib affected SUSE:Manager Client Tools 15-BETA rhnlib
spacecmd affected SUSE:Manager Client Tools 15-BETA spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 15-BETA spacewalk-client-tools
supportutils-plugin-salt affected SUSE:Manager Client Tools 15-BETA supportutils-plugin-salt
supportutils-plugin-susemanager-client affected SUSE:Manager Client Tools 15-BETA supportutils-plugin-susemanager-client
uyuni-common-libs affected SUSE:Manager Client Tools 15-BETA uyuni-common-libs
uyuni-proxy-systemd-services affected SUSE:Manager Client Tools 15-BETA uyuni-proxy-systemd-services
uyuni-proxy-systemd-services affected SUSE:Manager Client Tools Beta for SLE Micro 5 uyuni-proxy-systemd-services
Upstream advisory

openSUSE-SU-2024:0020-1

Open SourceExploitedCISA KEV listedCRITICAL2024-01-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

MGASA-2024-0017

Open SourceExploitedCISA KEV listedCRITICAL2024-01-25

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

openSUSE-SU-2024:0025-1

Open SourceExploitedCISA KEV listedCRITICAL2024-01-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected openSUSE:Leap 15.5 chromium
Upstream advisory

DSA-5602-1

Open SourceExploitedCISA KEV listed2024-01-17

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

GHSA-xr7r-f8xq-vfvv

Open SourceExploitedCISA KEV listedHIGH2024-01-31

runc vulnerable to container breakout through process.cwd trickery and leaked fds

Affected products

ProductStatusVendorPackageEcosystem
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
cadvisor affected chainguard cadvisor
cadvisor affected wolfi cadvisor
ctop affected chainguard ctop
ctop affected wolfi ctop
datadog-agent affected chainguard datadog-agent
datadog-agent affected wolfi datadog-agent
datadog-agent-fips affected chainguard datadog-agent-fips
docker affected wolfi docker
docker affected chainguard docker
grype affected wolfi grype
grype affected chainguard grype
ingress-nginx-controller affected chainguard ingress-nginx-controller
ingress-nginx-controller affected wolfi ingress-nginx-controller
ingress-nginx-controller-fips affected chainguard ingress-nginx-controller-fips
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k9s affected wolfi k9s
k9s affected chainguard k9s
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
kots affected chainguard kots
kots affected wolfi kots
kots-compat affected chainguard kots-compat
kubernetes-1.28 affected chainguard kubernetes-1.28
kubernetes-1.28 affected wolfi kubernetes-1.28
kubernetes-1.29 affected chainguard kubernetes-1.29
kubernetes-1.29 affected wolfi kubernetes-1.29
kubernetes-fips-1.27 affected chainguard kubernetes-fips-1.27
kubernetes-fips-1.28 affected chainguard kubernetes-fips-1.28
kubernetes-fips-1.29 affected chainguard kubernetes-fips-1.29
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
nerdctl affected chainguard nerdctl
nerdctl affected wolfi nerdctl
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent-1.43 affected chainguard newrelic-infrastructure-agent-1.43
opencontainers/runc affected github.com github.com/opencontainers/runc
podman affected wolfi podman
podman affected chainguard podman
podman-fips affected chainguard podman-fips
runc affected wolfi runc
runc affected chainguard runc
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
skopeo affected chainguard skopeo
skopeo affected wolfi skopeo
syft affected chainguard syft
syft affected wolfi syft
telegraf-1.26 affected wolfi telegraf-1.26
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.27 affected wolfi telegraf-1.27
telegraf-1.27 affected chainguard telegraf-1.27
telegraf-1.28 affected wolfi telegraf-1.28
telegraf-1.28 affected chainguard telegraf-1.28
trivy affected wolfi trivy
trivy affected chainguard trivy
wolfictl affected wolfi wolfictl
wolfictl affected chainguard wolfictl
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

GHSA-xr7r-f8xq-vfvv

GoogleExploitedCISA KEV listedHIGH2024-01-31

runc vulnerable to container breakout through process.cwd trickery and leaked fds

Affected products

ProductStatusVendorPackageEcosystem
opencontainers/runc affected github.com github.com/opencontainers/runc
Upstream advisory

AZL-34074

Open SourceExploitedCISA KEV listedHIGH2024-01-31

CVE-2024-21626 affecting package kubernetes for versions less than 1.28.4-3

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:2 kubernetes
Upstream advisory

AZL-34896

Open SourceExploitedCISA KEV listedHIGH2024-01-31

CVE-2024-21626 affecting package kubernetes for versions less than 1.30.1-1

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Azure Linux:3 kubernetes
Upstream advisory

CVE-2024-0519

GoogleExploitedCISA KEV listedHIGH2024-01-16

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0519

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
couchbase_server affected couchbase
fedora affected fedoraproject
Upstream advisory

CVE-2024-0519

GoogleExploitedCISA KEV listed2024-01-16

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0519

Upstream advisory

DEBIAN-CVE-2024-0519

Open SourceExploitedCISA KEV listedHIGH2024-01-16

DEBIAN-CVE-2024-0519

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0519

Project ZeroExploitedCISA KEV listed2024-01-16

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0519

Upstream advisory

DEBIAN-CVE-2024-0811

Open SourceWeaponized exploitMEDIUM2024-01-24

DEBIAN-CVE-2024-0811

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-5607-1

Open SourceWeaponized exploit2024-01-24

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

CVE-2024-0811

GoogleWeaponized exploitMEDIUM2024-01-23

Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)

CVEs:CVE-2024-0811

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-0811

GoogleWeaponized exploit2024-01-23

Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)

CVEs:CVE-2024-0811

Upstream advisory

ASB-A-308188337

GoogleWeaponized exploit2024-01-01

ASB-A-308188337

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48418

GoogleWeaponized exploitCRITICAL2024-01-02

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no additional     execution pri...

