Google Security Advisories · February 2024 — Google Security Advisories
217 advisories 131 CVEs 10 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2024-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 10 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

SUSE-SU-2024:0573-1

Open SourceExploitedCISA KEV listedCRITICAL2024-02-21

Security update for abseil-cpp, grpc, opencensus-proto, protobuf, python-abseil, python-grpcio, re2

Affected products

ProductStatusVendorPackageEcosystem
abseil-cpp affected SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise Workstation Extension 15 SP5 abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise Server for SAP Applications 15 SP4 abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise Module for Development Tools 15 SP5 abseil-cpp
abseil-cpp affected SUSE:Manager Proxy 4.3 abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise Micro 5.4 abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise Installer Updates 15 SP4 abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise Micro 5.5 abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise Micro 5.3 abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise Module for Basesystem 15 SP5 abseil-cpp
abseil-cpp affected openSUSE:Leap 15.5 abseil-cpp
abseil-cpp affected openSUSE:Leap Micro 5.4 abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise Installer Updates 15 SP5 abseil-cpp
abseil-cpp affected openSUSE:Leap Micro 5.3 abseil-cpp
abseil-cpp affected SUSE:Linux Enterprise Server 15 SP4-LTSS abseil-cpp
grpc affected SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS grpc
grpc affected openSUSE:Leap 15.5 grpc
grpc affected SUSE:Linux Enterprise Server for SAP Applications 15 SP4 grpc
grpc affected SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS grpc
grpc affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 grpc
grpc affected SUSE:Manager Proxy 4.3 grpc
grpc affected SUSE:Linux Enterprise Module for Public Cloud 15 SP5 grpc
grpc affected SUSE:Linux Enterprise Server 15 SP4-LTSS grpc
grpc affected SUSE:Linux Enterprise Module for Basesystem 15 SP5 grpc
opencensus-proto affected openSUSE:Leap 15.5 opencensus-proto
protobuf affected openSUSE:Leap Micro 5.4 protobuf
protobuf affected SUSE:Linux Enterprise Installer Updates 15 SP4 protobuf
protobuf affected SUSE:Linux Enterprise Installer Updates 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.3 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.4 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.5 protobuf
protobuf affected SUSE:Linux Enterprise Module for Basesystem 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise Module for Development Tools 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise Module for Package Hub 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 protobuf
protobuf affected SUSE:Linux Enterprise Module for Public Cloud 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise Module for Python 3 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS protobuf
protobuf affected SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS protobuf
protobuf affected SUSE:Linux Enterprise Server 15 SP4-LTSS protobuf
protobuf affected SUSE:Linux Enterprise Server for SAP Applications 15 SP4 protobuf
protobuf affected SUSE:Manager Proxy 4.3 protobuf
protobuf affected openSUSE:Leap Micro 5.3 protobuf
protobuf affected openSUSE:Leap 15.5 protobuf
python-abseil affected SUSE:Linux Enterprise Module for Python 3 15 SP5 python-abseil
python-abseil affected openSUSE:Leap 15.5 python-abseil
python-grpcio affected openSUSE:Leap 15.5 python-grpcio
python-grpcio affected SUSE:Linux Enterprise Module for Python 3 15 SP5 python-grpcio
re2 affected SUSE:Linux Enterprise Module for Basesystem 15 SP5 re2
re2 affected openSUSE:Leap 15.5 re2
re2 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP4 re2
re2 affected SUSE:Linux Enterprise Server 15 SP4-LTSS re2
re2 affected SUSE:Manager Proxy 4.3 re2
re2 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS re2
re2 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS re2
re2 affected SUSE:Linux Enterprise Module for Public Cloud 15 SP5 re2
Upstream advisory

SUSE-SU-2024:0487-1

Open SourceExploitedCISA KEV listed2024-02-15

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Client Tools 15 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Proxy Module 4.3 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Server Module 4.3 golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter affected openSUSE:Leap 15.5 golang-github-lusitaniae-apache_exporter
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 15 golang-github-prometheus-prometheus
grafana affected SUSE:Manager Client Tools 15 grafana
mgr-daemon affected SUSE:Manager Client Tools 15 mgr-daemon
prometheus-postgres_exporter affected openSUSE:Leap 15.5 prometheus-postgres_exporter
prometheus-postgres_exporter affected SUSE:Manager Client Tools 15 prometheus-postgres_exporter
spacecmd affected SUSE:Manager Client Tools 15 spacecmd
spacecmd affected openSUSE:Leap 15.5 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 15 spacewalk-client-tools
uyuni-proxy-systemd-services affected SUSE:Manager Client Tools for SLE Micro 5 uyuni-proxy-systemd-services
uyuni-proxy-systemd-services affected SUSE:Manager Client Tools 15 uyuni-proxy-systemd-services
Upstream advisory

SUSE-SU-2024:0486-1

Open SourceExploitedCISA KEV listedCRITICAL2024-02-15

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-lusitaniae-apache_exporter affected SUSE:Manager Client Tools 12 golang-github-lusitaniae-apache_exporter
golang-github-prometheus-alertmanager affected SUSE:Manager Client Tools 12 golang-github-prometheus-alertmanager
golang-github-prometheus-prometheus affected SUSE:Manager Client Tools 12 golang-github-prometheus-prometheus
grafana affected SUSE:Manager Client Tools 12 grafana
mgr-daemon affected SUSE:Manager Client Tools 12 mgr-daemon
prometheus-postgres_exporter affected SUSE:Manager Client Tools 12 prometheus-postgres_exporter
spacecmd affected SUSE:Manager Client Tools 12 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 12 spacewalk-client-tools
Upstream advisory

CVE-2024-21338

GoogleExploitedCISA KEV listedCRITICAL2024-02-13

Windows Kernel Elevation of Privilege Vulnerability

CVEs:CVE-2024-21338

Affected products

ProductStatusVendorPackageEcosystem
Windows affected Microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_21h2 affected microsoft
windows_11_22h2 affected microsoft
windows_11_23h2 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_2022_23h2 affected microsoft
Upstream advisory

CVE-2024-44308

Project ZeroExploitedCISA KEV listed2024-02-05

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

CVEs:CVE-2024-44308

Upstream advisory

CVE-2024-44308

GoogleExploitedCISA KEV listedCRITICAL2024-02-05

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code ...

