Advisories
Open SourceExploitedCISA KEV listedCRITICAL2024-02-21
Security update for abseil-cpp, grpc, opencensus-proto, protobuf, python-abseil, python-grpcio, re2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| abseil-cpp |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise Workstation Extension 15 SP5 |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise Module for Development Tools 15 SP5 |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Manager Proxy 4.3 |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise Micro 5.4 |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise Installer Updates 15 SP4 |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise Micro 5.5 |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise Micro 5.3 |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise Module for Basesystem 15 SP5 |
abseil-cpp |
— |
| abseil-cpp |
affected |
openSUSE:Leap 15.5 |
abseil-cpp |
— |
| abseil-cpp |
affected |
openSUSE:Leap Micro 5.4 |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise Installer Updates 15 SP5 |
abseil-cpp |
— |
| abseil-cpp |
affected |
openSUSE:Leap Micro 5.3 |
abseil-cpp |
— |
| abseil-cpp |
affected |
SUSE:Linux Enterprise Server 15 SP4-LTSS |
abseil-cpp |
— |
| grpc |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS |
grpc |
— |
| grpc |
affected |
openSUSE:Leap 15.5 |
grpc |
— |
| grpc |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 |
grpc |
— |
| grpc |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS |
grpc |
— |
| grpc |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 |
grpc |
— |
| grpc |
affected |
SUSE:Manager Proxy 4.3 |
grpc |
— |
| grpc |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 |
grpc |
— |
| grpc |
affected |
SUSE:Linux Enterprise Server 15 SP4-LTSS |
grpc |
— |
| grpc |
affected |
SUSE:Linux Enterprise Module for Basesystem 15 SP5 |
grpc |
— |
| opencensus-proto |
affected |
openSUSE:Leap 15.5 |
opencensus-proto |
— |
| protobuf |
affected |
openSUSE:Leap Micro 5.4 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Installer Updates 15 SP4 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Installer Updates 15 SP5 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Micro 5.3 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Micro 5.4 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Micro 5.5 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Basesystem 15 SP5 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Development Tools 15 SP5 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Package Hub 15 SP5 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Module for Python 3 15 SP5 |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Server 15 SP4-LTSS |
protobuf |
— |
| protobuf |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 |
protobuf |
— |
| protobuf |
affected |
SUSE:Manager Proxy 4.3 |
protobuf |
— |
| protobuf |
affected |
openSUSE:Leap Micro 5.3 |
protobuf |
— |
| protobuf |
affected |
openSUSE:Leap 15.5 |
protobuf |
— |
| python-abseil |
affected |
SUSE:Linux Enterprise Module for Python 3 15 SP5 |
python-abseil |
— |
| python-abseil |
affected |
openSUSE:Leap 15.5 |
python-abseil |
— |
| python-grpcio |
affected |
openSUSE:Leap 15.5 |
python-grpcio |
— |
| python-grpcio |
affected |
SUSE:Linux Enterprise Module for Python 3 15 SP5 |
python-grpcio |
— |
| re2 |
affected |
SUSE:Linux Enterprise Module for Basesystem 15 SP5 |
re2 |
— |
| re2 |
affected |
openSUSE:Leap 15.5 |
re2 |
— |
| re2 |
affected |
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 |
re2 |
— |
| re2 |
affected |
SUSE:Linux Enterprise Server 15 SP4-LTSS |
re2 |
— |
| re2 |
affected |
SUSE:Manager Proxy 4.3 |
re2 |
— |
| re2 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS |
re2 |
— |
| re2 |
affected |
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS |
re2 |
— |
| re2 |
affected |
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 |
re2 |
— |
Open SourceExploitedCISA KEV listed2024-02-15
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Client Tools 15 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Proxy Module 4.3 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Server Module 4.3 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-lusitaniae-apache_exporter |
affected |
openSUSE:Leap 15.5 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 15 |
golang-github-prometheus-prometheus |
— |
| grafana |
affected |
SUSE:Manager Client Tools 15 |
grafana |
— |
| mgr-daemon |
affected |
SUSE:Manager Client Tools 15 |
mgr-daemon |
— |
| prometheus-postgres_exporter |
affected |
openSUSE:Leap 15.5 |
prometheus-postgres_exporter |
— |
| prometheus-postgres_exporter |
affected |
SUSE:Manager Client Tools 15 |
prometheus-postgres_exporter |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 15 |
spacecmd |
— |
| spacecmd |
affected |
openSUSE:Leap 15.5 |
spacecmd |
— |
| spacewalk-client-tools |
affected |
SUSE:Manager Client Tools 15 |
spacewalk-client-tools |
— |
| uyuni-proxy-systemd-services |
affected |
SUSE:Manager Client Tools for SLE Micro 5 |
uyuni-proxy-systemd-services |
— |
| uyuni-proxy-systemd-services |
affected |
SUSE:Manager Client Tools 15 |
uyuni-proxy-systemd-services |
— |
Open SourceExploitedCISA KEV listedCRITICAL2024-02-15
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-lusitaniae-apache_exporter |
affected |
SUSE:Manager Client Tools 12 |
golang-github-lusitaniae-apache_exporter |
— |
| golang-github-prometheus-alertmanager |
affected |
SUSE:Manager Client Tools 12 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-prometheus |
affected |
SUSE:Manager Client Tools 12 |
golang-github-prometheus-prometheus |
— |
| grafana |
affected |
SUSE:Manager Client Tools 12 |
grafana |
— |
| mgr-daemon |
affected |
SUSE:Manager Client Tools 12 |
mgr-daemon |
— |
| prometheus-postgres_exporter |
affected |
SUSE:Manager Client Tools 12 |
prometheus-postgres_exporter |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 12 |
spacecmd |
— |
| spacewalk-client-tools |
affected |
SUSE:Manager Client Tools 12 |
spacewalk-client-tools |
— |
GoogleExploitedCISA KEV listedHIGH2024-02-13
CVEs:CVE-2024-21338
Project ZeroExploitedCISA KEV listed2024-02-13
Windows Kernel Elevation of Privilege Vulnerability
CVEs:CVE-2024-21338
GoogleExploitedCISA KEV listedCRITICAL2024-02-13
Windows Kernel Elevation of Privilege Vulnerability
CVEs:CVE-2024-21338
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| Windows |
affected |
Microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_10_21h2 |
affected |
microsoft |
— |
— |
| windows_10_22h2 |
affected |
microsoft |
— |
— |
| windows_11_21h2 |
affected |
microsoft |
— |
— |
| windows_11_22h2 |
affected |
microsoft |
— |
— |
| windows_11_23h2 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
| windows_server_2022 |
affected |
microsoft |
— |
— |
| windows_server_2022_23h2 |
affected |
microsoft |
— |
— |
GoogleExploitedCISA KEV listedHIGH2024-11-19
CVEs:CVE-2024-44308
Project ZeroExploitedCISA KEV listed2024-02-05
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.
CVEs:CVE-2024-44308
GoogleExploitedCISA KEV listedCRITICAL2024-02-05
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code ...