CVEs:CVE-2023-48418

Affected products

ProductStatusVendorPackageEcosystem
pixel_watch_firmware affected google
Upstream advisory

CVE-2024-21388

Open SourceActive exploitation (sightings)CRITICAL2024-01-09

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2024-21388

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2024-0517

Open SourceActive exploitation (sightings)CRITICAL2024-01-16

DEBIAN-CVE-2024-0517

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0517

GoogleActive exploitation (sightings)2024-01-16

Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0517

Upstream advisory

CVE-2024-0517

GoogleActive exploitation (sightings)CRITICAL2024-01-16

Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0517

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-21326

Open SourceActive exploitation (sightings)CRITICAL2024-01-09

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2024-21326

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2024-21385

Open SourceActive exploitation (sightings)CRITICAL2024-01-09

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2024-21385

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2024-1059

Open SourceActive exploitation (sightings)CRITICAL2024-01-30

DEBIAN-CVE-2024-1059

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1059

GoogleActive exploitation (sightings)CRITICAL2024-01-30

Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1059

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2024-0518

Open SourceActive exploitation (sightings)HIGH2024-01-16

DEBIAN-CVE-2024-0518

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0518

GoogleActive exploitation (sightings)2024-01-16

Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0518

Upstream advisory

CVE-2024-0518

GoogleActive exploitation (sightings)HIGH2024-01-16

Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0518

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2024-1077

Open SourceActive exploitation (sightings)CRITICAL2024-01-30

DEBIAN-CVE-2024-1077

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1077

GoogleActive exploitation (sightings)CRITICAL2024-01-30

Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

CVEs:CVE-2024-1077

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-21382

Open SourceActive exploitation (sightings)HIGH2024-01-09

Microsoft Edge for Android Information Disclosure Vulnerability

CVEs:CVE-2024-21382

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2024-1060

Open SourceActive exploitation (sightings)CRITICAL2024-01-30

DEBIAN-CVE-2024-1060

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1060

GoogleActive exploitation (sightings)CRITICAL2024-01-30

Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1060

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-pvcr-v8j8-j5q3

GoogleActive exploitation (sightings)HIGH2024-01-09

Parsing JSON serialized payload without protected field can lead to segfault

Affected products

ProductStatusVendorPackageEcosystem
lestrrat-go/jwx affected github.com github.com/lestrrat-go/jwx
lestrrat-go/jwx/v2 affected github.com github.com/lestrrat-go/jwx/v2
Upstream advisory

GHSA-pvcr-v8j8-j5q3

Open SourceActive exploitation (sightings)HIGH2024-01-09

Parsing JSON serialized payload without protected field can lead to segfault

Affected products

ProductStatusVendorPackageEcosystem
boring-registry affected wolfi boring-registry
boring-registry affected chainguard boring-registry
cosign-fips affected wolfi cosign-fips
cosign-fips affected chainguard cosign-fips
external-secrets-0.7 affected chainguard external-secrets-0.7
external-secrets-fips affected chainguard external-secrets-fips
external-secrets-operator affected wolfi external-secrets-operator
external-secrets-operator affected chainguard external-secrets-operator
falco affected wolfi falco
falco affected chainguard falco
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
istio-cni-1.19 affected chainguard istio-cni-1.19
istio-cni-1.19 affected wolfi istio-cni-1.19
istio-cni-1.20 affected wolfi istio-cni-1.20
istio-cni-1.20 affected chainguard istio-cni-1.20
istio-cni-fips-1.19 affected chainguard istio-cni-fips-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-fips-1.19 affected chainguard istio-operator-fips-1.19
istio-pilot-agent-1.18 affected wolfi istio-pilot-agent-1.18
istio-pilot-agent-1.18 affected chainguard istio-pilot-agent-1.18
istio-pilot-agent-1.19 affected wolfi istio-pilot-agent-1.19
istio-pilot-agent-1.19 affected chainguard istio-pilot-agent-1.19
istio-pilot-agent-1.20 affected wolfi istio-pilot-agent-1.20
istio-pilot-agent-1.20 affected chainguard istio-pilot-agent-1.20
istio-pilot-agent-fips-1.19 affected chainguard istio-pilot-agent-fips-1.19
istio-pilot-discovery-1.18 affected chainguard istio-pilot-discovery-1.18
istio-pilot-discovery-1.18 affected wolfi istio-pilot-discovery-1.18
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.20 affected chainguard istio-pilot-discovery-1.20
istio-pilot-discovery-1.20 affected wolfi istio-pilot-discovery-1.20
istio-pilot-discovery-fips-1.19 affected chainguard istio-pilot-discovery-fips-1.19
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kyverno affected chainguard kyverno
kyverno affected wolfi kyverno
lestrrat-go/jwx affected github.com github.com/lestrrat-go/jwx
lestrrat-go/jwx/v2 affected github.com github.com/lestrrat-go/jwx/v2
mc affected chainguard mc
mc affected wolfi mc
minio affected wolfi minio
minio affected chainguard minio
spire-server affected chainguard spire-server
spire-server affected wolfi spire-server
spire-server-fips affected chainguard spire-server-fips
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
vexctl affected wolfi vexctl
vexctl affected chainguard vexctl
Upstream advisory

CVE-2024-21387

Open SourceActive exploitation (sightings)MEDIUM2024-01-09

Microsoft Edge for Android Spoofing Vulnerability

CVEs:CVE-2024-21387

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2024-21639

Open SourceActive exploitation (sightings)CRITICAL2024-01-12

CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared memory, which leads to out-of-bounds read ...

CVEs:CVE-2024-21639

Affected products

ProductStatusVendorPackageEcosystem
chromium_embedded_framework affected chromiumembedded
Upstream advisory

CVE-2023-6921

GoogleActive exploitation (sightings)CRITICAL2024-01-08

Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.

CVEs:CVE-2023-6921

Affected products

ProductStatusVendorPackageEcosystem
google_integrator affected prestashow
Upstream advisory

CVE-2024-21640

Open SourceActive exploitation (sightings)CRITICAL2024-01-13

Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.`CefVideoConsumerOSR::OnFrameCaptured` does not check `pixel_format` properly, which leads to out-of-bounds read out of the sandbox. Thi...