CVEs:CVE-2024-44308

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2024-44308

GoogleExploitedCISA KEV listed2024-02-05

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

CVEs:CVE-2024-44308

Upstream advisory

RHSA-2024:0797

Open SourceActive exploitation (sightings)HIGH2024-02-13

Red Hat Security Advisory: Satellite 6.14.2 Async Security Update

Affected products

ProductStatusVendorPackageEcosystem
candlepin affected Red Hat:satellite:6.14::el8 candlepin
candlepin-selinux affected Red Hat:satellite:6.14::el8 candlepin-selinux
mosquitto affected Red Hat:satellite_capsule:6.14::el8 mosquitto
mosquitto affected Red Hat:satellite:6.14::el8 mosquitto
mosquitto-debuginfo affected Red Hat:satellite:6.14::el8 mosquitto-debuginfo
mosquitto-debuginfo affected Red Hat:satellite_capsule:6.14::el8 mosquitto-debuginfo
mosquitto-debugsource affected Red Hat:satellite:6.14::el8 mosquitto-debugsource
mosquitto-debugsource affected Red Hat:satellite_capsule:6.14::el8 mosquitto-debugsource
puppet-agent affected Red Hat:satellite:6.14::el8 puppet-agent
puppet-agent affected Red Hat:satellite_capsule:6.14::el8 puppet-agent
puppetserver affected Red Hat:satellite_capsule:6.14::el8 puppetserver
puppetserver affected Red Hat:satellite:6.14::el8 puppetserver
rubygem-grpc affected Red Hat:satellite:6.14::el8 rubygem-grpc
rubygem-puma affected Red Hat:satellite:6.14::el8 rubygem-puma
rubygem-puma-debuginfo affected Red Hat:satellite:6.14::el8 rubygem-puma-debuginfo
rubygem-puma-debugsource affected Red Hat:satellite:6.14::el8 rubygem-puma-debugsource
rubygem-sidekiq affected Red Hat:satellite:6.14::el8 rubygem-sidekiq
Upstream advisory

DSA-5629-1

Open SourceActive exploitation (sightings)2024-02-23

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

DSA-5617-1

Open SourceActive exploitation (sightings)2024-02-08

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2024-1283

Open SourceActive exploitation (sightings)CRITICAL2024-02-07

DEBIAN-CVE-2024-1283

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1283

GoogleActive exploitation (sightings)CRITICAL2024-02-06

Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1283

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-78w9-qxr3-hqhc

Open SourceActive exploitation (sightings)CRITICAL2024-02-21

GHSA-78w9-qxr3-hqhc

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-1675

Open SourceActive exploitation (sightings)CRITICAL2024-02-21

DEBIAN-CVE-2024-1675

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1675

GoogleActive exploitation (sightings)2024-02-20

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-1675

Upstream advisory

CVE-2024-1675

GoogleActive exploitation (sightings)CRITICAL2024-02-20

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-1675

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-7f39-34rh-fghp

Open SourceActive exploitation (sightings)HIGH2024-02-29

GHSA-7f39-34rh-fghp

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-1939

Open SourceActive exploitation (sightings)HIGH2024-02-29

DEBIAN-CVE-2024-1939

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

DSA-5634-1

Open SourceActive exploitation (sightings)2024-02-28

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

CVE-2024-1939

GoogleActive exploitation (sightings)2024-02-27

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1939

Upstream advisory

CVE-2024-1939

GoogleActive exploitation (sightings)HIGH2024-02-27

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1939

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-26192

Open SourceActive exploitation (sightings)HIGH2024-02-13

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVEs:CVE-2024-26192

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2024-21399

Open SourceActive exploitation (sightings)CRITICAL2024-02-01

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2024-21399

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2024-21376

Open SourceActive exploitation (sightings)CRITICAL2024-02-13

Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

CVEs:CVE-2024-21376

Affected products

ProductStatusVendorPackageEcosystem
azure_kubernetes_service affected microsoft
Upstream advisory

DEBIAN-CVE-2024-1284

Open SourceActive exploitation (sightings)CRITICAL2024-02-07

DEBIAN-CVE-2024-1284

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1284

GoogleActive exploitation (sightings)CRITICAL2024-02-06

Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1284

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-rm97-x556-q36h

GoogleActive exploitation (sightings)MEDIUM2024-02-24

sanitize-html Information Exposure vulnerability

Affected products

ProductStatusVendorPackageEcosystem
sanitize-html affected npm sanitize-html
Upstream advisory

GHSA-rm97-x556-q36h

Open SourceActive exploitation (sightings)MEDIUM2024-02-24

sanitize-html Information Exposure vulnerability

Affected products

ProductStatusVendorPackageEcosystem
py3-jupyterlab affected chainguard py3-jupyterlab
py3-jupyterlab affected wolfi py3-jupyterlab
sanitize-html affected npm sanitize-html
tensorflow-cpu-jupyter affected chainguard tensorflow-cpu-jupyter
Upstream advisory