CVEs:CVE-2024-44308
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| debian_linux |
affected |
debian |
— |
— |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
GoogleExploitedCISA KEV listed2024-02-05
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.
CVEs:CVE-2024-44308
Open SourceActive exploitation (sightings)HIGH2024-02-13
Red Hat Security Advisory: Satellite 6.14.2 Async Security Update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| candlepin |
affected |
Red Hat:satellite:6.14::el8 |
candlepin |
— |
| candlepin-selinux |
affected |
Red Hat:satellite:6.14::el8 |
candlepin-selinux |
— |
| mosquitto |
affected |
Red Hat:satellite_capsule:6.14::el8 |
mosquitto |
— |
| mosquitto |
affected |
Red Hat:satellite:6.14::el8 |
mosquitto |
— |
| mosquitto-debuginfo |
affected |
Red Hat:satellite:6.14::el8 |
mosquitto-debuginfo |
— |
| mosquitto-debuginfo |
affected |
Red Hat:satellite_capsule:6.14::el8 |
mosquitto-debuginfo |
— |
| mosquitto-debugsource |
affected |
Red Hat:satellite:6.14::el8 |
mosquitto-debugsource |
— |
| mosquitto-debugsource |
affected |
Red Hat:satellite_capsule:6.14::el8 |
mosquitto-debugsource |
— |
| puppet-agent |
affected |
Red Hat:satellite:6.14::el8 |
puppet-agent |
— |
| puppet-agent |
affected |
Red Hat:satellite_capsule:6.14::el8 |
puppet-agent |
— |
| puppetserver |
affected |
Red Hat:satellite_capsule:6.14::el8 |
puppetserver |
— |
| puppetserver |
affected |
Red Hat:satellite:6.14::el8 |
puppetserver |
— |
| rubygem-grpc |
affected |
Red Hat:satellite:6.14::el8 |
rubygem-grpc |
— |
| rubygem-puma |
affected |
Red Hat:satellite:6.14::el8 |
rubygem-puma |
— |
| rubygem-puma-debuginfo |
affected |
Red Hat:satellite:6.14::el8 |
rubygem-puma-debuginfo |
— |
| rubygem-puma-debugsource |
affected |
Red Hat:satellite:6.14::el8 |
rubygem-puma-debugsource |
— |
| rubygem-sidekiq |
affected |
Red Hat:satellite:6.14::el8 |
rubygem-sidekiq |
— |
Open SourceActive exploitation (sightings)2024-02-23
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceActive exploitation (sightings)2024-02-08
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-02-07
DEBIAN-CVE-2024-1283
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2024-02-06
Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1283
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)CRITICAL2024-02-06
CVEs:CVE-2024-1283
Open SourceActive exploitation (sightings)CRITICAL2024-02-21
GHSA-78w9-qxr3-hqhc
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
chainguard |
chromium |
— |
| chromium |
affected |
wolfi |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-02-21
DEBIAN-CVE-2024-1675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2024-02-20
Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-1675
GoogleActive exploitation (sightings)CRITICAL2024-02-20
Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-1675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-02-20
CVEs:CVE-2024-1675
Open SourceActive exploitation (sightings)HIGH2024-02-29
GHSA-7f39-34rh-fghp
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
chainguard |
chromium |
— |
| chromium |
affected |
wolfi |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2024-02-29
DEBIAN-CVE-2024-1939
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
Open SourceActive exploitation (sightings)2024-02-28
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
GoogleActive exploitation (sightings)HIGH2024-02-27
CVEs:CVE-2024-1939
GoogleActive exploitation (sightings)2024-02-27
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1939
GoogleActive exploitation (sightings)HIGH2024-02-27
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1939
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-02-23
CVEs:CVE-2024-26192
Open SourceActive exploitation (sightings)HIGH2024-02-13
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVEs:CVE-2024-26192
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-02-01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2024-21399
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-02-01
CVEs:CVE-2024-21399
GoogleActive exploitation (sightings)CRITICAL2024-02-13
CVEs:CVE-2024-21376
Open SourceActive exploitation (sightings)CRITICAL2024-02-13
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
CVEs:CVE-2024-21376
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| azure_kubernetes_service |
affected |
microsoft |
— |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-02-07
DEBIAN-CVE-2024-1284
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)CRITICAL2024-02-06
Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1284
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)CRITICAL2024-02-06
CVEs:CVE-2024-1284
GoogleActive exploitation (sightings)MEDIUM2024-02-24
sanitize-html Information Exposure vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| sanitize-html |
affected |
npm |
sanitize-html |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-02-24
sanitize-html Information Exposure vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| py3-jupyterlab |
affected |
chainguard |
py3-jupyterlab |
— |
| py3-jupyterlab |
affected |
wolfi |
py3-jupyterlab |
— |
| sanitize-html |
affected |
npm |
sanitize-html |
— |
| tensorflow-cpu-jupyter |
affected |
chainguard |
tensorflow-cpu-jupyter |
— |
Open SourceActive exploitation (sightings)2024-02-01
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2024-02-29
GHSA-5p54-7x9q-259p
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
chainguard |
chromium |
— |
| chromium |
affected |
wolfi |
chromium |
— |
Open SourceActive exploitation (sightings)HIGH2024-02-29
DEBIAN-CVE-2024-1938
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2024-02-27
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1938
GoogleActive exploitation (sightings)HIGH2024-02-27
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1938
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-02-27
CVEs:CVE-2024-1938
Open SourceActive exploitation (sightings)CRITICAL2024-02-21
GHSA-672f-vpw8-x67x
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
chainguard |
chromium |
— |
| chromium |
affected |
wolfi |
chromium |
— |
Open SourceActive exploitation (sightings)CRITICAL2024-02-21
DEBIAN-CVE-2024-1673
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)2024-02-20
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
CVEs:CVE-2024-1673
GoogleActive exploitation (sightings)HIGH2024-02-20
CVEs:CVE-2024-1673
GoogleActive exploitation (sightings)CRITICAL2024-02-20
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
CVEs:CVE-2024-1673
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-02-21
GHSA-frg3-hm7v-3rpf
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
chainguard |
chromium |
— |
| chromium |
affected |
wolfi |
chromium |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-02-21
DEBIAN-CVE-2024-1671
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-20
Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-1671
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-20
CVEs:CVE-2024-1671
GoogleActive exploitation (sightings)2024-02-20
Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-1671
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2023-51504
GoogleActive exploitation (sightings)CRITICAL2024-02-05
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2.
CVEs:CVE-2023-51504
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dan\'s_embedder_for_google_calendar |
affected |
dandulaney |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2023-6884
GoogleActive exploitation (sightings)HIGH2024-02-05
This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible f...
CVEs:CVE-2023-6884
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| plugin_for_google_reviews |
affected |
richplugins |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-21
CVEs:CVE-2024-1562
GoogleActive exploitation (sightings)HIGH2024-02-21
The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for ...