CVEs:CVE-2024-21640

Affected products

ProductStatusVendorPackageEcosystem
chromium_embedded_framework affected chromiumembedded
Upstream advisory

DEBIAN-CVE-2024-0808

Open SourceActive exploitation (sightings)CRITICAL2024-01-24

DEBIAN-CVE-2024-0808

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0808

GoogleActive exploitation (sightings)2024-01-23

Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

CVEs:CVE-2024-0808

Upstream advisory

CVE-2024-0808

GoogleActive exploitation (sightings)CRITICAL2024-01-23

Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

CVEs:CVE-2024-0808

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2024-0804

Open SourceActive exploitation (sightings)CRITICAL2024-01-24

DEBIAN-CVE-2024-0804

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0804

GoogleActive exploitation (sightings)2024-01-23

Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-0804

Upstream advisory

CVE-2024-0804

GoogleActive exploitation (sightings)CRITICAL2024-01-23

Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-0804

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2024-0812

Open SourceActive exploitation (sightings)HIGH2024-01-24

DEBIAN-CVE-2024-0812

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0812

GoogleActive exploitation (sightings)2024-01-23

Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0812

Upstream advisory

CVE-2024-0812

GoogleActive exploitation (sightings)HIGH2024-01-23

Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0812

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2024-0807

Open SourceActive exploitation (sightings)CRITICAL2024-01-24

DEBIAN-CVE-2024-0807

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0807

GoogleActive exploitation (sightings)CRITICAL2024-01-23

Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0807

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-0807

GoogleActive exploitation (sightings)2024-01-23

Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0807

Upstream advisory

DEBIAN-CVE-2024-0806

Open SourceActive exploitation (sightings)CRITICAL2024-01-24

DEBIAN-CVE-2024-0806

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0806

GoogleActive exploitation (sightings)2024-01-23

Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)

CVEs:CVE-2024-0806

Upstream advisory

CVE-2024-0806

GoogleActive exploitation (sightings)CRITICAL2024-01-23

Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)

CVEs:CVE-2024-0806

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-3172

GoogleActive exploitation (sightings)2024-01-23

Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3172

Upstream advisory

CVE-2024-3172

GoogleActive exploitation (sightings)CRITICAL2024-01-23

Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3172

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-32889

Open SourceActive exploitation (sightings)HIGH2024-01-02

In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY0116...

CVEs:CVE-2023-32889

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2024-0809

Open SourceActive exploitation (sightings)MEDIUM2024-01-24

DEBIAN-CVE-2024-0809

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0809

GoogleActive exploitation (sightings)2024-01-23

Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-0809

Upstream advisory

CVE-2024-0809

GoogleActive exploitation (sightings)MEDIUM2024-01-23

Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-0809

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-21383

Open SourceActive exploitation (sightings)LOW2024-01-09

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2024-21383

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2024-0805

Open SourceActive exploitation (sightings)MEDIUM2024-01-24

DEBIAN-CVE-2024-0805

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0805

GoogleActive exploitation (sightings)MEDIUM2024-01-23

Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)

CVEs:CVE-2024-0805

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-0805

GoogleActive exploitation (sightings)2024-01-23

Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)

CVEs:CVE-2024-0805

Upstream advisory

GHSA-mg2x-mggj-6955

Open SourceActive exploitation (sightings)HIGH2024-01-24

Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow affected PyPI apache-airflow
apache-airflow affected PyPI apache-airflow
apache-airflow-providers-cncf-kubernetes affected PyPI apache-airflow-providers-cncf-kubernetes
apache-airflow-providers-cncf-kubernetes affected PyPI apache-airflow-providers-cncf-kubernetes
Upstream advisory

GHSA-mg2x-mggj-6955

Open SourceActive exploitation (sightings)HIGH2024-01-24

Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow affected PyPI apache-airflow
apache-airflow-providers-cncf-kubernetes affected PyPI apache-airflow-providers-cncf-kubernetes
Upstream advisory

CVE-2023-51702

Open SourceActive exploitation (sightings)HIGH2024-01-24

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without a...

CVEs:CVE-2023-51702

Affected products

ProductStatusVendorPackageEcosystem
airflow affected apache
airflow_cncf_kubernetes affected apache
apache-airflow-providers-cncf-kubernetes affected apache
Upstream advisory

CVE-2023-51702

Open SourceActive exploitation (sightings)MEDIUM2024-01-24

Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service

CVEs:CVE-2023-51702

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow affected PyPI apache-airflow
apache-airflow-providers-cncf-kubernetes affected PyPI apache-airflow-providers-cncf-kubernetes
Upstream advisory

CVE-2023-51702

Open SourceActive exploitation (sightings)HIGH2024-01-24

Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service

CVEs:CVE-2023-51702

Affected products

ProductStatusVendorPackageEcosystem
apache-airflow affected PyPI apache-airflow
apache-airflow-providers-cncf-kubernetes affected PyPI apache-airflow-providers-cncf-kubernetes
Upstream advisory

DEBIAN-CVE-2024-0813

Open SourceActive exploitation (sightings)CRITICAL2024-01-24

DEBIAN-CVE-2024-0813

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0813

GoogleActive exploitation (sightings)2024-01-23

Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)

CVEs:CVE-2024-0813

Upstream advisory

CVE-2024-0813

GoogleActive exploitation (sightings)CRITICAL2024-01-23

Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)

CVEs:CVE-2024-0813

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2024-0810

Open SourceActive exploitation (sightings)CRITICAL2024-01-24

DEBIAN-CVE-2024-0810

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0810

GoogleActive exploitation (sightings)CRITICAL2024-01-23

Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

CVEs:CVE-2024-0810

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-0810

GoogleActive exploitation (sightings)2024-01-23

Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

CVEs:CVE-2024-0810

Upstream advisory

CVE-2024-3169

GoogleActive exploitation (sightings)CRITICAL2024-01-30

Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-3169

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-0814

Open SourceActive exploitation (sightings)MEDIUM2024-01-24

DEBIAN-CVE-2024-0814

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0814

GoogleActive exploitation (sightings)2024-01-23

Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-0814

Upstream advisory

CVE-2024-0814

GoogleActive exploitation (sightings)MEDIUM2024-01-23

Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-0814

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2023-52198

GoogleActive exploitation (sightings)CRITICAL2024-01-08

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125.

CVEs:CVE-2023-52198

Affected products

ProductStatusVendorPackageEcosystem
private_google_calendars affected michielvaneerd
Upstream advisory

CVE-2024-20803

Open SourceActive exploitation (sightings)MEDIUM2024-01-03

Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.

CVEs:CVE-2024-20803

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-2884

GoogleActive exploitation (sightings)2024-01-30

Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-2884

Upstream advisory

CVE-2024-2884

GoogleActive exploitation (sightings)MEDIUM2024-01-30

Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-2884

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2023-48419

GoogleActive exploitation (sightings)CRITICAL2024-01-02

An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 

CVEs:CVE-2023-48419

Affected products

ProductStatusVendorPackageEcosystem
home_firmware affected google
home_mini_firmware affected google
nest_audio_firmware affected google
nest_mini_firmware affected google
Upstream advisory

CVE-2024-20805

Open SourceActive exploitation (sightings)HIGH2024-01-03

Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.