DSA-5612-1

Open SourceActive exploitation (sightings)2024-02-01

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

GHSA-5p54-7x9q-259p

Open SourceActive exploitation (sightings)HIGH2024-02-29

GHSA-5p54-7x9q-259p

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-1938

Open SourceActive exploitation (sightings)HIGH2024-02-29

DEBIAN-CVE-2024-1938

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1938

GoogleActive exploitation (sightings)2024-02-27

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1938

Upstream advisory

CVE-2024-1938

GoogleActive exploitation (sightings)HIGH2024-02-27

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1938

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-672f-vpw8-x67x

Open SourceActive exploitation (sightings)CRITICAL2024-02-21

GHSA-672f-vpw8-x67x

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-1673

Open SourceActive exploitation (sightings)CRITICAL2024-02-21

DEBIAN-CVE-2024-1673

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1673

GoogleActive exploitation (sightings)2024-02-20

Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

CVEs:CVE-2024-1673

Upstream advisory

CVE-2024-1673

GoogleActive exploitation (sightings)CRITICAL2024-02-20

Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

CVEs:CVE-2024-1673

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-frg3-hm7v-3rpf

Open SourceActive exploitation (sightings)MEDIUM2024-02-21

GHSA-frg3-hm7v-3rpf

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-1671

Open SourceActive exploitation (sightings)MEDIUM2024-02-21

DEBIAN-CVE-2024-1671

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1671

GoogleActive exploitation (sightings)MEDIUM2024-02-20

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-1671

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-1671

GoogleActive exploitation (sightings)2024-02-20

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-1671

Upstream advisory

CVE-2023-51504

GoogleActive exploitation (sightings)CRITICAL2024-02-05

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2.

CVEs:CVE-2023-51504

Affected products

ProductStatusVendorPackageEcosystem
dan\'s_embedder_for_google_calendar affected dandulaney
Upstream advisory

CVE-2023-6884

GoogleActive exploitation (sightings)HIGH2024-02-05

This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible f...

CVEs:CVE-2023-6884

Affected products

ProductStatusVendorPackageEcosystem
plugin_for_google_reviews affected richplugins
Upstream advisory

CVE-2024-1562

GoogleActive exploitation (sightings)HIGH2024-02-21

The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for ...

CVEs:CVE-2024-1562

Affected products

ProductStatusVendorPackageEcosystem
woocommerce_google_sheet_connector affected gsheetconnector
Upstream advisory

CVE-2024-20815

Open SourceActive exploitation (sightings)HIGH2024-02-05

Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

CVEs:CVE-2024-20815

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20816

Open SourceActive exploitation (sightings)HIGH2024-02-05

Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

CVEs:CVE-2024-20816

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-27294

Open SourceActive exploitation (sightings)HIGH2024-02-29

dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version 1.4.3 throug...

CVEs:CVE-2024-27294

Affected products

ProductStatusVendorPackageEcosystem
dp-golang affected danielparks
Upstream advisory

CVE-2024-20813

Open SourceActive exploitation (sightings)HIGH2024-02-05

Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2024-20813

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20820

Open SourceActive exploitation (sightings)HIGH2024-02-05

Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.

CVEs:CVE-2024-20820

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20814

Open SourceActive exploitation (sightings)MEDIUM2024-02-05

Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.

CVEs:CVE-2024-20814

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20812

Open SourceActive exploitation (sightings)HIGH2024-02-05

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

CVEs:CVE-2024-20812

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20817

Open SourceActive exploitation (sightings)HIGH2024-02-05

Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

CVEs:CVE-2024-20817

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20818

Open SourceActive exploitation (sightings)HIGH2024-02-05

Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

CVEs:CVE-2024-20818

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20819

Open SourceActive exploitation (sightings)HIGH2024-02-05

Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

CVEs:CVE-2024-20819

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20810

Open SourceActive exploitation (sightings)MEDIUM2024-02-05

Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.

CVEs:CVE-2024-20810

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20811

Open SourceActive exploitation (sightings)MEDIUM2024-02-05

Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.

CVEs:CVE-2024-20811

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-20002

Open SourceActive exploitation (sightings)HIGH2024-02-05

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961715; Issue ID:...

CVEs:CVE-2024-20002

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20013

Open SourceActive exploitation (sightings)HIGH2024-02-05

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08471742; Iss...

CVEs:CVE-2024-20013

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-295051806

GoogleActive exploitation (sightings)2024-02-01

PUB-A-295051806

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-295051886

GoogleActive exploitation (sightings)2024-02-01

PUB-A-295051886

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-295052084

GoogleActive exploitation (sightings)2024-02-01

PUB-A-295052084

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-295052588

GoogleActive exploitation (sightings)2024-02-01

PUB-A-295052588

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20001

Open SourceActive exploitation (sightings)HIGH2024-02-05

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961601; Issue ID:...

CVEs:CVE-2024-20001

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20016

Open SourceActive exploitation (sightings)HIGH2024-02-05

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation Patch ID: ALPS07835901; Issue ID: ALPS07835901.

CVEs:CVE-2024-20016

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-295052332

GoogleActive exploitation (sightings)2024-02-01

PUB-A-295052332

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20015

Open SourceActive exploitation (sightings)HIGH2024-02-05

In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441...

CVEs:CVE-2024-20015

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20012

Open SourceActive exploitation (sightings)MEDIUM2024-02-05

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue I...