CVEs:CVE-2024-1562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| woocommerce_google_sheet_connector |
affected |
gsheetconnector |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-02-05
CVEs:CVE-2024-20815
Open SourceActive exploitation (sightings)HIGH2024-02-05
Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
CVEs:CVE-2024-20815
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-02-05
CVEs:CVE-2024-20816
Open SourceActive exploitation (sightings)HIGH2024-02-05
Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
CVEs:CVE-2024-20816
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)2024-02-29
dp-golang Go installation could be owned by wrong user
CVEs:CVE-2024-27294
Open SourceActive exploitation (sightings)HIGH2024-02-29
dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version 1.4.3 throug...
CVEs:CVE-2024-27294
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dp-golang |
affected |
danielparks |
— |
— |
Open SourceActive exploitation (sightings)HIGH2024-02-05
Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2024-20813
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-02-05
CVEs:CVE-2024-20813
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20820
Open SourceActive exploitation (sightings)HIGH2024-02-05
Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.
CVEs:CVE-2024-20820
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-02-05
Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.
CVEs:CVE-2024-20814
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20814
Open SourceActive exploitation (sightings)HIGH2024-02-05
Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.
CVEs:CVE-2024-20812
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-02-05
CVEs:CVE-2024-20812
Open SourceActive exploitation (sightings)HIGH2024-02-05
Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
CVEs:CVE-2024-20817
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20817
Open SourceActive exploitation (sightings)HIGH2024-02-05
Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
CVEs:CVE-2024-20818
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20818
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20819
Open SourceActive exploitation (sightings)HIGH2024-02-05
Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
CVEs:CVE-2024-20819
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-02-05
Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.
CVEs:CVE-2024-20810
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
GoogleActive exploitation (sightings)LOW2024-02-05
CVEs:CVE-2024-20810
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20811
Open SourceActive exploitation (sightings)MEDIUM2024-02-05
Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.
CVEs:CVE-2024-20811
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
samsung |
— |
— |
Open SourceActive exploitation (sightings)HIGH2024-02-05
In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961715; Issue ID:...
CVEs:CVE-2024-20002
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20002
Open SourceActive exploitation (sightings)HIGH2024-02-05
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08471742; Iss...
CVEs:CVE-2024-20013
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20013
GoogleActive exploitation (sightings)2024-02-01
PUB-A-295051806
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)2024-02-01
PUB-A-295051886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)2024-02-01
PUB-A-295052084
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)2024-02-01
PUB-A-295052588
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2024-02-05
In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961601; Issue ID:...
CVEs:CVE-2024-20001
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20001
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20016
Open SourceActive exploitation (sightings)HIGH2024-02-05
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation Patch ID: ALPS07835901; Issue ID: ALPS07835901.
CVEs:CVE-2024-20016
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)2024-02-01
PUB-A-295052332
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2024-02-05
CVEs:CVE-2024-20015
Open SourceActive exploitation (sightings)HIGH2024-02-05
In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441...
CVEs:CVE-2024-20015
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2024-02-05
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue I...
CVEs:CVE-2024-20012
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2024-02-05
CVEs:CVE-2024-20012
Open SourceActive exploitation (sightings)HIGH2024-02-05
there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-22012
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2024-02-05
CVEs:CVE-2024-22012
GoogleActive exploitation (sightings)HIGH2024-02-01
PUB-A-309407679
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitHIGH2024-02-05
In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-0040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2024-02-05
CVEs:CVE-2024-0040
Open SourcePoC exploitHIGH2024-02-10
angular vulnerable to super-linear runtime due to backtracking
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
| org.webjars.bower:angular |
affected |
Maven |
org.webjars.bower:angular |
— |
| org.webjars.npm:angular |
affected |
Maven |
org.webjars.npm:angular |
— |
| solr |
affected |
chainguard |
solr |
— |
| solr |
affected |
wolfi |
solr |
— |
Open SourcePoC exploitHIGH2024-02-10
angular vulnerable to super-linear runtime due to backtracking
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
| org.webjars.bower:angular |
affected |
Maven |
org.webjars.bower:angular |
— |
| org.webjars.npm:angular |
affected |
Maven |
org.webjars.npm:angular |
— |
Open SourcePoC exploitHIGH2024-02-10
DEBIAN-CVE-2024-21490
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular.js |
affected |
Debian:12 |
angular.js |
— |
| angular.js |
affected |
Debian:11 |
angular.js |
— |
| angular.js |
affected |
Debian:13 |
angular.js |
— |
| angular.js |
affected |
Debian:14 |
angular.js |
— |
Open SourcePoC exploitHIGH2024-02-10
angular vulnerable to super-linear runtime due to backtracking
CVEs:CVE-2024-21490
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
| org.webjars.bower:angular |
affected |
Maven |
org.webjars.bower:angular |
— |
| org.webjars.npm:angular |
affected |
Maven |
org.webjars.npm:angular |
— |
Open SourcePoC exploitHIGH2024-02-10
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large careful...
CVEs:CVE-2024-21490
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular.js |
affected |
angularjs |
— |
— |
| angular.js |
affected |
angularjs |
— |
— |
Open SourcePoC exploitHIGH2024-02-10
angular vulnerable to super-linear runtime due to backtracking
CVEs:CVE-2024-21490
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
| org.webjars.bower:angular |
affected |
Maven |
org.webjars.bower:angular |
— |
| org.webjars.npm:angular |
affected |
Maven |
org.webjars.npm:angular |
— |
Open SourcePoC exploitHIGH2024-02-29
Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON
CVEs:CVE-2024-24786
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
google.golang.org |
google.golang.org/protobuf |
— |
| protobuf/encoding/protojson |
affected |
google.golang.org |
google.golang.org/protobuf/encoding/protojson |
— |
| protobuf/internal/encoding/json |
affected |
google.golang.org |
google.golang.org/protobuf/internal/encoding/json |
— |
GooglePoC exploitHIGH2024-02-29
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnkno...
CVEs:CVE-2024-24786
GooglePoC exploit2024-02-29
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.