CVEs:CVE-2024-20805

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
myfiles affected samsung
Upstream advisory

CVE-2023-6339

GoogleActive exploitation (sightings)CRITICAL2024-01-02

Google Nest WiFi Pro root code-execution & user-data compromise

CVEs:CVE-2023-6339

Affected products

ProductStatusVendorPackageEcosystem
nest_wifi_pro_firmware affected google
Upstream advisory

CVE-2024-20806

Open SourceActive exploitation (sightings)MEDIUM2024-01-03

Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.

CVEs:CVE-2024-20806

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2023-32882

Open SourceActive exploitation (sightings)HIGH2024-01-02

In battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID...

CVEs:CVE-2023-32882

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32878

Open SourceActive exploitation (sightings)MEDIUM2024-01-02

In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issu...

CVEs:CVE-2023-32878

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32891

Open SourceActive exploitation (sightings)HIGH2024-01-02

In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS079...

CVEs:CVE-2023-32891

Affected products

ProductStatusVendorPackageEcosystem
android affected google
lr13 affected mediatek
nr15 affected mediatek
nr16 affected mediatek
nr17 affected mediatek
Upstream advisory

CVE-2023-32885

Open SourceActive exploitation (sightings)HIGH2024-01-02

In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780685; Issu...

CVEs:CVE-2023-32885

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32884

Open SourceActive exploitation (sightings)MEDIUM2024-01-02

In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944011...

CVEs:CVE-2023-32884

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32883

Open SourceActive exploitation (sightings)HIGH2024-01-02

In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08282249; ...

CVEs:CVE-2023-32883

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32879

Open SourceActive exploitation (sightings)HIGH2024-01-02

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ...

CVEs:CVE-2023-32879

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32877

Open SourceActive exploitation (sightings)HIGH2024-01-02

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ...

CVEs:CVE-2023-32877

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32875

Open SourceActive exploitation (sightings)MEDIUM2024-01-02

In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; I...

CVEs:CVE-2023-32875

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32876

Open SourceActive exploitation (sightings)MEDIUM2024-01-02

In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308612; I...

CVEs:CVE-2023-32876

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32881

Open SourceActive exploitation (sightings)HIGH2024-01-02

In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue I...

CVEs:CVE-2023-32881

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32880

Open SourceActive exploitation (sightings)MEDIUM2024-01-02

In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issu...

CVEs:CVE-2023-32880

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48353

Open SourceActive exploitation (sightings)CRITICAL2024-01-18

In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-48353

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48358

Open SourceActive exploitation (sightings)CRITICAL2024-01-18

In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-48358

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48354

Open SourceActive exploitation (sightings)HIGH2024-01-18

In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed

CVEs:CVE-2023-48354

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48355

Open SourceActive exploitation (sightings)CRITICAL2024-01-18

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-48355

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48357

Open SourceActive exploitation (sightings)CRITICAL2024-01-18

In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-48357

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48339

Open SourceActive exploitation (sightings)HIGH2024-01-18

In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

CVEs:CVE-2023-48339

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48346

Open SourceActive exploitation (sightings)HIGH2024-01-18

In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48345

Open SourceActive exploitation (sightings)HIGH2024-01-18

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GO-2024-2456

Open SourcePoC exploitCRITICAL2024-01-23

Path traversal and RCE in github.com/go-git/go-git/v5 and gopkg.in/src-d/go-git.v4

Affected products

ProductStatusVendorPackageEcosystem
bom affected chainguard bom
bom affected wolfi bom
gitness affected wolfi gitness
gitness affected chainguard gitness
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
go-git/go-git/v5 affected github.com github.com/go-git/go-git/v5
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
src-d/go-git.v4 affected gopkg.in gopkg.in/src-d/go-git.v4
src-fingerprint affected wolfi src-fingerprint
src-fingerprint affected chainguard src-fingerprint
Upstream advisory

DEBIAN-CVE-2023-49569

Open SourcePoC exploitCRITICAL2024-01-12

DEBIAN-CVE-2023-49569

Affected products

ProductStatusVendorPackageEcosystem
golang-github-go-git-go-git affected Debian:12 golang-github-go-git-go-git
golang-github-go-git-go-git affected Debian:13 golang-github-go-git-go-git
golang-github-go-git-go-git affected Debian:14 golang-github-go-git-go-git
Upstream advisory

GHSA-449p-3h89-pw88

Open SourcePoC exploitCRITICAL2024-01-10

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

Affected products

ProductStatusVendorPackageEcosystem
bom affected wolfi bom
bom affected chainguard bom
flux-2.0 affected chainguard flux-2.0
gitness affected chainguard gitness
gitness affected wolfi gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
go-git/go-git/v5 affected github.com github.com/go-git/go-git/v5
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
goreleaser-1.18 affected wolfi goreleaser-1.18
goreleaser-1.18 affected chainguard goreleaser-1.18
grafana-9 affected chainguard grafana-9
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
src-d/go-git.v4 affected gopkg.in gopkg.in/src-d/go-git.v4
src-fingerprint affected wolfi src-fingerprint
src-fingerprint affected chainguard src-fingerprint
Upstream advisory

GHSA-449p-3h89-pw88

GooglePoC exploitCRITICAL2024-01-10

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

Affected products

ProductStatusVendorPackageEcosystem
go-git/go-git/v5 affected github.com github.com/go-git/go-git/v5
src-d/go-git.v4 affected gopkg.in gopkg.in/src-d/go-git.v4
Upstream advisory

CVE-2024-20721

Open SourcePoC exploitMEDIUM2024-01-11

Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the...