CVEs:CVE-2024-20012

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-22012

Open SourceActive exploitation (sightings)HIGH2024-02-05

there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-22012

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-309407679

GoogleActive exploitation (sightings)HIGH2024-02-01

PUB-A-309407679

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-0040

Open SourcePoC exploitHIGH2024-02-05

In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-0040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-4w4v-5hc9-xrr2

Open SourcePoC exploitHIGH2024-02-10

angular vulnerable to super-linear runtime due to backtracking

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
org.webjars.bower:angular affected Maven org.webjars.bower:angular
org.webjars.npm:angular affected Maven org.webjars.npm:angular
solr affected chainguard solr
solr affected wolfi solr
Upstream advisory

GHSA-4w4v-5hc9-xrr2

Open SourcePoC exploitHIGH2024-02-10

angular vulnerable to super-linear runtime due to backtracking

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
org.webjars.bower:angular affected Maven org.webjars.bower:angular
org.webjars.npm:angular affected Maven org.webjars.npm:angular
Upstream advisory

DEBIAN-CVE-2024-21490

Open SourcePoC exploitHIGH2024-02-10

DEBIAN-CVE-2024-21490

Affected products

ProductStatusVendorPackageEcosystem
angular.js affected Debian:12 angular.js
angular.js affected Debian:11 angular.js
angular.js affected Debian:13 angular.js
angular.js affected Debian:14 angular.js
Upstream advisory

CVE-2024-21490

Open SourcePoC exploitHIGH2024-02-10

angular vulnerable to super-linear runtime due to backtracking

CVEs:CVE-2024-21490

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
org.webjars.bower:angular affected Maven org.webjars.bower:angular
org.webjars.npm:angular affected Maven org.webjars.npm:angular
Upstream advisory

CVE-2024-21490

Open SourcePoC exploitHIGH2024-02-10

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large careful...

CVEs:CVE-2024-21490

Affected products

ProductStatusVendorPackageEcosystem
angular.js affected angularjs
angular.js affected angularjs
Upstream advisory

CVE-2024-21490

Open SourcePoC exploitHIGH2024-02-10

angular vulnerable to super-linear runtime due to backtracking

CVEs:CVE-2024-21490

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
org.webjars.bower:angular affected Maven org.webjars.bower:angular
org.webjars.npm:angular affected Maven org.webjars.npm:angular
Upstream advisory

CVE-2024-24786

Open SourcePoC exploitHIGH2024-02-29

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

CVEs:CVE-2024-24786

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected google.golang.org google.golang.org/protobuf
protobuf/encoding/protojson affected google.golang.org google.golang.org/protobuf/encoding/protojson
protobuf/internal/encoding/json affected google.golang.org google.golang.org/protobuf/internal/encoding/json
Upstream advisory

CVE-2024-24786

GooglePoC exploitHIGH2024-02-29

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnkno...

CVEs:CVE-2024-24786

Upstream advisory

CVE-2024-24786

GooglePoC exploit2024-02-29

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

CVEs:CVE-2024-24786

Upstream advisory

RHSA-2024:1041

Open SourcePoC exploitHIGH2024-02-29

Red Hat Security Advisory: go-toolset-1.19-golang security update

Affected products

ProductStatusVendorPackageEcosystem
go-toolset-1.19-golang affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang
go-toolset-1.19-golang-bin affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-bin
go-toolset-1.19-golang-docs affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-docs
go-toolset-1.19-golang-misc affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-misc
go-toolset-1.19-golang-race affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-race
go-toolset-1.19-golang-src affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-src
go-toolset-1.19-golang-tests affected Red Hat:devtools:2023::el7 go-toolset-1.19-golang-tests
Upstream advisory

RHSA-2024:0887

Open SourcePoC exploitHIGH2024-02-20

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

ALSA-2024:0887

Open SourcePoC exploitCRITICAL2024-02-20

Moderate: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected AlmaLinux:8 delve
golang affected AlmaLinux:8 golang
golang-bin affected AlmaLinux:8 golang-bin
golang-docs affected AlmaLinux:8 golang-docs
golang-misc affected AlmaLinux:8 golang-misc
golang-src affected AlmaLinux:8 golang-src
golang-tests affected AlmaLinux:8 golang-tests
go-toolset affected AlmaLinux:8 go-toolset
Upstream advisory

CVE-2024-0031

Open SourcePoC exploitCRITICAL2024-02-05

In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2024-0031

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0030

Open SourcePoC exploitMEDIUM2024-02-05

In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2024-0030

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-xw73-rw38-6vjc

GooglePoC exploitHIGH2024-02-01

Classic builder cache poisoning

Affected products

ProductStatusVendorPackageEcosystem
docker/docker affected github.com github.com/docker/docker
moby/moby affected github.com github.com/moby/moby
Upstream advisory