CVEs:CVE-2024-24786
Open SourcePoC exploitHIGH2024-02-29
Red Hat Security Advisory: go-toolset-1.19-golang security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go-toolset-1.19-golang |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang |
— |
| go-toolset-1.19-golang-bin |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-bin |
— |
| go-toolset-1.19-golang-docs |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-docs |
— |
| go-toolset-1.19-golang-misc |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-misc |
— |
| go-toolset-1.19-golang-race |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-race |
— |
| go-toolset-1.19-golang-src |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-src |
— |
| go-toolset-1.19-golang-tests |
affected |
Red Hat:devtools:2023::el7 |
go-toolset-1.19-golang-tests |
— |
Open SourcePoC exploitHIGH2024-02-20
Red Hat Security Advisory: go-toolset:rhel8 security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| delve |
affected |
Red Hat:enterprise_linux:8::appstream |
delve |
— |
| delve-debuginfo |
affected |
Red Hat:enterprise_linux:8::appstream |
delve-debuginfo |
— |
| delve-debugsource |
affected |
Red Hat:enterprise_linux:8::appstream |
delve-debugsource |
— |
| golang |
affected |
Red Hat:enterprise_linux:8::appstream |
golang |
— |
| golang-bin |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-bin |
— |
| golang-docs |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-docs |
— |
| golang-misc |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-misc |
— |
| golang-src |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-src |
— |
| golang-tests |
affected |
Red Hat:enterprise_linux:8::appstream |
golang-tests |
— |
| go-toolset |
affected |
Red Hat:enterprise_linux:8::appstream |
go-toolset |
— |
Open SourcePoC exploitCRITICAL2024-02-20
Moderate: go-toolset:rhel8 security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| delve |
affected |
AlmaLinux:8 |
delve |
— |
| golang |
affected |
AlmaLinux:8 |
golang |
— |
| golang-bin |
affected |
AlmaLinux:8 |
golang-bin |
— |
| golang-docs |
affected |
AlmaLinux:8 |
golang-docs |
— |
| golang-misc |
affected |
AlmaLinux:8 |
golang-misc |
— |
| golang-src |
affected |
AlmaLinux:8 |
golang-src |
— |
| golang-tests |
affected |
AlmaLinux:8 |
golang-tests |
— |
| go-toolset |
affected |
AlmaLinux:8 |
go-toolset |
— |
Open SourcePoC exploitCRITICAL2024-02-05
In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2024-0031
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2024-02-05
CVEs:CVE-2024-0031
Open SourcePoC exploitMEDIUM2024-02-05
In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2024-0030
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2024-02-05
CVEs:CVE-2024-0030
GooglePoC exploitHIGH2024-02-01
Classic builder cache poisoning
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| docker/docker |
affected |
github.com |
github.com/docker/docker |
— |
| moby/moby |
affected |
github.com |
github.com/moby/moby |
— |
Open SourcePoC exploitHIGH2024-02-01
Classic builder cache poisoning
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aactl |
affected |
chainguard |
aactl |
— |
| aactl |
affected |
wolfi |
aactl |
— |
| argo-workflows |
affected |
wolfi |
argo-workflows |
— |
| argo-workflows |
affected |
chainguard |
argo-workflows |
— |
| argo-workflows-fips |
affected |
chainguard |
argo-workflows-fips |
— |
| bom |
affected |
chainguard |
bom |
— |
| bom |
affected |
wolfi |
bom |
— |
| buildkitd |
affected |
wolfi |
buildkitd |
— |
| buildkitd |
affected |
chainguard |
buildkitd |
— |
| cadvisor |
affected |
wolfi |
cadvisor |
— |
| cadvisor |
affected |
chainguard |
cadvisor |
— |
| cadvisor-fips |
affected |
chainguard |
cadvisor-fips |
— |
| cert-manager-1.12 |
affected |
wolfi |
cert-manager-1.12 |
— |
| cert-manager-1.12 |
affected |
chainguard |
cert-manager-1.12 |
— |
| cert-manager-1.13 |
affected |
chainguard |
cert-manager-1.13 |
— |
| cert-manager-1.13 |
affected |
wolfi |
cert-manager-1.13 |
— |
| cert-manager-1.14 |
affected |
chainguard |
cert-manager-1.14 |
— |
| cert-manager-1.14 |
affected |
wolfi |
cert-manager-1.14 |
— |
| cert-manager-fips-1.12 |
affected |
chainguard |
cert-manager-fips-1.12 |
— |
| cert-manager-fips-1.13 |
affected |
chainguard |
cert-manager-fips-1.13 |
— |
| cert-manager-fips-1.14 |
affected |
chainguard |
cert-manager-fips-1.14 |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| cosign |
affected |
chainguard |
cosign |
— |
| cosign |
affected |
wolfi |
cosign |
— |
| cosign-fips |
affected |
chainguard |
cosign-fips |
— |
| cosign-fips |
affected |
wolfi |
cosign-fips |
— |
| crane |
affected |
chainguard |
crane |
— |
| crane |
affected |
wolfi |
crane |
— |
| cri-tools |
affected |
chainguard |
cri-tools |
— |
| cri-tools |
affected |
wolfi |
cri-tools |
— |
| ctop |
affected |
chainguard |
ctop |
— |
| ctop |
affected |
wolfi |
ctop |
— |
| dagger |
affected |
wolfi |
dagger |
— |
| dagger |
affected |
chainguard |
dagger |
— |
| datadog-agent |
affected |
wolfi |
datadog-agent |
— |
| datadog-agent |
affected |
chainguard |
datadog-agent |
— |
| datadog-agent-fips |
affected |
chainguard |
datadog-agent-fips |
— |
| docker |
affected |
wolfi |
docker |
— |
| docker |
affected |
chainguard |
docker |
— |
| docker-credential-gcr |
affected |
wolfi |
docker-credential-gcr |
— |
| docker-credential-gcr |
affected |
chainguard |
docker-credential-gcr |
— |
| docker/docker |
affected |
github.com |
github.com/docker/docker |
— |
| docker-machine-driver-harvester |
affected |
wolfi |
docker-machine-driver-harvester |
— |
| docker-machine-driver-harvester |
affected |
chainguard |
docker-machine-driver-harvester |
— |
| eksctl |
affected |
chainguard |
eksctl |
— |
| eksctl |
affected |
wolfi |
eksctl |
— |
| falco |
affected |
chainguard |
falco |
— |
| falco |
affected |
wolfi |
falco |
— |
| falcoctl |
affected |
chainguard |
falcoctl |
— |
| falcoctl |
affected |
wolfi |
falcoctl |
— |
| falcoctl-fips |
affected |
chainguard |
falcoctl-fips |
— |
| falcoctl-fips-0.4 |
affected |
chainguard |
falcoctl-fips-0.4 |
— |
| filebeat |
affected |
chainguard |
filebeat |
— |
| filebeat |
affected |
wolfi |
filebeat |
— |
| filebeat-fips |
affected |
chainguard |
filebeat-fips |
— |
| flux |
affected |
chainguard |
flux |
— |
| flux |
affected |
wolfi |
flux |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-image-reflector-controller |
affected |
wolfi |
flux-image-reflector-controller |
— |
| flux-image-reflector-controller |
affected |
chainguard |
flux-image-reflector-controller |
— |
| gitlab-rails-ee-17.0 |
affected |
chainguard |
gitlab-rails-ee-17.0 |
— |