CVEs:CVE-2024-20721

Affected products

ProductStatusVendorPackageEcosystem
acrobat affected adobe
edge_chromium affected microsoft
Upstream advisory

GO-2024-2466

Open SourcePoC exploitHIGH2024-01-23

Denial of service in github.com/go-git/go-git/v5 and gopkg.in/src-d/go-git.v4

Affected products

ProductStatusVendorPackageEcosystem
apko affected wolfi apko
apko affected chainguard apko
bom affected wolfi bom
bom affected chainguard bom
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
gitness affected wolfi gitness
gitness affected chainguard gitness
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
go-git/go-git/v5 affected github.com github.com/go-git/go-git/v5
go-licenses affected chainguard go-licenses
go-licenses affected wolfi go-licenses
gomplate affected chainguard gomplate
gomplate affected wolfi gomplate
goreleaser affected wolfi goreleaser
goreleaser affected chainguard goreleaser
kots affected wolfi kots
kots affected chainguard kots
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-yaml affected chainguard pulumi-language-yaml
pulumi-language-yaml affected wolfi pulumi-language-yaml
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
src-d/go-git.v4 affected gopkg.in gopkg.in/src-d/go-git.v4
src-fingerprint affected wolfi src-fingerprint
src-fingerprint affected chainguard src-fingerprint
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

DEBIAN-CVE-2023-49568

Open SourcePoC exploitCRITICAL2024-01-12

DEBIAN-CVE-2023-49568

Affected products

ProductStatusVendorPackageEcosystem
golang-github-go-git-go-git affected Debian:12 golang-github-go-git-go-git
golang-github-go-git-go-git affected Debian:13 golang-github-go-git-go-git
golang-github-go-git-go-git affected Debian:14 golang-github-go-git-go-git
Upstream advisory

CVE-2024-0023

Open SourcePoC exploitHIGH2024-01-03

In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2024-0023

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0015

Open SourcePoC exploitHIGH2024-01-03

In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not ...

CVEs:CVE-2024-0015

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2024-0011

Open SourceCoalition ESS < 30%2024-01-14

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

DEBIAN-CVE-2024-0223

Open SourceCoalition ESS < 30%CRITICAL2024-01-04

DEBIAN-CVE-2024-0223

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-5595-1

Open SourceCoalition ESS < 30%2024-01-04

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2024-0223

GoogleCoalition ESS < 30%CRITICAL2024-01-03

Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0223

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-2v6x-frw8-7r7f

Open SourceCoalition ESS < 30%HIGH2024-01-23

Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kube-state-metrics affected github.com github.com/kubernetes/kube-state-metrics
kube-state-metrics affected k8s.io k8s.io/kube-state-metrics
Upstream advisory

GHSA-2v6x-frw8-7r7f

Open SourceCoalition ESS < 30%HIGH2024-01-23

Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/kube-state-metrics affected github.com github.com/kubernetes/kube-state-metrics
kube-state-metrics affected k8s.io k8s.io/kube-state-metrics
Upstream advisory

DEBIAN-CVE-2023-49295

Open SourceCoalition ESS < 30%HIGH2024-01-10

DEBIAN-CVE-2023-49295

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lucas-clemente-quic-go affected Debian:11 golang-github-lucas-clemente-quic-go
golang-github-lucas-clemente-quic-go affected Debian:12 golang-github-lucas-clemente-quic-go
golang-github-lucas-clemente-quic-go affected Debian:13 golang-github-lucas-clemente-quic-go
golang-github-lucas-clemente-quic-go affected Debian:14 golang-github-lucas-clemente-quic-go
Upstream advisory

DEBIAN-CVE-2024-0222

Open SourceCoalition ESS < 30%CRITICAL2024-01-04

DEBIAN-CVE-2024-0222

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0222

GoogleCoalition ESS < 30%CRITICAL2024-01-03

Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0222

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

ASB-A-309364195

GoogleCoalition ESS < 30%2024-01-01

ASB-A-309364195

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2024-0224

Open SourceCoalition ESS < 30%CRITICAL2024-01-04

DEBIAN-CVE-2024-0224

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0224

GoogleCoalition ESS < 30%CRITICAL2024-01-03

Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0224

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2024-0225

Open SourceCoalition ESS < 30%CRITICAL2024-01-04

DEBIAN-CVE-2024-0225

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-0225

GoogleCoalition ESS < 30%CRITICAL2024-01-03

Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0225

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-20709

Open SourceCoalition ESS < 30%MEDIUM2024-01-11

Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the...

CVEs:CVE-2024-20709

Affected products

ProductStatusVendorPackageEcosystem
acrobat affected adobe
edge_chromium affected microsoft
Upstream advisory

CVE-2024-21336

Open SourceCoalition ESS < 30%LOW2024-01-09

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2024-21336

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-0094

GoogleCoalition ESS < 30%CRITICAL2024-01-16

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ...

CVEs:CVE-2023-0094

Affected products

ProductStatusVendorPackageEcosystem
upqode_google_maps affected qoders
Upstream advisory

CVE-2024-20675

Open SourceCoalition ESS < 30%MEDIUM2024-01-09

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVEs:CVE-2024-20675

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2024-0333

Open SourceCoalition ESS < 30%MEDIUM2024-01-10

DEBIAN-CVE-2024-0333

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-5598-1

Open SourceCoalition ESS < 30%2024-01-10

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2024-0333

GoogleCoalition ESS < 30%MEDIUM2024-01-09

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-0333

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-21337

Open SourceCoalition ESS < 30%CRITICAL2024-01-09

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2024-21337

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2023-36629

Open SourceCoalition ESS < 30%MEDIUM2024-01-09

The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

CVEs:CVE-2023-36629

Affected products

ProductStatusVendorPackageEcosystem
st54-android-packages-apps-nfc affected st
Upstream advisory

RHSA-2024:0406

Open SourceCoalition ESS < 30%MEDIUM2024-01-25

Red Hat Security Advisory: protobuf-c security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf-c affected Red Hat:rhel_eus:8.6::appstream protobuf-c
protobuf-c-compiler affected Red Hat:rhel_eus:8.6::appstream protobuf-c-compiler
protobuf-c-compiler-debuginfo affected Red Hat:rhel_eus:8.6::appstream protobuf-c-compiler-debuginfo
protobuf-c-debuginfo affected Red Hat:rhel_eus:8.6::appstream protobuf-c-debuginfo
protobuf-c-debugsource affected Red Hat:rhel_eus:8.6::appstream protobuf-c-debugsource
protobuf-c-devel affected Red Hat:rhel_eus:8.6::appstream protobuf-c-devel
Upstream advisory

ASB-A-275619408

GoogleCoalition ESS < 30%2024-01-01

ASB-A-275619408

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-0016

Open SourceCoalition ESS < 30%MEDIUM2024-01-03

In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-0016

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20804

Open SourceCoalition ESS < 30%HIGH2024-01-03

Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.

CVEs:CVE-2024-20804

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
myfiles affected samsung
Upstream advisory

CVE-2024-0021

Open SourceCoalition ESS < 30%HIGH2024-01-03

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no addit...