GHSA-xw73-rw38-6vjc

Open SourcePoC exploitHIGH2024-02-01

Classic builder cache poisoning

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
argo-workflows affected wolfi argo-workflows
argo-workflows affected chainguard argo-workflows
argo-workflows-fips affected chainguard argo-workflows-fips
bom affected chainguard bom
bom affected wolfi bom
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
cadvisor affected wolfi cadvisor
cadvisor affected chainguard cadvisor
cadvisor-fips affected chainguard cadvisor-fips
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-1.13 affected wolfi cert-manager-1.13
cert-manager-1.14 affected chainguard cert-manager-1.14
cert-manager-1.14 affected wolfi cert-manager-1.14
cert-manager-fips-1.12 affected chainguard cert-manager-fips-1.12
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
cert-manager-fips-1.14 affected chainguard cert-manager-fips-1.14
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
cosign affected chainguard cosign
cosign affected wolfi cosign
cosign-fips affected chainguard cosign-fips
cosign-fips affected wolfi cosign-fips
crane affected chainguard crane
crane affected wolfi crane
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
ctop affected chainguard ctop
ctop affected wolfi ctop
dagger affected wolfi dagger
dagger affected chainguard dagger
datadog-agent affected wolfi datadog-agent
datadog-agent affected chainguard datadog-agent
datadog-agent-fips affected chainguard datadog-agent-fips
docker affected wolfi docker
docker affected chainguard docker
docker-credential-gcr affected wolfi docker-credential-gcr
docker-credential-gcr affected chainguard docker-credential-gcr
docker/docker affected github.com github.com/docker/docker
docker-machine-driver-harvester affected wolfi docker-machine-driver-harvester
docker-machine-driver-harvester affected chainguard docker-machine-driver-harvester
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
falco affected chainguard falco
falco affected wolfi falco
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
falcoctl-fips affected chainguard falcoctl-fips
falcoctl-fips-0.4 affected chainguard falcoctl-fips-0.4
filebeat affected chainguard filebeat
filebeat affected wolfi filebeat
filebeat-fips affected chainguard filebeat-fips
flux affected chainguard flux
flux affected wolfi flux
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-image-reflector-controller affected wolfi flux-image-reflector-controller
flux-image-reflector-controller affected chainguard flux-image-reflector-controller
gitlab-rails-ee-17.0 affected chainguard gitlab-rails-ee-17.0
gitlab-rails-ee-17.3 affected chainguard gitlab-rails-ee-17.3
gitlab-rails-ee-fips-17.0 affected chainguard gitlab-rails-ee-fips-17.0
gitlab-rails-ee-fips-17.2 affected chainguard gitlab-rails-ee-fips-17.2
gitlab-runner affected wolfi gitlab-runner
gitlab-runner affected chainguard gitlab-runner
gitlab-runner-fips-17.0 affected chainguard gitlab-runner-fips-17.0
gitsign affected chainguard gitsign
gitsign affected wolfi gitsign
goreleaser affected wolfi goreleaser
goreleaser affected chainguard goreleaser
goreleaser-1.18 affected wolfi goreleaser-1.18
goreleaser-1.18 affected chainguard goreleaser-1.18
guac affected chainguard guac
guac affected wolfi guac
helm affected chainguard helm
helm affected wolfi helm
helm-3 affected chainguard helm-3
helm-3 affected wolfi helm-3
helm-4 affected wolfi helm-4
helm-4 affected chainguard helm-4
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected chainguard helm-operator
helm-operator affected wolfi helm-operator
helm-operator-fips affected chainguard helm-operator-fips
istio-fips-1.20 affected chainguard istio-fips-1.20
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-fips-1.19 affected chainguard istio-operator-fips-1.19
istio-pilot-agent-1.19 affected chainguard istio-pilot-agent-1.19
istio-pilot-agent-1.19 affected wolfi istio-pilot-agent-1.19
istio-pilot-agent-1.20 affected wolfi istio-pilot-agent-1.20
istio-pilot-agent-1.20 affected chainguard istio-pilot-agent-1.20
istio-pilot-agent-1.21 affected chainguard istio-pilot-agent-1.21
istio-pilot-agent-1.21 affected wolfi istio-pilot-agent-1.21
istio-pilot-agent-fips-1.19 affected chainguard istio-pilot-agent-fips-1.19
istio-pilot-discovery-1.19 affected chainguard istio-pilot-discovery-1.19
istio-pilot-discovery-1.19 affected wolfi istio-pilot-discovery-1.19
istio-pilot-discovery-1.20 affected chainguard istio-pilot-discovery-1.20
istio-pilot-discovery-1.20 affected wolfi istio-pilot-discovery-1.20
istio-pilot-discovery-1.21 affected chainguard istio-pilot-discovery-1.21
istio-pilot-discovery-1.21 affected wolfi istio-pilot-discovery-1.21
istio-pilot-discovery-fips-1.19 affected chainguard istio-pilot-discovery-fips-1.19
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k9s affected chainguard k9s
k9s affected wolfi k9s
kargo affected chainguard kargo
kargo affected wolfi kargo
ko-fips affected wolfi ko-fips
ko-fips affected chainguard ko-fips
kots affected chainguard kots
kots affected wolfi kots
kpt affected chainguard kpt
kpt affected wolfi kpt
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
kyverno affected chainguard kyverno
kyverno affected wolfi kyverno
loki affected chainguard loki
loki affected wolfi loki
loki-2.9 affected chainguard loki-2.9
moby/moby affected github.com github.com/moby/moby
nerdctl affected chainguard nerdctl
nerdctl affected wolfi nerdctl
newrelic-infrastructure-agent affected chainguard newrelic-infrastructure-agent
newrelic-infrastructure-agent affected wolfi newrelic-infrastructure-agent
newrelic-infrastructure-agent-1.43 affected chainguard newrelic-infrastructure-agent-1.43
policy-controller affected chainguard policy-controller
policy-controller affected wolfi policy-controller
policy-controller-fips affected chainguard policy-controller-fips
prometheus affected wolfi prometheus
prometheus affected chainguard prometheus
prometheus-2.45 affected chainguard prometheus-2.45
prometheus-2.45 affected wolfi prometheus-2.45
prometheus-2.50 affected wolfi prometheus-2.50
prometheus-2.50 affected chainguard prometheus-2.50
prometheus-fips affected chainguard prometheus-fips
prometheus-fips-2.45 affected chainguard prometheus-fips-2.45
pulumi affected chainguard pulumi
pulumi affected wolfi pulumi
rancher-2.10 affected chainguard rancher-2.10
rancher-2.10 affected wolfi rancher-2.10
rancher-2.11 affected chainguard rancher-2.11
rancher-2.11 affected wolfi rancher-2.11
rancher-agent-2.10 affected wolfi rancher-agent-2.10
rancher-agent-2.10 affected chainguard rancher-agent-2.10
rancher-agent-2.11 affected wolfi rancher-agent-2.11
rancher-agent-2.11 affected chainguard rancher-agent-2.11
rancher-agent-2.9 affected wolfi rancher-agent-2.9
rancher-agent-2.9 affected chainguard rancher-agent-2.9
rancher-machine affected wolfi rancher-machine
rancher-machine affected chainguard rancher-machine
scorecard affected chainguard scorecard
scorecard affected wolfi scorecard
skaffold affected chainguard skaffold
skaffold affected wolfi skaffold
skopeo affected wolfi skopeo
skopeo affected chainguard skopeo
slsa-verifier affected wolfi slsa-verifier
slsa-verifier affected chainguard slsa-verifier
tekton-chains affected chainguard tekton-chains
tekton-chains affected wolfi tekton-chains
tekton-pipelines affected wolfi tekton-pipelines
tekton-pipelines affected chainguard tekton-pipelines
telegraf-1.26 affected wolfi telegraf-1.26
telegraf-1.26 affected chainguard telegraf-1.26
telegraf-1.27 affected chainguard telegraf-1.27
telegraf-1.27 affected wolfi telegraf-1.27
telegraf-1.28 affected wolfi telegraf-1.28
telegraf-1.28 affected chainguard telegraf-1.28
telegraf-1.29 affected chainguard telegraf-1.29
telegraf-1.29 affected wolfi telegraf-1.29
telegraf-1.30 affected wolfi telegraf-1.30
telegraf-1.30 affected chainguard telegraf-1.30
timoni affected chainguard timoni
timoni affected wolfi timoni
traefik affected chainguard traefik
traefik affected wolfi traefik
traefik-fips affected chainguard traefik-fips
trivy affected wolfi trivy
trivy affected chainguard trivy
up affected wolfi up
up affected chainguard up
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
zarf affected wolfi zarf
zarf affected chainguard zarf
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

GHSA-r5qg-76hh-gr9p

Open SourceCoalition ESS < 30%CRITICAL2024-02-21

GHSA-r5qg-76hh-gr9p

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-1676

Open SourceCoalition ESS < 30%MEDIUM2024-02-21

DEBIAN-CVE-2024-1676

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1676

GoogleCoalition ESS < 30%CRITICAL2024-02-20

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-1676

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-1676

GoogleCoalition ESS < 30%2024-02-20

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-1676

Upstream advisory

GHSA-wjv4-j3hc-gxvv

Open SourceCoalition ESS < 30%CRITICAL2024-02-21

GHSA-wjv4-j3hc-gxvv

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-1670

Open SourceCoalition ESS < 30%CRITICAL2024-02-21

DEBIAN-CVE-2024-1670

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1670

GoogleCoalition ESS < 30%CRITICAL2024-02-20

Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1670

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-1670

GoogleCoalition ESS < 30%2024-02-20

Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1670

Upstream advisory

ASB-A-317829109

GoogleCoalition ESS < 30%2024-02-01

ASB-A-317829109

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-317829110

GoogleCoalition ESS < 30%2024-02-01

ASB-A-317829110

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-317826159

GoogleCoalition ESS < 30%2024-02-01

ASB-A-317826159

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-21403

Open SourceCoalition ESS < 30%CRITICAL2024-02-13

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

CVEs:CVE-2024-21403

Affected products

ProductStatusVendorPackageEcosystem
azure_kubernetes_service affected microsoft
Upstream advisory

ASB-A-317829112

GoogleCoalition ESS < 30%2024-02-01

ASB-A-317829112

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-f8gg-fh4p-4795

Open SourceCoalition ESS < 30%MEDIUM2024-02-21

GHSA-f8gg-fh4p-4795

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-1669

Open SourceCoalition ESS < 30%HIGH2024-02-21

DEBIAN-CVE-2024-1669

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2024-1669

GoogleCoalition ESS < 30%2024-02-20

Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1669

Upstream advisory

CVE-2024-1669

GoogleCoalition ESS < 30%HIGH2024-02-20

Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-1669

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

GHSA-r53h-jv2g-vpx6

GoogleCoalition ESS < 30%HIGH2024-02-22

Helm's Missing YAML Content Leads To Panic

Affected products

ProductStatusVendorPackageEcosystem
helm/v3 affected helm.sh helm.sh/helm/v3
Upstream advisory

GHSA-r53h-jv2g-vpx6

Open SourceCoalition ESS < 30%HIGH2024-02-22

Helm's Missing YAML Content Leads To Panic

Affected products

ProductStatusVendorPackageEcosystem
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-1.13 affected wolfi cert-manager-1.13
cert-manager-1.14 affected wolfi cert-manager-1.14
cert-manager-1.14 affected chainguard cert-manager-1.14
cert-manager-fips-1.12 affected chainguard cert-manager-fips-1.12
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
cert-manager-fips-1.14 affected chainguard cert-manager-fips-1.14
chartmuseum affected wolfi chartmuseum
chartmuseum affected chainguard chartmuseum
cilium-cli affected wolfi cilium-cli
cilium-cli affected chainguard cilium-cli
eksctl affected wolfi eksctl
eksctl affected chainguard eksctl
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected wolfi helm-operator
helm-operator affected chainguard helm-operator
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
helm/v3 affected helm.sh helm.sh/helm/v3
istio-fips-1.20 affected chainguard istio-fips-1.20
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-fips-1.19 affected chainguard istio-operator-fips-1.19
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
k9s affected wolfi k9s
k9s affected chainguard k9s
kots affected wolfi kots
kots affected chainguard kots
kots-compat affected chainguard kots-compat
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
trivy affected wolfi trivy
trivy affected chainguard trivy
up affected chainguard up
up affected wolfi up
zarf affected wolfi zarf
zarf affected chainguard zarf
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

GHSA-q8f8-rhx9-2qm4

Open SourceCoalition ESS < 30%HIGH2024-02-21

GHSA-q8f8-rhx9-2qm4

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-1672

Open SourceCoalition ESS < 30%MEDIUM2024-02-21

DEBIAN-CVE-2024-1672

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-1672

GoogleCoalition ESS < 30%HIGH2024-02-20

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-1672

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

CVE-2024-1672

GoogleCoalition ESS < 30%2024-02-20

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-1672

Upstream advisory

DEBIAN-CVE-2023-50658

Open SourceCoalition ESS < 30%HIGH2024-02-29

DEBIAN-CVE-2023-50658

Affected products

ProductStatusVendorPackageEcosystem
golang-github-dvsekhvalnov-jose2go affected Debian:11 golang-github-dvsekhvalnov-jose2go
golang-github-dvsekhvalnov-jose2go affected Debian:12 golang-github-dvsekhvalnov-jose2go
golang-github-dvsekhvalnov-jose2go affected Debian:13 golang-github-dvsekhvalnov-jose2go
golang-github-dvsekhvalnov-jose2go affected Debian:14 golang-github-dvsekhvalnov-jose2go
Upstream advisory

GHSA-29vg-wcmp-5fp9

Open SourceCoalition ESS < 30%HIGH2024-02-21

GHSA-29vg-wcmp-5fp9

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2024-1674

Open SourceCoalition ESS < 30%HIGH2024-02-21

DEBIAN-CVE-2024-1674

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2024-1674

GoogleCoalition ESS < 30%2024-02-20

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-1674

Upstream advisory

CVE-2024-1674

GoogleCoalition ESS < 30%HIGH2024-02-20

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-1674

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
Upstream advisory

SUSE-SU-2024:0512-1

Open SourceCoalition ESS < 30%CRITICAL2024-02-15

Security update for golang-github-prometheus-alertmanager

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-alertmanager affected SUSE:Manager Proxy Module 4.3 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected SUSE:Manager Client Tools 15 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected SUSE:Linux Enterprise Module for Package Hub 15 SP5 golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager affected openSUSE:Leap 15.5 golang-github-prometheus-alertmanager
Upstream advisory

CVE-2024-21423

Open SourceCoalition ESS < 30%HIGH2024-02-13

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVEs:CVE-2024-21423

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GO-2024-2554

Open SourceCoalition ESS < 30%HIGH2024-02-29

Path traversal in helm.sh/helm/v3

Affected products

ProductStatusVendorPackageEcosystem
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
flux-helm-controller affected wolfi flux-helm-controller
flux-helm-controller affected chainguard flux-helm-controller
flux-source-controller affected chainguard flux-source-controller
flux-source-controller affected wolfi flux-source-controller
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected chainguard helm-operator
helm-operator affected wolfi helm-operator
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
helm/v3 affected helm.sh helm.sh/helm/v3
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k9s affected chainguard k9s
k9s affected wolfi k9s
kots affected chainguard kots
kots affected wolfi kots
kubescape affected wolfi kubescape
kubescape affected chainguard kubescape
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
trivy affected wolfi trivy
trivy affected chainguard trivy
up affected wolfi up
up affected chainguard up
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

GHSA-v53g-5gjp-272r

Open SourceCoalition ESS < 30%HIGH2024-02-15

Helm dependency management path traversal

Affected products

ProductStatusVendorPackageEcosystem
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.13 affected chainguard cert-manager-1.13
cert-manager-1.13 affected wolfi cert-manager-1.13
cert-manager-1.14 affected wolfi cert-manager-1.14
cert-manager-1.14 affected chainguard cert-manager-1.14
cert-manager-fips-1.12 affected chainguard cert-manager-fips-1.12
cert-manager-fips-1.13 affected chainguard cert-manager-fips-1.13
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-source-controller affected wolfi flux-source-controller
flux-source-controller affected chainguard flux-source-controller
helm-fips affected chainguard helm-fips
helm-fips-3 affected chainguard helm-fips-3
helm-fips-4 affected chainguard helm-fips-4
helm-operator affected chainguard helm-operator
helm-operator affected wolfi helm-operator
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
helm/v3 affected helm.sh helm.sh/helm/v3
istio-fips-1.20 affected chainguard istio-fips-1.20
istio-operator-1.19 affected wolfi istio-operator-1.19
istio-operator-1.19 affected chainguard istio-operator-1.19
istio-operator-1.20 affected wolfi istio-operator-1.20
istio-operator-1.20 affected chainguard istio-operator-1.20
istio-operator-fips-1.19 affected chainguard istio-operator-fips-1.19
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
k9s affected wolfi k9s
k9s affected chainguard k9s
kots affected chainguard kots
kots affected wolfi kots
kots-compat affected chainguard kots-compat
kubescape affected chainguard kubescape
kubescape affected wolfi kubescape
kubevela affected wolfi kubevela
kubevela affected chainguard kubevela
trivy affected chainguard trivy
trivy affected wolfi trivy
up affected wolfi up
up affected chainguard up
zarf affected wolfi zarf
zarf affected chainguard zarf
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

GHSA-v53g-5gjp-272r

GoogleCoalition ESS < 30%HIGH2024-02-15

Helm dependency management path traversal

Affected products

ProductStatusVendorPackageEcosystem
helm/v3 affected helm.sh helm.sh/helm/v3
Upstream advisory

CVE-2024-23314

Open SourceCoalition ESS < 30%HIGH2024-02-14

When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVEs:CVE-2024-23314

Affected products

ProductStatusVendorPackageEcosystem
big-ip_access_policy_manager affected f5
big-ip_advanced_firewall_manager affected f5
big-ip_analytics affected f5
big-ip_application_acceleration_manager affected f5
big-ip_application_security_manager affected f5
big-ip_domain_name_system affected f5
big-ip_fraud_protection_service affected f5
big-ip_global_traffic_manager affected f5
big-ip_link_controller affected f5
big-ip_local_traffic_manager affected f5
big-ip_next_service_proxy_for_kubernetes affected f5
big-ip_policy_enforcement_manager affected f5
big-iq_centralized_management affected f5
Upstream advisory

CVE-2022-42443

Open SourceCoalition ESS < 30%CRITICAL2024-02-17

An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploading of files. IBM X-Force ID: 238535.

CVEs:CVE-2022-42443

Affected products

ProductStatusVendorPackageEcosystem
trusteer_android_sdk_for_mobile affected ibm
trusteer_ios_sdk_for_mobile affected ibm
Upstream advisory

CVE-2024-0032

Open SourceCoalition ESS < 30%MEDIUM2024-02-05

In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed f...

CVEs:CVE-2024-0032

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20011

Open SourceCoalition ESS < 30%CRITICAL2024-02-05

In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS084411...

CVEs:CVE-2024-20011

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-314698315

GoogleCoalition ESS < 30%2024-02-01

ASB-A-314698315

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20009

Open SourceCoalition ESS < 30%HIGH2024-02-05

In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08...

CVEs:CVE-2024-20009

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-314698313

GoogleCoalition ESS < 30%2024-02-01

ASB-A-314698313

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

AZL-34456

Open SourceCoalition ESS < 30%HIGH2024-02-23

CVE-2024-25629 affecting package grpc for versions less than 1.42.0-9

Affected products

ProductStatusVendorPackageEcosystem
grpc affected Azure Linux:2 grpc
Upstream advisory

CVE-2023-40122

Open SourceCoalition ESS < 30%MEDIUM2024-02-05

In applyCustomDescription of SaveUi.java, there is a possible way to view other user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2023-40122

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20007

Open SourceCoalition ESS < 30%HIGH2024-02-05

In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441369; Issu...

CVEs:CVE-2024-20007

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-314698312

GoogleCoalition ESS < 30%2024-02-01

ASB-A-314698312

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20006

Open SourceCoalition ESS < 30%HIGH2024-02-05

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477148; Issue ID: A...

CVEs:CVE-2024-20006

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
rdk-b affected rdkcentral
Upstream advisory

ASB-A-314707751

GoogleCoalition ESS < 30%2024-02-01

ASB-A-314707751

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-308188986

GoogleCoalition ESS < 30%2024-02-01

ASB-A-308188986

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-0033

Open SourceCoalition ESS < 30%HIGH2024-02-05

In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-0033

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-298150556

GoogleCoalition ESS < 30%2024-02-01

ASB-A-298150556

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-301630648

GoogleCoalition ESS < 30%2024-02-01

ASB-A-301630648

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-0029

Open SourceCoalition ESS < 30%HIGH2024-02-05

In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...

CVEs:CVE-2024-0029

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0014

Open SourceCoalition ESS < 30%HIGH2024-02-05

In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2024-0014

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-304082474

GoogleCoalition ESS < 30%NONE2024-02-01

ASB-A-304082474

Affected products

ProductStatusVendorPackageEcosystem
vendor/google/services/ConfigUpdater affected platform platform/vendor/google/services/ConfigUpdater
Upstream advisory

CVE-2024-0038

Open SourceCoalition ESS < 30%HIGH2024-02-05

In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed...

CVEs:CVE-2024-0038

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-40093

Open SourceCoalition ESS < 30%MEDIUM2024-02-05

In multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2023-40093

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0035

Open SourceCoalition ESS < 30%HIGH2024-02-05

In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...

CVEs:CVE-2024-0035

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0034

Open SourceCoalition ESS < 30%HIGH2024-02-05

In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2024-0034

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0036

Open SourceCoalition ESS < 30%HIGH2024-02-05

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privilege with no ad...

CVEs:CVE-2024-0036

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-0037

Open SourceCoalition ESS < 30%MEDIUM2024-02-05

In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is...

CVEs:CVE-2024-0037

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-303101658

GoogleCoalition ESS < 30%2024-02-01

ASB-A-303101658

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2024-0041

Open SourceCoalition ESS < 30%HIGH2024-02-05

In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution ...

CVEs:CVE-2024-0041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20010

Open SourceCoalition ESS < 30%MEDIUM2024-02-05

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358560; Issue I...

CVEs:CVE-2024-20010

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-314698314

GoogleCoalition ESS < 30%2024-02-01

ASB-A-314698314

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2023-30767

Open SourceEPSS <= 49%MEDIUM2024-02-14

Improper buffer restrictions in Intel(R) Optimization for TensorFlow before version 2.13.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVEs:CVE-2023-30767

Affected products

ProductStatusVendorPackageEcosystem
optimization_for_tensorflow affected intel
Upstream advisory

ASB-A-314032846

GoogleAll remaining2024-02-01

ASB-A-314032846

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-314033392

GoogleAll remaining2024-02-01

ASB-A-314033392

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.