| gitlab-rails-ee-17.3 |
affected |
chainguard |
gitlab-rails-ee-17.3 |
— |
| gitlab-rails-ee-fips-17.0 |
affected |
chainguard |
gitlab-rails-ee-fips-17.0 |
— |
| gitlab-rails-ee-fips-17.2 |
affected |
chainguard |
gitlab-rails-ee-fips-17.2 |
— |
| gitlab-runner |
affected |
wolfi |
gitlab-runner |
— |
| gitlab-runner |
affected |
chainguard |
gitlab-runner |
— |
| gitlab-runner-fips-17.0 |
affected |
chainguard |
gitlab-runner-fips-17.0 |
— |
| gitsign |
affected |
chainguard |
gitsign |
— |
| gitsign |
affected |
wolfi |
gitsign |
— |
| goreleaser |
affected |
wolfi |
goreleaser |
— |
| goreleaser |
affected |
chainguard |
goreleaser |
— |
| goreleaser-1.18 |
affected |
wolfi |
goreleaser-1.18 |
— |
| goreleaser-1.18 |
affected |
chainguard |
goreleaser-1.18 |
— |
| guac |
affected |
chainguard |
guac |
— |
| guac |
affected |
wolfi |
guac |
— |
| helm |
affected |
chainguard |
helm |
— |
| helm |
affected |
wolfi |
helm |
— |
| helm-3 |
affected |
chainguard |
helm-3 |
— |
| helm-3 |
affected |
wolfi |
helm-3 |
— |
| helm-4 |
affected |
wolfi |
helm-4 |
— |
| helm-4 |
affected |
chainguard |
helm-4 |
— |
| helm-fips |
affected |
chainguard |
helm-fips |
— |
| helm-fips-3 |
affected |
chainguard |
helm-fips-3 |
— |
| helm-fips-4 |
affected |
chainguard |
helm-fips-4 |
— |
| helm-operator |
affected |
chainguard |
helm-operator |
— |
| helm-operator |
affected |
wolfi |
helm-operator |
— |
| helm-operator-fips |
affected |
chainguard |
helm-operator-fips |
— |
| istio-fips-1.20 |
affected |
chainguard |
istio-fips-1.20 |
— |
| istio-operator-1.19 |
affected |
chainguard |
istio-operator-1.19 |
— |
| istio-operator-1.19 |
affected |
wolfi |
istio-operator-1.19 |
— |
| istio-operator-1.20 |
affected |
chainguard |
istio-operator-1.20 |
— |
| istio-operator-1.20 |
affected |
wolfi |
istio-operator-1.20 |
— |
| istio-operator-fips-1.19 |
affected |
chainguard |
istio-operator-fips-1.19 |
— |
| istio-pilot-agent-1.19 |
affected |
chainguard |
istio-pilot-agent-1.19 |
— |
| istio-pilot-agent-1.19 |
affected |
wolfi |
istio-pilot-agent-1.19 |
— |
| istio-pilot-agent-1.20 |
affected |
wolfi |
istio-pilot-agent-1.20 |
— |
| istio-pilot-agent-1.20 |
affected |
chainguard |
istio-pilot-agent-1.20 |
— |
| istio-pilot-agent-1.21 |
affected |
chainguard |
istio-pilot-agent-1.21 |
— |
| istio-pilot-agent-1.21 |
affected |
wolfi |
istio-pilot-agent-1.21 |
— |
| istio-pilot-agent-fips-1.19 |
affected |
chainguard |
istio-pilot-agent-fips-1.19 |
— |
| istio-pilot-discovery-1.19 |
affected |
chainguard |
istio-pilot-discovery-1.19 |
— |
| istio-pilot-discovery-1.19 |
affected |
wolfi |
istio-pilot-discovery-1.19 |
— |
| istio-pilot-discovery-1.20 |
affected |
chainguard |
istio-pilot-discovery-1.20 |
— |
| istio-pilot-discovery-1.20 |
affected |
wolfi |
istio-pilot-discovery-1.20 |
— |
| istio-pilot-discovery-1.21 |
affected |
chainguard |
istio-pilot-discovery-1.21 |
— |
| istio-pilot-discovery-1.21 |
affected |
wolfi |
istio-pilot-discovery-1.21 |
— |
| istio-pilot-discovery-fips-1.19 |
affected |
chainguard |
istio-pilot-discovery-fips-1.19 |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| k3s |
affected |
chainguard |
k3s |
— |
| k3s |
affected |
wolfi |
k3s |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k9s |
affected |
chainguard |
k9s |
— |
| k9s |
affected |
wolfi |
k9s |
— |
| kargo |
affected |
chainguard |
kargo |
— |
| kargo |
affected |
wolfi |
kargo |
— |
| ko-fips |
affected |
wolfi |
ko-fips |
— |
| ko-fips |
affected |
chainguard |
ko-fips |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kpt |
affected |
chainguard |
kpt |
— |
| kpt |
affected |
wolfi |
kpt |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| kyverno |
affected |
chainguard |
kyverno |
— |
| kyverno |
affected |
wolfi |
kyverno |
— |
| loki |
affected |
chainguard |
loki |
— |
| loki |
affected |
wolfi |
loki |
— |
| loki-2.9 |
affected |
chainguard |
loki-2.9 |
— |
| moby/moby |
affected |
github.com |
github.com/moby/moby |
— |
| nerdctl |
affected |
chainguard |
nerdctl |
— |
| nerdctl |
affected |
wolfi |
nerdctl |
— |
| newrelic-infrastructure-agent |
affected |
chainguard |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent |
affected |
wolfi |
newrelic-infrastructure-agent |
— |
| newrelic-infrastructure-agent-1.43 |
affected |
chainguard |
newrelic-infrastructure-agent-1.43 |
— |
| policy-controller |
affected |
chainguard |
policy-controller |
— |
| policy-controller |
affected |
wolfi |
policy-controller |
— |
| policy-controller-fips |
affected |
chainguard |
policy-controller-fips |
— |
| prometheus |
affected |
wolfi |
prometheus |
— |
| prometheus |
affected |
chainguard |
prometheus |
— |
| prometheus-2.45 |
affected |
chainguard |
prometheus-2.45 |
— |
| prometheus-2.45 |
affected |
wolfi |
prometheus-2.45 |
— |
| prometheus-2.50 |
affected |
wolfi |
prometheus-2.50 |
— |
| prometheus-2.50 |
affected |
chainguard |
prometheus-2.50 |
— |
| prometheus-fips |
affected |
chainguard |
prometheus-fips |
— |
| prometheus-fips-2.45 |
affected |
chainguard |
prometheus-fips-2.45 |
— |
| pulumi |
affected |
chainguard |
pulumi |
— |
| pulumi |
affected |
wolfi |
pulumi |
— |
| rancher-2.10 |
affected |
chainguard |
rancher-2.10 |
— |
| rancher-2.10 |
affected |
wolfi |
rancher-2.10 |
— |
| rancher-2.11 |
affected |
chainguard |
rancher-2.11 |
— |
| rancher-2.11 |
affected |
wolfi |
rancher-2.11 |
— |
| rancher-agent-2.10 |
affected |
wolfi |
rancher-agent-2.10 |
— |
| rancher-agent-2.10 |
affected |
chainguard |
rancher-agent-2.10 |
— |
| rancher-agent-2.11 |
affected |
wolfi |
rancher-agent-2.11 |
— |
| rancher-agent-2.11 |
affected |
chainguard |
rancher-agent-2.11 |
— |
| rancher-agent-2.9 |
affected |
wolfi |
rancher-agent-2.9 |
— |
| rancher-agent-2.9 |
affected |
chainguard |
rancher-agent-2.9 |
— |
| rancher-machine |
affected |
wolfi |
rancher-machine |
— |
| rancher-machine |
affected |
chainguard |
rancher-machine |
— |
| scorecard |
affected |
chainguard |
scorecard |
— |
| scorecard |
affected |
wolfi |
scorecard |
— |
| skaffold |
affected |
chainguard |
skaffold |
— |
| skaffold |
affected |
wolfi |
skaffold |
— |
| skopeo |
affected |
wolfi |
skopeo |
— |
| skopeo |
affected |
chainguard |
skopeo |
— |
| slsa-verifier |
affected |
wolfi |
slsa-verifier |
— |
| slsa-verifier |
affected |
chainguard |
slsa-verifier |
— |
| tekton-chains |
affected |
chainguard |
tekton-chains |
— |
| tekton-chains |
affected |
wolfi |
tekton-chains |
— |
| tekton-pipelines |
affected |
wolfi |
tekton-pipelines |
— |
| tekton-pipelines |
affected |
chainguard |
tekton-pipelines |
— |
| telegraf-1.26 |
affected |
wolfi |
telegraf-1.26 |
— |
| telegraf-1.26 |
affected |
chainguard |