CVEs:CVE-2024-0021

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0018

Open SourceCoalition ESS < 30%HIGH2024-01-03

In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2024-0018

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-295908146

GoogleCoalition ESS < 30%2024-01-01

ASB-A-295908146

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom/opensource/graphics-kernel affected platform platform/vendor/qcom/opensource/graphics-kernel
Upstream advisory

ASB-A-303101495

GoogleCoalition ESS < 30%2024-01-01

ASB-A-303101495

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-303101624

GoogleCoalition ESS < 30%2024-01-01

ASB-A-303101624

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-303101664

GoogleCoalition ESS < 30%2024-01-01

ASB-A-303101664

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-303101067

GoogleCoalition ESS < 30%2024-01-01

ASB-A-303101067

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-303101456

GoogleCoalition ESS < 30%2024-01-01

ASB-A-303101456

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-303107435

GoogleCoalition ESS < 30%2024-01-01

PUB-A-303107435

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-0020

Open SourceCoalition ESS < 30%MEDIUM2024-01-03

In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional exe...

CVEs:CVE-2024-0020

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0017

Open SourceCoalition ESS < 30%MEDIUM2024-01-03

In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2024-0017

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0019

Open SourceCoalition ESS < 30%MEDIUM2024-01-03

In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional executio...

CVEs:CVE-2024-0019

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-32872

Open SourceCoalition ESS < 30%HIGH2024-01-02

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Iss...

CVEs:CVE-2023-32872

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-309367791

GoogleCoalition ESS < 30%2024-01-01

ASB-A-309367791

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-40085

Open SourceCoalition ESS < 30%MEDIUM2024-01-03

In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2023-40085

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-21165

Open SourceCoalition ESS < 30%HIGH2024-01-03

In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2023-21165

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-292001469

GoogleCoalition ESS < 30%HIGH2024-01-01

ASB-A-292001469

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48342

Open SourceCoalition ESS < 30%CRITICAL2024-01-03

In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-48342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-4164

Open SourceCoalition ESS < 30%HIGH2024-01-02

There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional execution privileges needed.

CVEs:CVE-2023-4164

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-311288747

GoogleCoalition ESS < 30%2024-01-01

ASB-A-311288747

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-311290653

GoogleCoalition ESS < 30%2024-01-01

ASB-A-311290653

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-48356

Open SourceCoalition ESS < 30%CRITICAL2024-01-18

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-48356

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48359

Open SourceCoalition ESS < 30%CRITICAL2024-01-18

In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed

CVEs:CVE-2023-48359

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48347

Open SourceCoalition ESS < 30%HIGH2024-01-18

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48340

Open SourceCoalition ESS < 30%CRITICAL2024-01-03

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48340

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48341

Open SourceCoalition ESS < 30%HIGH2024-01-03

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48343

Open SourceCoalition ESS < 30%CRITICAL2024-01-03

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48343

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48344

Open SourceCoalition ESS < 30%HIGH2024-01-03

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48348

Open SourceCoalition ESS < 30%CRITICAL2024-01-03

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48349

Open SourceCoalition ESS < 30%CRITICAL2024-01-03

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48349

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48350

Open SourceCoalition ESS < 30%CRITICAL2024-01-03

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48350

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48351

Open SourceCoalition ESS < 30%CRITICAL2024-01-03

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48351

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-48352

Open SourceCoalition ESS < 30%CRITICAL2024-01-03

In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVEs:CVE-2023-48352

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-311273933

GoogleCoalition ESS < 30%2024-01-01

ASB-A-311273933

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-311273934

GoogleCoalition ESS < 30%2024-01-01

ASB-A-311273934

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-311279652

GoogleCoalition ESS < 30%2024-01-01

ASB-A-311279652

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-311279655

GoogleCoalition ESS < 30%2024-01-01

ASB-A-311279655

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-311279656

GoogleCoalition ESS < 30%2024-01-01

ASB-A-311279656

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-311282174

GoogleCoalition ESS < 30%2024-01-01

ASB-A-311282174

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-311288752

GoogleCoalition ESS < 30%2024-01-01

ASB-A-311288752

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-311290655

GoogleCoalition ESS < 30%2024-01-01

ASB-A-311290655

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-303101147

GoogleCoalition ESS < 30%2024-01-01

ASB-A-303101147

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

GO-2024-2453

Open SourceAll remaining2024-01-18

Timing side channel in github.com/cloudflare/circl

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller affected wolfi actions-runner-controller
apko affected chainguard apko
apko affected wolfi apko
argo-workflows affected chainguard argo-workflows
argo-workflows affected wolfi argo-workflows
boring-registry affected wolfi boring-registry
boring-registry affected chainguard boring-registry
cloudflare/circl affected github.com github.com/cloudflare/circl
cosign affected wolfi cosign
cosign affected chainguard cosign
cosign-fips affected chainguard cosign-fips
crossplane affected wolfi crossplane
crossplane affected chainguard crossplane
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-aws-cloudformation affected chainguard crossplane-provider-aws-cloudformation
crossplane-provider-aws-cloudformation affected wolfi crossplane-provider-aws-cloudformation
crossplane-provider-aws-cloudfront affected chainguard crossplane-provider-aws-cloudfront
crossplane-provider-aws-cloudfront affected wolfi crossplane-provider-aws-cloudfront
crossplane-provider-aws-cloudwatchlogs affected wolfi crossplane-provider-aws-cloudwatchlogs
crossplane-provider-aws-cloudwatchlogs affected chainguard crossplane-provider-aws-cloudwatchlogs
crossplane-provider-aws-dynamodb affected chainguard crossplane-provider-aws-dynamodb
crossplane-provider-aws-dynamodb affected wolfi crossplane-provider-aws-dynamodb
crossplane-provider-aws-ec2 affected wolfi crossplane-provider-aws-ec2
crossplane-provider-aws-ec2 affected chainguard crossplane-provider-aws-ec2
crossplane-provider-aws-eks affected chainguard crossplane-provider-aws-eks
crossplane-provider-aws-eks affected wolfi crossplane-provider-aws-eks
crossplane-provider-aws-elasticache affected chainguard crossplane-provider-aws-elasticache
crossplane-provider-aws-elasticache affected wolfi crossplane-provider-aws-elasticache
crossplane-provider-aws-firehose affected chainguard crossplane-provider-aws-firehose
crossplane-provider-aws-firehose affected wolfi crossplane-provider-aws-firehose
crossplane-provider-aws-iam affected wolfi crossplane-provider-aws-iam
crossplane-provider-aws-iam affected chainguard crossplane-provider-aws-iam
crossplane-provider-aws-kinesis affected wolfi crossplane-provider-aws-kinesis
crossplane-provider-aws-kinesis affected chainguard crossplane-provider-aws-kinesis
crossplane-provider-aws-kms affected wolfi crossplane-provider-aws-kms
crossplane-provider-aws-kms affected chainguard crossplane-provider-aws-kms
crossplane-provider-aws-lambda affected wolfi crossplane-provider-aws-lambda
crossplane-provider-aws-lambda affected chainguard crossplane-provider-aws-lambda
crossplane-provider-aws-memorydb affected chainguard crossplane-provider-aws-memorydb
crossplane-provider-aws-memorydb affected wolfi crossplane-provider-aws-memorydb
crossplane-provider-aws-rds affected chainguard crossplane-provider-aws-rds
crossplane-provider-aws-rds affected wolfi crossplane-provider-aws-rds
crossplane-provider-aws-route53 affected chainguard crossplane-provider-aws-route53
crossplane-provider-aws-route53 affected wolfi crossplane-provider-aws-route53
crossplane-provider-aws-s3 affected chainguard crossplane-provider-aws-s3
crossplane-provider-aws-s3 affected wolfi crossplane-provider-aws-s3
crossplane-provider-aws-sns affected wolfi crossplane-provider-aws-sns
crossplane-provider-aws-sns affected chainguard crossplane-provider-aws-sns
crossplane-provider-aws-sqs affected wolfi crossplane-provider-aws-sqs
crossplane-provider-aws-sqs affected chainguard crossplane-provider-aws-sqs
crossplane-provider-family-aws affected chainguard crossplane-provider-family-aws
crossplane-provider-family-aws affected wolfi crossplane-provider-family-aws
falcoctl-fips affected chainguard falcoctl-fips
flux affected chainguard flux
flux affected wolfi flux
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller affected chainguard flux-notification-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
gitness affected chainguard gitness
gitness affected wolfi gitness
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
gomplate affected chainguard gomplate
gomplate affected wolfi gomplate
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
grype affected wolfi grype
grype affected chainguard grype
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
melange affected wolfi melange
melange affected chainguard melange
policy-controller affected chainguard policy-controller
policy-controller affected wolfi policy-controller
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-yaml affected chainguard pulumi-language-yaml
pulumi-language-yaml affected wolfi pulumi-language-yaml
rclone affected wolfi rclone
rclone affected chainguard rclone
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
sops affected chainguard sops
sops affected wolfi sops
spire-server affected chainguard spire-server
spire-server affected wolfi spire-server
spire-server-fips affected chainguard spire-server-fips
syft affected chainguard syft
syft affected wolfi syft
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
terraform-provider-google affected wolfi terraform-provider-google
terraform-provider-google affected chainguard terraform-provider-google
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
tkn affected wolfi tkn
tkn affected chainguard tkn
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
wolfictl affected chainguard wolfictl
wolfictl affected wolfi wolfictl
zarf affected wolfi zarf
zarf affected chainguard zarf
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

GHSA-9763-4f94-gfch

GoogleAll remaining2024-01-08

CIRCL's Kyber: timing side-channel (kyberslash2)

Affected products

ProductStatusVendorPackageEcosystem
cloudflare/circl affected github.com github.com/cloudflare/circl
Upstream advisory

GHSA-9763-4f94-gfch

Open SourceAll remainingHIGH2024-01-08

CIRCL's Kyber: timing side-channel (kyberslash2)

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
actions-runner-controller affected chainguard actions-runner-controller
actions-runner-controller affected wolfi actions-runner-controller
apko affected wolfi apko
apko affected chainguard apko
argo-cd-2.9 affected wolfi argo-cd-2.9
argo-cd-2.9 affected chainguard argo-cd-2.9
argo-workflows affected wolfi argo-workflows
argo-workflows affected chainguard argo-workflows
boring-registry affected chainguard boring-registry
boring-registry affected wolfi boring-registry
cloudflare/circl affected github.com github.com/cloudflare/circl
cloudflare/circl affected github.com github.com/cloudflare/circl
cloudflare/circl affected github.com
cosign affected wolfi cosign
cosign affected chainguard cosign
cosign-fips affected chainguard cosign-fips
cosign-fips affected wolfi cosign-fips
crossplane affected chainguard crossplane
crossplane affected wolfi crossplane
crossplane-provider-aws affected wolfi crossplane-provider-aws
crossplane-provider-aws affected chainguard crossplane-provider-aws
crossplane-provider-aws-cloudformation affected wolfi crossplane-provider-aws-cloudformation
crossplane-provider-aws-cloudformation affected chainguard crossplane-provider-aws-cloudformation
crossplane-provider-aws-cloudfront affected wolfi crossplane-provider-aws-cloudfront
crossplane-provider-aws-cloudfront affected chainguard crossplane-provider-aws-cloudfront
crossplane-provider-aws-cloudwatchlogs affected chainguard crossplane-provider-aws-cloudwatchlogs
crossplane-provider-aws-cloudwatchlogs affected wolfi crossplane-provider-aws-cloudwatchlogs
crossplane-provider-aws-dynamodb affected wolfi crossplane-provider-aws-dynamodb
crossplane-provider-aws-dynamodb affected chainguard crossplane-provider-aws-dynamodb
crossplane-provider-aws-ec2 affected wolfi crossplane-provider-aws-ec2
crossplane-provider-aws-ec2 affected chainguard crossplane-provider-aws-ec2
crossplane-provider-aws-eks affected chainguard crossplane-provider-aws-eks
crossplane-provider-aws-eks affected wolfi crossplane-provider-aws-eks
crossplane-provider-aws-elasticache affected chainguard crossplane-provider-aws-elasticache
crossplane-provider-aws-elasticache affected wolfi crossplane-provider-aws-elasticache
crossplane-provider-aws-firehose affected wolfi crossplane-provider-aws-firehose
crossplane-provider-aws-firehose affected chainguard crossplane-provider-aws-firehose
crossplane-provider-aws-iam affected wolfi crossplane-provider-aws-iam
crossplane-provider-aws-iam affected chainguard crossplane-provider-aws-iam
crossplane-provider-aws-kinesis affected wolfi crossplane-provider-aws-kinesis
crossplane-provider-aws-kinesis affected chainguard crossplane-provider-aws-kinesis
crossplane-provider-aws-kms affected chainguard crossplane-provider-aws-kms
crossplane-provider-aws-kms affected wolfi crossplane-provider-aws-kms
crossplane-provider-aws-lambda affected wolfi crossplane-provider-aws-lambda
crossplane-provider-aws-lambda affected chainguard crossplane-provider-aws-lambda
crossplane-provider-aws-memorydb affected chainguard crossplane-provider-aws-memorydb
crossplane-provider-aws-memorydb affected wolfi crossplane-provider-aws-memorydb
crossplane-provider-aws-rds affected wolfi crossplane-provider-aws-rds
crossplane-provider-aws-rds affected chainguard crossplane-provider-aws-rds
crossplane-provider-aws-route53 affected chainguard crossplane-provider-aws-route53
crossplane-provider-aws-route53 affected wolfi crossplane-provider-aws-route53
crossplane-provider-aws-s3 affected wolfi crossplane-provider-aws-s3
crossplane-provider-aws-s3 affected chainguard crossplane-provider-aws-s3
crossplane-provider-aws-sns affected wolfi crossplane-provider-aws-sns
crossplane-provider-aws-sns affected chainguard crossplane-provider-aws-sns
crossplane-provider-aws-sqs affected chainguard crossplane-provider-aws-sqs
crossplane-provider-aws-sqs affected wolfi crossplane-provider-aws-sqs
crossplane-provider-family-aws affected wolfi crossplane-provider-family-aws
crossplane-provider-family-aws affected chainguard crossplane-provider-family-aws
falco affected wolfi falco
falco affected chainguard falco
falcoctl-fips affected chainguard falcoctl-fips
flux affected wolfi flux
flux affected chainguard flux
flux-0 affected chainguard flux-0
flux-0.37 affected chainguard flux-0.37
flux-2.0 affected chainguard flux-2.0
flux-image-automation-controller affected wolfi flux-image-automation-controller
flux-image-automation-controller affected chainguard flux-image-automation-controller
flux-image-automation-controller-0 affected chainguard flux-image-automation-controller-0
flux-kustomize-controller affected wolfi flux-kustomize-controller
flux-kustomize-controller affected chainguard flux-kustomize-controller
flux-kustomize-controller-2.0 affected chainguard flux-kustomize-controller-2.0
flux-notification-controller affected chainguard flux-notification-controller
flux-notification-controller affected wolfi flux-notification-controller
flux-notification-controller-0 affected chainguard flux-notification-controller-0
flux-notification-controller-2.0 affected chainguard flux-notification-controller-2.0
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller-0 affected chainguard flux-source-controller-0
flux-source-controller-0.37 affected chainguard flux-source-controller-0.37
flux-source-controller-2.0 affected chainguard flux-source-controller-2.0
github.com/cloudflare/circl affected Go github.com/cloudflare/circl
gitness affected chainguard gitness
gitness affected wolfi gitness
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
gomplate affected wolfi gomplate
gomplate affected chainguard gomplate
goreleaser affected chainguard goreleaser
goreleaser affected wolfi goreleaser
grafana affected chainguard grafana
grafana affected wolfi grafana
grafana-10.1 affected chainguard grafana-10.1
grafana-7 affected chainguard grafana-7
grafana-9.3 affected chainguard grafana-9.3
grype affected wolfi grype
grype affected chainguard grype
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
keda-2.11 affected chainguard keda-2.11
keda-2.11 affected wolfi keda-2.11
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
melange affected chainguard melange
melange affected wolfi melange
opentofu affected wolfi opentofu
opentofu affected chainguard opentofu
opentofu-1.6 affected chainguard opentofu-1.6
policy-controller affected chainguard policy-controller
policy-controller affected wolfi policy-controller
pulumi affected wolfi pulumi
pulumi affected chainguard pulumi
pulumi-kubernetes-operator affected chainguard pulumi-kubernetes-operator
pulumi-kubernetes-operator affected wolfi pulumi-kubernetes-operator
pulumi-language-dotnet affected chainguard pulumi-language-dotnet
pulumi-language-dotnet affected wolfi pulumi-language-dotnet
pulumi-language-java affected chainguard pulumi-language-java
pulumi-language-java affected wolfi pulumi-language-java
pulumi-language-yaml affected wolfi pulumi-language-yaml
pulumi-language-yaml affected chainguard pulumi-language-yaml
rclone affected wolfi rclone
rclone affected chainguard rclone
scorecard affected wolfi scorecard
scorecard affected chainguard scorecard
skaffold affected wolfi skaffold
skaffold affected chainguard skaffold
slsa-verifier affected chainguard slsa-verifier
slsa-verifier affected wolfi slsa-verifier
sops affected wolfi sops
sops affected chainguard sops
spire-server affected wolfi spire-server
spire-server affected chainguard spire-server
spire-server-fips affected chainguard spire-server-fips
syft affected wolfi syft
syft affected chainguard syft
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
terraform-provider-google affected wolfi terraform-provider-google
terraform-provider-google affected chainguard terraform-provider-google
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
tkn affected wolfi tkn
tkn affected chainguard tkn
vault-1.13 affected chainguard vault-1.13
vault-1.13 affected wolfi vault-1.13
vault-fips-1.14 affected chainguard vault-fips-1.14
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
wolfictl affected chainguard wolfictl
wolfictl affected wolfi wolfictl
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

GO-2023-2412

Open SourceAll remaining2024-01-02

RAPL accessibility in github.com/containerd/containerd

Affected products

ProductStatusVendorPackageEcosystem
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
containerd/containerd affected github.com github.com/containerd/containerd
ctop affected wolfi ctop
ctop affected chainguard ctop
eksctl affected wolfi eksctl
eksctl affected chainguard eksctl
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
fuse-overlayfs-snapshotter affected chainguard fuse-overlayfs-snapshotter
fuse-overlayfs-snapshotter affected wolfi fuse-overlayfs-snapshotter
gitness affected chainguard gitness
gitness affected wolfi gitness
grype affected chainguard grype
grype affected wolfi grype
helm affected chainguard helm
helm affected wolfi helm
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
k3d affected wolfi k3d
k3d affected chainguard k3d
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
kaniko affected chainguard kaniko
kaniko affected wolfi kaniko
kots affected chainguard kots
kots affected wolfi kots
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kubevela affected chainguard kubevela
kubevela affected wolfi kubevela
melange affected chainguard melange
melange affected wolfi melange
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
skaffold affected wolfi skaffold
skaffold affected chainguard skaffold
trivy affected chainguard trivy
trivy affected wolfi trivy
up affected chainguard up
up affected wolfi up
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.