telegraf-1.26 |
— |
| telegraf-1.27 |
affected |
chainguard |
telegraf-1.27 |
— |
| telegraf-1.27 |
affected |
wolfi |
telegraf-1.27 |
— |
| telegraf-1.28 |
affected |
wolfi |
telegraf-1.28 |
— |
| telegraf-1.28 |
affected |
chainguard |
telegraf-1.28 |
— |
| telegraf-1.29 |
affected |
chainguard |
telegraf-1.29 |
— |
| telegraf-1.29 |
affected |
wolfi |
telegraf-1.29 |
— |
| telegraf-1.30 |
affected |
wolfi |
telegraf-1.30 |
— |
| telegraf-1.30 |
affected |
chainguard |
telegraf-1.30 |
— |
| timoni |
affected |
chainguard |
timoni |
— |
| timoni |
affected |
wolfi |
timoni |
— |
| traefik |
affected |
chainguard |
traefik |
— |
| traefik |
affected |
wolfi |
traefik |
— |
| traefik-fips |
affected |
chainguard |
traefik-fips |
— |
| trivy |
affected |
wolfi |
trivy |
— |
| trivy |
affected |
chainguard |
trivy |
— |
| up |
affected |
wolfi |
up |
— |
| up |
affected |
chainguard |
up |
— |
| vexctl |
affected |
chainguard |
vexctl |
— |
| vexctl |
affected |
wolfi |
vexctl |
— |
| zarf |
affected |
wolfi |
zarf |
— |
| zarf |
affected |
chainguard |
zarf |
— |
| zot |
affected |
chainguard |
zot |
— |
| zot |
affected |
wolfi |
zot |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-02-21
GHSA-r5qg-76hh-gr9p
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
chainguard |
chromium |
— |
| chromium |
affected |
wolfi |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2024-02-21
DEBIAN-CVE-2024-1676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2024-02-20
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2024-1676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2024-02-20
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2024-1676
GoogleCoalition ESS < 30%CRITICAL2024-02-20
CVEs:CVE-2024-1676
Open SourceCoalition ESS < 30%CRITICAL2024-02-21
GHSA-wjv4-j3hc-gxvv
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
wolfi |
chromium |
— |
| chromium |
affected |
chainguard |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-02-21
DEBIAN-CVE-2024-1670
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2024-02-20
Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1670
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2024-02-20
Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1670
GoogleCoalition ESS < 30%HIGH2024-02-20
CVEs:CVE-2024-1670
GoogleCoalition ESS < 30%2024-02-01
ASB-A-317829109
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-317829110
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-317826159
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2024-02-13
CVEs:CVE-2024-21403
Open SourceCoalition ESS < 30%CRITICAL2024-02-13
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVEs:CVE-2024-21403
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| azure_kubernetes_service |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-317829112
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2024-02-21
GHSA-f8gg-fh4p-4795
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
chainguard |
chromium |
— |
| chromium |
affected |
wolfi |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2024-02-21
DEBIAN-CVE-2024-1669
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%2024-02-20
Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1669
GoogleCoalition ESS < 30%HIGH2024-02-20
Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-1669
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-02-20
CVEs:CVE-2024-1669
GoogleCoalition ESS < 30%HIGH2024-02-22
Helm's Missing YAML Content Leads To Panic
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| helm/v3 |
affected |
helm.sh |
helm.sh/helm/v3 |
— |
Open SourceCoalition ESS < 30%HIGH2024-02-22
Helm's Missing YAML Content Leads To Panic
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cert-manager-1.12 |
affected |
wolfi |
cert-manager-1.12 |
— |
| cert-manager-1.12 |
affected |
chainguard |
cert-manager-1.12 |
— |
| cert-manager-1.13 |
affected |
chainguard |
cert-manager-1.13 |
— |
| cert-manager-1.13 |
affected |
wolfi |
cert-manager-1.13 |
— |
| cert-manager-1.14 |
affected |
wolfi |
cert-manager-1.14 |
— |
| cert-manager-1.14 |
affected |
chainguard |
cert-manager-1.14 |
— |
| cert-manager-fips-1.12 |
affected |
chainguard |
cert-manager-fips-1.12 |
— |
| cert-manager-fips-1.13 |
affected |
chainguard |
cert-manager-fips-1.13 |
— |
| cert-manager-fips-1.14 |
affected |
chainguard |
cert-manager-fips-1.14 |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| cilium-cli |
affected |
wolfi |
cilium-cli |
— |
| cilium-cli |
affected |
chainguard |
cilium-cli |
— |
| eksctl |
affected |
wolfi |
eksctl |
— |
| eksctl |
affected |
chainguard |
eksctl |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| helm-fips |
affected |
chainguard |
helm-fips |
— |
| helm-fips-3 |
affected |
chainguard |
helm-fips-3 |
— |
| helm-fips-4 |
affected |
chainguard |
helm-fips-4 |
— |
| helm-operator |
affected |
wolfi |
helm-operator |
— |
| helm-operator |
affected |
chainguard |
helm-operator |
— |
| helm-push |
affected |
wolfi |
helm-push |
— |
| helm-push |
affected |
chainguard |
helm-push |
— |
| helm/v3 |
affected |
helm.sh |
helm.sh/helm/v3 |
— |
| istio-fips-1.20 |
affected |
chainguard |
istio-fips-1.20 |
— |
| istio-operator-1.19 |
affected |
chainguard |
istio-operator-1.19 |
— |
| istio-operator-1.19 |
affected |
wolfi |
istio-operator-1.19 |
— |
| istio-operator-1.20 |
affected |
wolfi |
istio-operator-1.20 |
— |
| istio-operator-1.20 |
affected |
chainguard |
istio-operator-1.20 |
— |
| istio-operator-fips-1.19 |
affected |
chainguard |
istio-operator-fips-1.19 |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k9s |
affected |
wolfi |
k9s |
— |
| k9s |
affected |
chainguard |
k9s |
— |
| kots |
affected |
wolfi |
kots |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots-compat |
affected |
chainguard |
kots-compat |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| trivy |
affected |
wolfi |
trivy |
— |
| trivy |
affected |
chainguard |
trivy |
— |
| up |
affected |
chainguard |
up |
— |
| up |
affected |
wolfi |
up |
— |
| zarf |
affected |
wolfi |
zarf |
— |
| zarf |
affected |
chainguard |
zarf |
— |
| zot |
affected |
chainguard |
zot |
— |
| zot |
affected |
wolfi |
zot |
— |
Open SourceCoalition ESS < 30%HIGH2024-02-21
GHSA-q8f8-rhx9-2qm4
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
chainguard |
chromium |
— |
| chromium |
affected |
wolfi |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2024-02-21
DEBIAN-CVE-2024-1672
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2024-02-20
Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-1672
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
GoogleCoalition ESS < 30%2024-02-20
Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-1672
GoogleCoalition ESS < 30%HIGH2024-02-20
CVEs:CVE-2024-1672
Open SourceCoalition ESS < 30%HIGH2024-02-29
DEBIAN-CVE-2023-50658
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-dvsekhvalnov-jose2go |
affected |
Debian:11 |
golang-github-dvsekhvalnov-jose2go |
— |
| golang-github-dvsekhvalnov-jose2go |
affected |
Debian:12 |
golang-github-dvsekhvalnov-jose2go |
— |
| golang-github-dvsekhvalnov-jose2go |
affected |
Debian:13 |
golang-github-dvsekhvalnov-jose2go |
— |
| golang-github-dvsekhvalnov-jose2go |
affected |
Debian:14 |
golang-github-dvsekhvalnov-jose2go |
— |
Open SourceCoalition ESS < 30%HIGH2024-02-21
GHSA-29vg-wcmp-5fp9
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
wolfi |
chromium |
— |
| chromium |
affected |
chainguard |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2024-02-21
DEBIAN-CVE-2024-1674
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2024-02-20
CVEs:CVE-2024-1674
GoogleCoalition ESS < 30%2024-02-20
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-1674
GoogleCoalition ESS < 30%HIGH2024-02-20
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-1674
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-02-15
Security update for golang-github-prometheus-alertmanager
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-prometheus-alertmanager |
affected |
SUSE:Manager Proxy Module 4.3 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-alertmanager |
affected |
SUSE:Manager Client Tools 15 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-alertmanager |
affected |
SUSE:Linux Enterprise Module for Package Hub 15 SP5 |
golang-github-prometheus-alertmanager |
— |
| golang-github-prometheus-alertmanager |
affected |
openSUSE:Leap 15.5 |
golang-github-prometheus-alertmanager |
— |
GoogleCoalition ESS < 30%MEDIUM2024-02-23
CVEs:CVE-2024-21423
Open SourceCoalition ESS < 30%HIGH2024-02-13
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVEs:CVE-2024-21423
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%HIGH2024-02-29
Path traversal in helm.sh/helm/v3
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| cilium-cli |
affected |
chainguard |
cilium-cli |
— |
| cilium-cli |
affected |
wolfi |
cilium-cli |
— |
| eksctl |
affected |
chainguard |
eksctl |
— |
| eksctl |
affected |
wolfi |
eksctl |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| helm-fips |
affected |
chainguard |
helm-fips |
— |
| helm-fips-3 |
affected |
chainguard |
helm-fips-3 |
— |
| helm-fips-4 |
affected |
chainguard |
helm-fips-4 |
— |
| helm-operator |
affected |
chainguard |
helm-operator |
— |
| helm-operator |
affected |
wolfi |
helm-operator |
— |
| helm-push |
affected |
chainguard |
helm-push |
— |
| helm-push |
affected |
wolfi |
helm-push |
— |
| helm/v3 |
affected |
helm.sh |
helm.sh/helm/v3 |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k9s |
affected |
chainguard |
k9s |
— |
| k9s |
affected |
wolfi |
k9s |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| trivy |
affected |
wolfi |
trivy |
— |
| trivy |
affected |
chainguard |
trivy |
— |
| up |
affected |
wolfi |
up |
— |
| up |
affected |
chainguard |
up |
— |
| zarf |
affected |
chainguard |
zarf |
— |
| zarf |
affected |
wolfi |
zarf |
— |
| zot |
affected |
wolfi |
zot |
— |
| zot |
affected |
chainguard |
zot |
— |
Open SourceCoalition ESS < 30%HIGH2024-02-15
Helm dependency management path traversal
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cert-manager-1.12 |
affected |
wolfi |
cert-manager-1.12 |
— |
| cert-manager-1.12 |
affected |
chainguard |
cert-manager-1.12 |
— |
| cert-manager-1.13 |
affected |
chainguard |
cert-manager-1.13 |
— |
| cert-manager-1.13 |
affected |
wolfi |
cert-manager-1.13 |
— |
| cert-manager-1.14 |
affected |
wolfi |
cert-manager-1.14 |
— |
| cert-manager-1.14 |
affected |
chainguard |
cert-manager-1.14 |
— |
| cert-manager-fips-1.12 |
affected |
chainguard |
cert-manager-fips-1.12 |
— |
| cert-manager-fips-1.13 |
affected |
chainguard |
cert-manager-fips-1.13 |
— |
| chartmuseum |
affected |
chainguard |
chartmuseum |
— |
| chartmuseum |
affected |
wolfi |
chartmuseum |
— |
| cilium-cli |
affected |
chainguard |
cilium-cli |
— |
| cilium-cli |
affected |
wolfi |
cilium-cli |
— |
| eksctl |
affected |
chainguard |
eksctl |
— |
| eksctl |
affected |
wolfi |
eksctl |
— |
| flux-helm-controller |
affected |
chainguard |
flux-helm-controller |
— |
| flux-helm-controller |
affected |
wolfi |
flux-helm-controller |
— |
| flux-source-controller |
affected |
wolfi |
flux-source-controller |
— |
| flux-source-controller |
affected |
chainguard |
flux-source-controller |
— |
| helm-fips |
affected |
chainguard |
helm-fips |
— |
| helm-fips-3 |
affected |
chainguard |
helm-fips-3 |
— |
| helm-fips-4 |
affected |
chainguard |
helm-fips-4 |
— |
| helm-operator |
affected |
chainguard |
helm-operator |
— |
| helm-operator |
affected |
wolfi |
helm-operator |
— |
| helm-push |
affected |
chainguard |
helm-push |
— |
| helm-push |
affected |
wolfi |
helm-push |
— |
| helm/v3 |
affected |
helm.sh |
helm.sh/helm/v3 |
— |
| istio-fips-1.20 |
affected |
chainguard |
istio-fips-1.20 |
— |
| istio-operator-1.19 |
affected |
wolfi |
istio-operator-1.19 |
— |
| istio-operator-1.19 |
affected |
chainguard |
istio-operator-1.19 |
— |
| istio-operator-1.20 |
affected |
wolfi |
istio-operator-1.20 |
— |
| istio-operator-1.20 |
affected |
chainguard |
istio-operator-1.20 |
— |
| istio-operator-fips-1.19 |
affected |
chainguard |
istio-operator-fips-1.19 |
— |
| k8sgpt |
affected |
wolfi |
k8sgpt |
— |
| k8sgpt |
affected |
chainguard |
k8sgpt |
— |
| k9s |
affected |
wolfi |
k9s |
— |
| k9s |
affected |
chainguard |
k9s |
— |
| kots |
affected |
chainguard |
kots |
— |
| kots |
affected |
wolfi |
kots |
— |
| kots-compat |
affected |
chainguard |
kots-compat |
— |
| kubescape |
affected |
chainguard |
kubescape |
— |
| kubescape |
affected |
wolfi |
kubescape |
— |
| kubevela |
affected |
wolfi |
kubevela |
— |
| kubevela |
affected |
chainguard |
kubevela |
— |
| trivy |
affected |
chainguard |
trivy |
— |
| trivy |
affected |
wolfi |
trivy |
— |
| up |
affected |
wolfi |
up |
— |
| up |
affected |
chainguard |
up |
— |
| zarf |
affected |
wolfi |
zarf |
— |
| zarf |
affected |
chainguard |
zarf |
— |
| zot |
affected |
wolfi |
zot |
— |
| zot |
affected |
chainguard |
zot |
— |
GoogleCoalition ESS < 30%HIGH2024-02-15
Helm dependency management path traversal
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| helm/v3 |
affected |
helm.sh |
helm.sh/helm/v3 |
— |
GoogleCoalition ESS < 30%HIGH2024-02-14
CVEs:CVE-2024-23314
Open SourceCoalition ESS < 30%HIGH2024-02-14
When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVEs:CVE-2024-23314
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| big-ip_access_policy_manager |
affected |
f5 |
— |
— |
| big-ip_advanced_firewall_manager |
affected |
f5 |
— |
— |
| big-ip_analytics |
affected |
f5 |
— |
— |
| big-ip_application_acceleration_manager |
affected |
f5 |
— |
— |
| big-ip_application_security_manager |
affected |
f5 |
— |
— |
| big-ip_domain_name_system |
affected |
f5 |
— |
— |
| big-ip_fraud_protection_service |
affected |
f5 |
— |
— |
| big-ip_global_traffic_manager |
affected |
f5 |
— |
— |
| big-ip_link_controller |
affected |
f5 |
— |
— |
| big-ip_local_traffic_manager |
affected |
f5 |
— |
— |
| big-ip_next_service_proxy_for_kubernetes |
affected |
f5 |
— |
— |
| big-ip_policy_enforcement_manager |
affected |
f5 |
— |
— |
| big-iq_centralized_management |
affected |
f5 |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2024-02-17
An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploading of files. IBM X-Force ID: 238535.
CVEs:CVE-2022-42443
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| trusteer_android_sdk_for_mobile |
affected |
ibm |
— |
— |
| trusteer_ios_sdk_for_mobile |
affected |
ibm |
— |
— |
GoogleCoalition ESS < 30%LOW2024-02-17
CVEs:CVE-2022-42443
Open SourceCoalition ESS < 30%MEDIUM2024-02-05
In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed f...
CVEs:CVE-2024-0032
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-02-05
CVEs:CVE-2024-0032
GoogleCoalition ESS < 30%CRITICAL2024-02-05
CVEs:CVE-2024-20011
Open SourceCoalition ESS < 30%CRITICAL2024-02-05
In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS084411...
CVEs:CVE-2024-20011
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-314698315
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2024-02-05
CVEs:CVE-2024-20009
Open SourceCoalition ESS < 30%HIGH2024-02-05
In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08...
CVEs:CVE-2024-20009
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-314698313
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2024-02-23
CVE-2024-25629 affecting package grpc for versions less than 1.42.0-9
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| grpc |
affected |
Azure Linux:2 |
grpc |
— |
Open SourceCoalition ESS < 30%MEDIUM2024-02-05
In applyCustomDescription of SaveUi.java, there is a possible way to view other user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2023-40122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-02-05
CVEs:CVE-2023-40122
Open SourceCoalition ESS < 30%HIGH2024-02-05
In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441369; Issu...
CVEs:CVE-2024-20007
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2024-02-05
CVEs:CVE-2024-20007
GoogleCoalition ESS < 30%2024-02-01
ASB-A-314698312
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2024-02-05
CVEs:CVE-2024-20006
Open SourceCoalition ESS < 30%HIGH2024-02-05
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477148; Issue ID: A...
CVEs:CVE-2024-20006
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| openwrt |
affected |
openwrt |
— |
— |
| rdk-b |
affected |
rdkcentral |
— |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-314707751
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-308188986
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2024-02-05
CVEs:CVE-2024-0033
Open SourceCoalition ESS < 30%HIGH2024-02-05
In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-0033
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-298150556
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-301630648
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2024-02-05
CVEs:CVE-2024-0029
Open SourceCoalition ESS < 30%HIGH2024-02-05
In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...
CVEs:CVE-2024-0029
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2024-02-05
In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2024-0014
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2024-02-05
CVEs:CVE-2024-0014
GoogleCoalition ESS < 30%NONE2024-02-01
ASB-A-304082474
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| vendor/google/services/ConfigUpdater |
affected |
platform |
platform/vendor/google/services/ConfigUpdater |
— |
GoogleCoalition ESS < 30%HIGH2024-02-05
CVEs:CVE-2024-0038
Open SourceCoalition ESS < 30%HIGH2024-02-05
In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed...
CVEs:CVE-2024-0038
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-02-05
CVEs:CVE-2023-40093
Open SourceCoalition ESS < 30%MEDIUM2024-02-05
In multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2023-40093
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2024-02-05
CVEs:CVE-2024-0035
Open SourceCoalition ESS < 30%HIGH2024-02-05
In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...
CVEs:CVE-2024-0035
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2024-02-05
In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...
CVEs:CVE-2024-0034
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2024-02-05
CVEs:CVE-2024-0034
GoogleCoalition ESS < 30%HIGH2024-02-05
CVEs:CVE-2024-0036
Open SourceCoalition ESS < 30%HIGH2024-02-05
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privilege with no ad...
CVEs:CVE-2024-0036
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2024-02-05
CVEs:CVE-2024-0037
Open SourceCoalition ESS < 30%MEDIUM2024-02-05
In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is...
CVEs:CVE-2024-0037
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-303101658
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleCoalition ESS < 30%HIGH2024-02-05
CVEs:CVE-2024-0041
Open SourceCoalition ESS < 30%HIGH2024-02-05
In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution ...
CVEs:CVE-2024-0041
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2024-02-05
CVEs:CVE-2024-20010
Open SourceCoalition ESS < 30%MEDIUM2024-02-05
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358560; Issue I...
CVEs:CVE-2024-20010
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2024-02-01
ASB-A-314698314
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceEPSS <= 49%MEDIUM2024-02-14
Improper buffer restrictions in Intel(R) Optimization for TensorFlow before version 2.13.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVEs:CVE-2023-30767
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| optimization_for_tensorflow |
affected |
intel |
— |
— |
GoogleEPSS <= 49%MEDIUM2024-02-14
CVEs:CVE-2023-30767
GoogleAll remaining2024-02-01
ASB-A-314032846
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleAll remaining2024-02-01
ASB-A-314033392
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |