Google Security Advisories · October 2024 — Google Security Advisories
432 advisories 282 CVEs 16 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2024-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 16 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

GHSA-vgxq-6rcf-qwrw

Open SourceExploitedCISA KEV listedCRITICAL2024-10-11

angular-base64-upload vulnerable to unauthenticated remote code execution

Affected products

ProductStatusVendorPackageEcosystem
angular-base64-upload affected npm angular-base64-upload
Upstream advisory

GHSA-vgxq-6rcf-qwrw

Open SourceExploitedCISA KEV listedCRITICAL2024-10-11

angular-base64-upload vulnerable to unauthenticated remote code execution

Affected products

ProductStatusVendorPackageEcosystem
angular-base64-upload affected npm angular-base64-upload
Upstream advisory

CVE-2024-42640

Open SourceExploitedCISA KEV listedCRITICAL2024-10-11

angular-base64-upload vulnerable to unauthenticated remote code execution

CVEs:CVE-2024-42640

Affected products

ProductStatusVendorPackageEcosystem
angular-base64-upload affected npm angular-base64-upload
Upstream advisory

CVE-2024-42640

Open SourceExploitedCISA KEV listedCRITICAL2024-10-11

angular-base64-upload vulnerable to unauthenticated remote code execution

CVEs:CVE-2024-42640

Affected products

ProductStatusVendorPackageEcosystem
angular-base64-upload affected npm angular-base64-upload
Upstream advisory

CVE-2024-42640

GoogleExploitedCISA KEV listedCRITICAL2024-10-11

angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through de...

CVEs:CVE-2024-42640

Upstream advisory

CVE-2024-9680

GoogleExploitedCISA KEV listed2024-10-09

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

CVEs:CVE-2024-9680

Upstream advisory

CVE-2024-9680

Project ZeroExploitedCISA KEV listed2024-10-09

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

CVEs:CVE-2024-9680

Upstream advisory

CVE-2024-9680

GoogleExploitedCISA KEV listedCRITICAL2024-10-09

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ES...

CVEs:CVE-2024-9680

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
firefox affected mozilla
thunderbird affected mozilla
Upstream advisory

MGASA-2024-0321

Open SourceExploitedCISA KEV listedCRITICAL2024-10-04

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

CVE-2024-44068

Project ZeroExploitedCISA KEV listed2024-10-06

An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.

CVEs:CVE-2024-44068

Upstream advisory

CVE-2024-44068

GoogleExploitedCISA KEV listedCRITICAL2024-10-06

An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.

CVEs:CVE-2024-44068

Affected products

ProductStatusVendorPackageEcosystem
exynos_850_firmware affected samsung
exynos_980_firmware affected samsung
exynos_9820_firmware affected samsung
exynos_9825_firmware affected samsung
exynos_990_firmware affected samsung
exynos_w920_firmware affected samsung
Upstream advisory

CVE-2024-43047

GoogleExploitedCISA KEV listedCRITICAL2024-10-07

Memory corruption while maintaining memory maps of HLOS memory.

CVEs:CVE-2024-43047

Affected products

ProductStatusVendorPackageEcosystem
fastconnect_6700_firmware affected qualcomm
fastconnect_6800_firmware affected qualcomm
fastconnect_6900_firmware affected qualcomm
fastconnect_7800_firmware affected qualcomm
qam8295p_firmware affected qualcomm
qca6174a_firmware affected qualcomm
qca6391_firmware affected qualcomm
qca6426_firmware affected qualcomm
qca6436_firmware affected qualcomm
qca6574au_firmware affected qualcomm
qca6584au_firmware affected qualcomm
qca6595au_firmware affected qualcomm
qca6595_firmware affected qualcomm
qca6688aq_firmware affected qualcomm
qca6696_firmware affected qualcomm
qca6698aq_firmware affected qualcomm
qcs410_firmware affected qualcomm
qcs610_firmware affected qualcomm
qcs6490_firmware affected qualcomm
sa4150p_firmware affected qualcomm
sa4155p_firmware affected qualcomm
sa6145p_firmware affected qualcomm
sa6150p_firmware affected qualcomm
sa6155p_firmware affected qualcomm
sa8145p_firmware affected qualcomm
sa8150p_firmware affected qualcomm
sa8155p_firmware affected qualcomm
sa8195p_firmware affected qualcomm
sa8295p_firmware affected qualcomm
sd660_firmware affected qualcomm
sd865_5g_firmware affected qualcomm
sg4150p_firmware affected qualcomm
snapdragon_660_mobile_firmware affected qualcomm
snapdragon_680_4g_mobile_firmware affected qualcomm
snapdragon_685_4g_mobile_firmware affected qualcomm
snapdragon_865_5g_mobile_firmware affected qualcomm
snapdragon_865\+_5g_mobile_firmware affected qualcomm
snapdragon_870_5g_mobile_firmware affected qualcomm
snapdragon_888_5g_mobile_firmware affected qualcomm
snapdragon_888\+_5g_mobile_firmware affected qualcomm
snapdragon_8_gen_1_mobile_firmware affected qualcomm
snapdragon_auto_5g_modem-rf_firmware affected qualcomm
snapdragon_auto_5g_modem-rf_gen_2_firmware affected qualcomm
snapdragon_x55_5g_modem-rf_firmware affected qualcomm
snapdragon_xr2_5g_firmware affected qualcomm
sw5100_firmware affected qualcomm
sw5100p_firmware affected qualcomm
sxr2130_firmware affected qualcomm
video_collaboration_vc1_platform_firmware affected qualcomm
video_collaboration_vc3_platform_firmware affected qualcomm
wcd9335_firmware affected qualcomm
wcd9341_firmware affected qualcomm
wcd9370_firmware affected qualcomm
wcd9375_firmware affected qualcomm
wcd9380_firmware affected qualcomm
wcd9385_firmware affected qualcomm
wcn3950_firmware affected qualcomm
wcn3980_firmware affected qualcomm
wcn3988_firmware affected qualcomm
wcn3990_firmware affected qualcomm
wsa8810_firmware affected qualcomm
wsa8815_firmware affected qualcomm
wsa8830_firmware affected qualcomm
wsa8835_firmware affected qualcomm
Upstream advisory

GO-2024-3203

Open SourceActive exploitation (sightings)2024-10-17

VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/image-builder affected github.com github.com/kubernetes-sigs/image-builder
Upstream advisory

GHSA-9224-ggvw-wh7v

Open SourceActive exploitation (sightings)CRITICAL2024-10-15

VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/image-builder affected github.com github.com/kubernetes-sigs/image-builder
Upstream advisory

GHSA-9224-ggvw-wh7v

Open SourceActive exploitation (sightings)CRITICAL2024-10-15

VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/image-builder affected github.com github.com/kubernetes-sigs/image-builder
Upstream advisory

CVE-2024-9486

GoogleActive exploitation (sightings)CRITICAL2024-10-14

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, ...

CVEs:CVE-2024-9486

Affected products

ProductStatusVendorPackageEcosystem
image_builder affected kubernetes-sigs
Upstream advisory

CVE-2024-9486

GoogleActive exploitation (sightings)2024-10-14

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.

CVEs:CVE-2024-9486

Upstream advisory

CVE-2024-9486

Open SourceActive exploitation (sightings)CRITICAL2024-10-14

VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder

CVEs:CVE-2024-9486

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/image-builder affected github.com github.com/kubernetes-sigs/image-builder
Upstream advisory

GO-2024-3204

Open SourceActive exploitation (sightings)2024-10-17

VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/image-builder affected github.com github.com/kubernetes-sigs/image-builder
Upstream advisory

GHSA-8jpg-62jc-hwhr

Open SourceActive exploitation (sightings)CRITICAL2024-10-15

VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/image-builder affected github.com github.com/kubernetes-sigs/image-builder
Upstream advisory

GHSA-8jpg-62jc-hwhr

Open SourceActive exploitation (sightings)CRITICAL2024-10-15

VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/image-builder affected github.com github.com/kubernetes-sigs/image-builder
Upstream advisory

CVE-2024-9594

Open SourceActive exploitation (sightings)MEDIUM2024-10-14

VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder

CVEs:CVE-2024-9594

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/image-builder affected github.com github.com/kubernetes-sigs/image-builder
Upstream advisory

CVE-2024-9594

GoogleActive exploitation (sightings)CRITICAL2024-10-14

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root acces...

CVEs:CVE-2024-9594

Affected products

ProductStatusVendorPackageEcosystem
image_builder affected kubernetes-sigs
Upstream advisory

CVE-2024-9594

GoogleActive exploitation (sightings)2024-10-14

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. The credentials are disabled at the conclusion of the image build process. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project. Because these images were vulnerable during the image build process, they are affected only if an attacker was able to reach the VM where the image build was happening and used the vulnerability to modify the image at the time the image build was occurring.

CVEs:CVE-2024-9594

Upstream advisory

GHSA-2rxp-v6pw-ch6m

GoogleActive exploitation (sightings)HIGH2024-10-28

REXML ReDoS vulnerability

Affected products

ProductStatusVendorPackageEcosystem
rexml affected RubyGems rexml
Upstream advisory

GHSA-2rxp-v6pw-ch6m

Open SourceActive exploitation (sightings)HIGH2024-10-28

REXML ReDoS vulnerability

Affected products

ProductStatusVendorPackageEcosystem
jruby-9.4 affected wolfi jruby-9.4
jruby-9.4 affected chainguard jruby-9.4
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-fluentd-operator affected chainguard kube-fluentd-operator
logstash-8 affected wolfi logstash-8
logstash-8 affected chainguard logstash-8
logstash-jre-bcfips affected chainguard logstash-jre-bcfips
rexml affected RubyGems rexml
rexml affected RubyGems
ruby-3.1 affected wolfi ruby-3.1
ruby-3.1 affected chainguard ruby-3.1
ruby3.1-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.1-fluentd-kubernetes-daemonset-1.16
ruby3.1-fluentd-kubernetes-daemonset-1.17 affected chainguard ruby3.1-fluentd-kubernetes-daemonset-1.17
ruby3.1-fluentd-kubernetes-daemonset-1.17 affected wolfi ruby3.1-fluentd-kubernetes-daemonset-1.17
ruby-3.2 affected chainguard ruby-3.2
ruby-3.2 affected wolfi ruby-3.2
ruby3.2-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.2-fluentd-kubernetes-daemonset-1.16
ruby3.2-fluentd-kubernetes-daemonset-1.17 affected wolfi ruby3.2-fluentd-kubernetes-daemonset-1.17
ruby3.2-fluentd-kubernetes-daemonset-1.17 affected chainguard ruby3.2-fluentd-kubernetes-daemonset-1.17
ruby-3.3 affected wolfi ruby-3.3
ruby-3.3 affected chainguard ruby-3.3
ruby3.3-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.3-fluentd-kubernetes-daemonset-1.16
ruby3.4-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.4-fluentd-kubernetes-daemonset-1.16
ruby3.4-fluentd-kubernetes-daemonset-1.17 affected wolfi ruby3.4-fluentd-kubernetes-daemonset-1.17
ruby3.4-fluentd-kubernetes-daemonset-1.17 affected chainguard ruby3.4-fluentd-kubernetes-daemonset-1.17
Upstream advisory

MGASA-2024-0341

Open SourceActive exploitation (sightings)CRITICAL2024-10-29

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

ASB-A-359692772

GoogleActive exploitation (sightings)2024-10-01

ASB-A-359692772

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

openSUSE-SU-2024:0327-1

Open SourceActive exploitation (sightings)CRITICAL2024-10-07

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.5 chromium
chromium affected openSUSE:Leap 15.6 chromium
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected SUSE:Package Hub 15 SP6 chromium
Upstream advisory

openSUSE-SU-2024:14383-1

Open SourceActive exploitation (sightings)2024-10-04

chromedriver-129.0.6668.89-1.2 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

DSA-5781-1

Open SourceActive exploitation (sightings)2024-10-03

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

CVE-2024-7025

GoogleActive exploitation (sightings)CRITICAL2024-10-01

Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-7025

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-7025

GoogleActive exploitation (sightings)2024-10-01

Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-7025

Upstream advisory

openSUSE-SU-2024:14441-1

Open SourceActive exploitation (sightings)2024-10-30

chromedriver-130.0.6723.69-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

openSUSE-SU-2024:0341-1

Open SourceActive exploitation (sightings)2024-10-28

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected SUSE:Package Hub 15 SP6 chromium
chromium affected openSUSE:Leap 15.5 chromium
chromium affected openSUSE:Leap 15.6 chromium
Upstream advisory

DSA-5799-1

Open SourceActive exploitation (sightings)2024-10-28

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

CVE-2024-34665

Open SourceActive exploitation (sightings)HIGH2024-10-07

Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34665

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34666

Open SourceActive exploitation (sightings)HIGH2024-10-07

Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34666

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34667

Open SourceActive exploitation (sightings)HIGH2024-10-07

Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34667

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34668

Open SourceActive exploitation (sightings)HIGH2024-10-07

Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34668

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34669

Open SourceActive exploitation (sightings)HIGH2024-10-07

Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVEs:CVE-2024-34669

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-50486

Open SourceActive exploitation (sightings)CRITICAL2024-10-28

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through <= 1.0.5.

CVEs:CVE-2024-50486

Affected products

ProductStatusVendorPackageEcosystem
flutter_api affected acnoo
Upstream advisory

GHSA-3hjp-j522-245f

Open SourceActive exploitation (sightings)HIGH2024-10-23

GHSA-3hjp-j522-245f

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-10229

Open SourceActive exploitation (sightings)HIGH2024-10-22

DEBIAN-CVE-2024-10229

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-10229

GoogleActive exploitation (sightings)HIGH2024-10-22

Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)

CVEs:CVE-2024-10229

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-10229

GoogleActive exploitation (sightings)2024-10-22

Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)

CVEs:CVE-2024-10229

Upstream advisory

DEBIAN-CVE-2024-44337

Open SourceActive exploitation (sightings)CRITICAL2024-10-15

DEBIAN-CVE-2024-44337

Affected products

ProductStatusVendorPackageEcosystem
golang-github-gomarkdown-markdown affected Debian:12 golang-github-gomarkdown-markdown
golang-github-gomarkdown-markdown affected Debian:13 golang-github-gomarkdown-markdown
golang-github-gomarkdown-markdown affected Debian:14 golang-github-gomarkdown-markdown
Upstream advisory

GHSA-3wfx-mj93-vf8v

Open SourceActive exploitation (sightings)HIGH2024-10-23

GHSA-3wfx-mj93-vf8v

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-10231

Open SourceActive exploitation (sightings)HIGH2024-10-22

DEBIAN-CVE-2024-10231

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-10231

GoogleActive exploitation (sightings)2024-10-22

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-10231

Upstream advisory

CVE-2024-10231

GoogleActive exploitation (sightings)HIGH2024-10-22

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-10231

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-43577

Open SourceActive exploitation (sightings)MEDIUM2024-10-08

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2024-43577

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2024-9675

Open SourceActive exploitation (sightings)MEDIUM2024-10-09

DEBIAN-CVE-2024-9675

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-buildah affected Debian:11 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:12 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:13 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:14 golang-github-containers-buildah
Upstream advisory

GO-2024-3210

Open SourceActive exploitation (sightings)2024-10-28

Lack of JWT issuer and signer validation in github.com/awslabs/aws-alb-route-directive-adapter-for-istio

Affected products

ProductStatusVendorPackageEcosystem
awslabs/aws-alb-route-directive-adapter-for-istio affected github.com github.com/awslabs/aws-alb-route-directive-adapter-for-istio
Upstream advisory

CVE-2024-20103

Open SourceActive exploitation (sightings)CRITICAL2024-10-07

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001358...

CVEs:CVE-2024-20103

Affected products

ProductStatusVendorPackageEcosystem
android affected google
software_development_kit affected mediatek
Upstream advisory

CVE-2024-20100

Open SourceActive exploitation (sightings)CRITICAL2024-10-07

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; ...

CVEs:CVE-2024-20100

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iot_yocto affected mediatek
software_development_kit affected mediatek
Upstream advisory

ASB-A-359692770

GoogleActive exploitation (sightings)2024-10-01

ASB-A-359692770

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-359699097

GoogleActive exploitation (sightings)2024-10-01

ASB-A-359699097

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20101

Open SourceActive exploitation (sightings)CRITICAL2024-10-07

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; ...

CVEs:CVE-2024-20101

Affected products

ProductStatusVendorPackageEcosystem
android affected google
software_development_kit affected mediatek
Upstream advisory

ASB-A-359699100

GoogleActive exploitation (sightings)2024-10-01

ASB-A-359699100

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-335031447

GoogleActive exploitation (sightings)MEDIUM2024-10-01

PUB-A-335031447

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20102

Open SourceActive exploitation (sightings)MEDIUM2024-10-07

In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998892; ...

CVEs:CVE-2024-20102

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2024-9407

Open SourceActive exploitation (sightings)CRITICAL2024-10-01

DEBIAN-CVE-2024-9407

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-buildah affected Debian:11 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:12 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:13 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:14 golang-github-containers-buildah
Upstream advisory

CVE-2024-40673

Open SourceActive exploitation (sightings)HIGH2024-10-07

In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed....

CVEs:CVE-2024-40673

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-49606

GoogleActive exploitation (sightings)CRITICAL2024-10-20

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DotsquaresLtd Google Map Locations google-map-locations allows Reflected XSS.This issue affects Google Map Locations: from n/a through <= 1.0.

CVEs:CVE-2024-49606

Affected products

ProductStatusVendorPackageEcosystem
google_map_locations affected dotsquares
Upstream advisory

CVE-2024-39438

Open SourceActive exploitation (sightings)CRITICAL2024-10-09

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

CVEs:CVE-2024-39438

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-39437

Open SourceActive exploitation (sightings)CRITICAL2024-10-09

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

CVEs:CVE-2024-39437

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-39436

Open SourceActive exploitation (sightings)CRITICAL2024-10-09

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

CVEs:CVE-2024-39436

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47014

Open SourceActive exploitation (sightings)CRITICAL2024-10-15

Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.

CVEs:CVE-2024-47014

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-330537292

GoogleActive exploitation (sightings)2024-10-01

PUB-A-330537292

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47023

Open SourceActive exploitation (sightings)HIGH2024-10-15

there is a possible man-in-the-middle attack due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-47023

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-335031446

GoogleActive exploitation (sightings)NONE2024-10-01

PUB-A-335031446

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-40674

Open SourceActive exploitation (sightings)MEDIUM2024-10-07

In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction...

CVEs:CVE-2024-40674

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-49672

GoogleActive exploitation (sightings)HIGH2024-10-29

Cross-Site Request Forgery (CSRF) vulnerability in giffordcheung Google Docs RSVP google-docs-rsvp-guestlist allows Stored XSS.This issue affects Google Docs RSVP: from n/a through <= 2.0.1.

CVEs:CVE-2024-49672

Affected products

ProductStatusVendorPackageEcosystem
google_docs_rsvp affected gief
Upstream advisory

CVE-2024-40676

Open SourceActive exploitation (sightings)HIGH2024-10-07

In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges neede...

CVEs:CVE-2024-40676

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-49335

GoogleActive exploitation (sightings)HIGH2024-10-20

Cross-Site Request Forgery (CSRF) vulnerability in sh4d0w28 GoogleDrive folder list googledrive-folder-list allows Stored XSS.This issue affects GoogleDrive folder list: from n/a through <= 2.2.2.

CVEs:CVE-2024-49335

Affected products

ProductStatusVendorPackageEcosystem
googledrive_folder_list affected edush_maxim
Upstream advisory

CVE-2024-44097

GoogleActive exploitation (sightings)CRITICAL2024-10-02

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to ...

CVEs:CVE-2024-44097

Affected products

ProductStatusVendorPackageEcosystem
nest_cam_\(indoor\,_wired\)_firmware affected google
nest_cam_\(outdoor_or_indoor\,_battery\)_firmware affected google
nest_cam_with_floodlight_firmware affected google
nest_doorbell_\(battery\)_firmware affected google
Upstream advisory

ASB-A-350500647

GoogleActive exploitation (sightings)2024-10-01

ASB-A-350500647

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
vendor/qcom/opensource/graphics-kernel affected platform platform/vendor/qcom/opensource/graphics-kernel
Upstream advisory

CVE-2024-34662

Open SourceActive exploitation (sightings)HIGH2024-10-07

Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors.

CVEs:CVE-2024-34662

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2024-34664

Open SourceActive exploitation (sightings)MEDIUM2024-10-07

Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment.

CVEs:CVE-2024-34664

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20093

Open SourceActive exploitation (sightings)MEDIUM2024-10-07

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: M...

CVEs:CVE-2024-20093

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-359692902

GoogleActive exploitation (sightings)2024-10-01

ASB-A-359692902

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-359699091

GoogleActive exploitation (sightings)2024-10-01

ASB-A-359699091

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-359699094

GoogleActive exploitation (sightings)2024-10-01

ASB-A-359699094

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-359699096

GoogleActive exploitation (sightings)2024-10-01

ASB-A-359699096

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20097

Open SourceActive exploitation (sightings)MEDIUM2024-10-07

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: M...

CVEs:CVE-2024-20097

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20096

Open SourceActive exploitation (sightings)MEDIUM2024-10-07

In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996900; Issue ID: MS...

CVEs:CVE-2024-20096

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20095

Open SourceActive exploitation (sightings)MEDIUM2024-10-07

In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996894; Issue ID: MS...

CVEs:CVE-2024-20095

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47030

Open SourceActive exploitation (sightings)HIGH2024-10-15

Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-315191818.

CVEs:CVE-2024-47030

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-315191818

GoogleActive exploitation (sightings)2024-10-01

PUB-A-315191818

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47027

Open SourceActive exploitation (sightings)HIGH2024-10-15

In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2024-47027

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-326444917

GoogleActive exploitation (sightings)NONE2024-10-01

PUB-A-326444917

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-34733

Open SourceActive exploitation (sightings)HIGH2024-10-07

In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2024-34733

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-34748

Open SourceActive exploitation (sightings)HIGH2024-10-07

In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2024-34748

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-340329532

GoogleActive exploitation (sightings)HIGH2024-10-01

ASB-A-340329532

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-346640884

GoogleActive exploitation (sightings)HIGH2024-10-01

ASB-A-346640884

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-20090

Open SourceActive exploitation (sightings)HIGH2024-10-07

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID:...

CVEs:CVE-2024-20090

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-40649

Open SourceActive exploitation (sightings)HIGH2024-10-07

In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-40649

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-40651

Open SourceActive exploitation (sightings)HIGH2024-10-07

In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-40651

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-346633576

GoogleActive exploitation (sightings)HIGH2024-10-01

ASB-A-346633576

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-346635977

GoogleActive exploitation (sightings)HIGH2024-10-01

ASB-A-346635977

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-40672

Open SourceActive exploitation (sightings)HIGH2024-10-07

In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2024-40672

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-40677

Open SourceActive exploitation (sightings)HIGH2024-10-07

In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed....

CVEs:CVE-2024-40677

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20092

Open SourceActive exploitation (sightings)HIGH2024-10-07

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID:...

CVEs:CVE-2024-20092

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20091

Open SourceActive exploitation (sightings)MEDIUM2024-10-07

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: M...

CVEs:CVE-2024-20091

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-40669

Open SourceActive exploitation (sightings)HIGH2024-10-07

In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-40669

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-40670

Open SourceActive exploitation (sightings)HIGH2024-10-07

In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-40670

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-354263469

GoogleActive exploitation (sightings)HIGH2024-10-01

ASB-A-354263469

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-354268756

GoogleActive exploitation (sightings)HIGH2024-10-01

ASB-A-354268756

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47017

Open SourceActive exploitation (sightings)HIGH2024-10-15

In ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-47017

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-20099

GoogleActive exploitation (sightings)2024-10-07

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID: MSV-1625.

CVEs:CVE-2024-20099

Upstream advisory

CVE-2024-20099

Open SourceActive exploitation (sightings)HIGH2024-10-07

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID...

CVEs:CVE-2024-20099

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2024-20098

Open SourceActive exploitation (sightings)HIGH2024-10-07

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID...

CVEs:CVE-2024-20098

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected linuxfoundation
Upstream advisory

CVE-2024-20098

GoogleActive exploitation (sightings)2024-10-07

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID: MSV-1626.

CVEs:CVE-2024-20098

Upstream advisory

PUB-A-330389917

GoogleActive exploitation (sightings)HIGH2024-10-01

PUB-A-330389917

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-34663

Open SourceActive exploitation (sightings)HIGH2024-10-07

Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.

CVEs:CVE-2024-34663

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47035

Open SourceActive exploitation (sightings)HIGH2024-10-15

In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...

CVEs:CVE-2024-47035

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-341120728

GoogleActive exploitation (sightings)HIGH2024-10-01

PUB-A-341120728

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47015

Open SourceActive exploitation (sightings)HIGH2024-10-15

In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interacti...

CVEs:CVE-2024-47015

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-39440

Open SourceActive exploitation (sightings)HIGH2024-10-09

In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2024-39440

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-39439

Open SourceActive exploitation (sightings)CRITICAL2024-10-09

In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVEs:CVE-2024-39439

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-331672131

GoogleActive exploitation (sightings)HIGH2024-10-01

PUB-A-331672131

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47024

Open SourceActive exploitation (sightings)HIGH2024-10-15

In vring_size of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2024-47024

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47041

Open SourceActive exploitation (sightings)HIGH2024-10-15

In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-47041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-319710920

GoogleActive exploitation (sightings)NONE2024-10-01

PUB-A-319710920

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-340720879

GoogleActive exploitation (sightings)HIGH2024-10-01

PUB-A-340720879

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47013

Open SourceActive exploitation (sightings)HIGH2024-10-15

In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2024-47013

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47016

Open SourceActive exploitation (sightings)HIGH2024-10-15

there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-47016

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47033

Open SourceActive exploitation (sightings)HIGH2024-10-15

In lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-47033

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-328221525

GoogleActive exploitation (sightings)HIGH2024-10-01

PUB-A-328221525

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-330607706

GoogleActive exploitation (sightings)NONE2024-10-01

PUB-A-330607706

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-349428550

GoogleActive exploitation (sightings)HIGH2024-10-01

PUB-A-349428550

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47028

Open SourceActive exploitation (sightings)HIGH2024-10-15

In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-47028

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-329334922

GoogleActive exploitation (sightings)HIGH2024-10-01

PUB-A-329334922

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47026

Open SourceActive exploitation (sightings)MEDIUM2024-10-15

In gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-47026

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47029

Open SourceActive exploitation (sightings)MEDIUM2024-10-15

In TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution priv...

CVEs:CVE-2024-47029

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47034

Open SourceActive exploitation (sightings)MEDIUM2024-10-15

there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-47034

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-310937217

GoogleActive exploitation (sightings)MEDIUM2024-10-01

PUB-A-310937217

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-331483147

GoogleActive exploitation (sightings)MEDIUM2024-10-01

PUB-A-331483147

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-340527441

GoogleActive exploitation (sightings)MEDIUM2024-10-01

PUB-A-340527441

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47025

Open SourceActive exploitation (sightings)MEDIUM2024-10-15

In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-47025

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-306211423

GoogleActive exploitation (sightings)MEDIUM2024-10-01

PUB-A-306211423

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

RHSA-2024:2936

Open SourcePoC exploitHIGH2024-10-21

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:rhel_eus:8.8::appstream delve
delve-debuginfo affected Red Hat:rhel_eus:8.8::appstream delve-debuginfo
delve-debugsource affected Red Hat:rhel_eus:8.8::appstream delve-debugsource
golang affected Red Hat:rhel_eus:8.8::appstream golang
golang-bin affected Red Hat:rhel_eus:8.8::appstream golang-bin
golang-docs affected Red Hat:rhel_eus:8.8::appstream golang-docs
golang-misc affected Red Hat:rhel_eus:8.8::appstream golang-misc
golang-race affected Red Hat:rhel_eus:8.8::appstream golang-race
golang-src affected Red Hat:rhel_eus:8.8::appstream golang-src
golang-tests affected Red Hat:rhel_eus:8.8::appstream golang-tests
go-toolset affected Red Hat:rhel_eus:8.8::appstream go-toolset
Upstream advisory

RHSA-2024:2935

Open SourcePoC exploitHIGH2024-10-21

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:rhel_eus:8.6::appstream delve
delve-debuginfo affected Red Hat:rhel_eus:8.6::appstream delve-debuginfo
delve-debugsource affected Red Hat:rhel_eus:8.6::appstream delve-debugsource
golang affected Red Hat:rhel_eus:8.6::appstream golang
golang-bin affected Red Hat:rhel_eus:8.6::appstream golang-bin
golang-docs affected Red Hat:rhel_eus:8.6::appstream golang-docs
golang-misc affected Red Hat:rhel_eus:8.6::appstream golang-misc
golang-race affected Red Hat:rhel_eus:8.6::appstream golang-race
golang-src affected Red Hat:rhel_eus:8.6::appstream golang-src
golang-tests affected Red Hat:rhel_eus:8.6::appstream golang-tests
go-toolset affected Red Hat:rhel_eus:8.6::appstream go-toolset
Upstream advisory

RHSA-2024:1962

Open SourcePoC exploitHIGH2024-10-21

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

openSUSE-SU-2024:14399-1

Open SourcePoC exploit2024-10-14

etcd-for-k8s1.28-3.5.15-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
etcd-for-k8s1.28 affected openSUSE:Tumbleweed etcd-for-k8s1.28
Upstream advisory

openSUSE-SU-2024:14400-1

Open SourcePoC exploit2024-10-14

etcd-for-k8s1.30-3.5.15-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
etcd-for-k8s1.30 affected openSUSE:Tumbleweed etcd-for-k8s1.30
Upstream advisory

RHSA-2019:2726

Open SourcePoC exploitHIGH2024-10-09

Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

RHSA-2022:5337

Open SourcePoC exploitHIGH2024-10-21

Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

RHSA-2021:3076

Open SourcePoC exploitHIGH2024-10-21

Red Hat Security Advisory: go-toolset:rhel8 security, bug fix, and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

DSA-5793-1

Open SourcePoC exploit2024-10-20

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

openSUSE-SU-2024:14414-1

Open SourcePoC exploit2024-10-19

chromedriver-130.0.6723.58-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

openSUSE-SU-2024:0337-1

Open SourcePoC exploitCRITICAL2024-10-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected SUSE:Package Hub 15 SP6 chromium
chromium affected openSUSE:Leap 15.5 chromium
chromium affected openSUSE:Leap 15.6 chromium
Upstream advisory

RHSA-2021:5160

Open SourcePoC exploitHIGH2024-10-21

Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

RHSA-2021:3585

Open SourcePoC exploitHIGH2024-10-21

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

RHSA-2021:4156

Open SourcePoC exploitHIGH2024-10-21

Red Hat Security Advisory: go-toolset:rhel8 security, bug fix, and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-race affected Red Hat:enterprise_linux:8::appstream golang-race
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

SUSE-SU-2024:3747-1

Open SourcePoC exploitCRITICAL2024-10-22

Security update for protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected openSUSE:Leap 15.5 protobuf
protobuf affected SUSE:Linux Enterprise Installer Updates 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.5 protobuf
protobuf affected SUSE:Linux Enterprise Module for Basesystem 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise Module for Development Tools 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise Module for Package Hub 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise Module for Public Cloud 15 SP5 protobuf
protobuf affected SUSE:Linux Enterprise Module for Python 3 15 SP5 protobuf
protobuf affected openSUSE:Leap Micro 5.5 protobuf
Upstream advisory

SUSE-SU-2024:3746-1

Open SourcePoC exploitCRITICAL2024-10-22

Security update for protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected SUSE:Linux Enterprise Server 15 SP4-LTSS protobuf
protobuf affected SUSE:Linux Enterprise Server for SAP Applications 15 SP4 protobuf
protobuf affected SUSE:Manager Server 4.3 protobuf
protobuf affected SUSE:Linux Enterprise Installer Updates 15 SP4 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.3 protobuf
protobuf affected SUSE:Linux Enterprise Micro 5.4 protobuf
protobuf affected SUSE:Linux Enterprise Module for Public Cloud 15 SP4 protobuf
protobuf affected SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS protobuf
protobuf affected SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS protobuf
Upstream advisory

SUSE-SU-2024:3745-1

Open SourcePoC exploitCRITICAL2024-10-22

Security update for protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected SUSE:Linux Enterprise Module for Basesystem 15 SP6 protobuf
protobuf affected SUSE:Linux Enterprise Module for Development Tools 15 SP6 protobuf
protobuf affected SUSE:Linux Enterprise Module for Package Hub 15 SP6 protobuf
protobuf affected SUSE:Linux Enterprise Module for Python 3 15 SP6 protobuf
protobuf affected openSUSE:Leap 15.6 protobuf
Upstream advisory

CLSA-2024-1730133909

Open SourcePoC exploit2024-10-28

Fix CVE(s): CVE-2023-27043

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:18.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:18.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:18.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:18.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:18.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:18.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:18.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:18.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:18.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:18.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:18.04 python2.7-minimal
Upstream advisory

CLSA-2024-1729628050

Open SourcePoC exploitCRITICAL2024-10-22

Fix CVE(s): CVE-2023-27043

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.6 affected TuxCare:Ubuntu:18.04 idle-python3.6
libpython3.6 affected TuxCare:Ubuntu:18.04 libpython3.6
libpython3.6-dev affected TuxCare:Ubuntu:18.04 libpython3.6-dev
libpython3.6-minimal affected TuxCare:Ubuntu:18.04 libpython3.6-minimal
libpython3.6-stdlib affected TuxCare:Ubuntu:18.04 libpython3.6-stdlib
libpython3.6-testsuite affected TuxCare:Ubuntu:18.04 libpython3.6-testsuite
python3.6 affected TuxCare:Ubuntu:18.04 python3.6
python3.6-dev affected TuxCare:Ubuntu:18.04 python3.6-dev
python3.6-doc affected TuxCare:Ubuntu:18.04 python3.6-doc
python3.6-examples affected TuxCare:Ubuntu:18.04 python3.6-examples
python3.6-minimal affected TuxCare:Ubuntu:18.04 python3.6-minimal
python3.6-venv affected TuxCare:Ubuntu:18.04 python3.6-venv
Upstream advisory

CLSA-2024-1729627400

Open SourcePoC exploitCRITICAL2024-10-22

Fix CVE(s): CVE-2023-27043

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

CLSA-2024-1729627193

Open SourcePoC exploit2024-10-22

Fix CVE(s): CVE-2023-27043

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

CLSA-2024-1727895277

Open SourcePoC exploitCRITICAL2024-10-02

Fix CVE(s): CVE-2024-6232, CVE-2024-7592

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:18.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:18.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:18.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:18.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:18.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:18.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:18.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:18.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:18.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:18.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:18.04 python2.7-minimal
Upstream advisory

CLSA-2024-1727895166

Open SourcePoC exploitCRITICAL2024-10-02

Fix CVE(s): CVE-2024-6232, CVE-2024-7592

Affected products

ProductStatusVendorPackageEcosystem
idle-python2.7 affected TuxCare:Ubuntu:16.04 idle-python2.7
libpython2.7 affected TuxCare:Ubuntu:16.04 libpython2.7
libpython2.7-dev affected TuxCare:Ubuntu:16.04 libpython2.7-dev
libpython2.7-minimal affected TuxCare:Ubuntu:16.04 libpython2.7-minimal
libpython2.7-stdlib affected TuxCare:Ubuntu:16.04 libpython2.7-stdlib
libpython2.7-testsuite affected TuxCare:Ubuntu:16.04 libpython2.7-testsuite
python2.7 affected TuxCare:Ubuntu:16.04 python2.7
python2.7-dev affected TuxCare:Ubuntu:16.04 python2.7-dev
python2.7-doc affected TuxCare:Ubuntu:16.04 python2.7-doc
python2.7-examples affected TuxCare:Ubuntu:16.04 python2.7-examples
python2.7-minimal affected TuxCare:Ubuntu:16.04 python2.7-minimal
Upstream advisory

RHSA-2024:4237

Open SourcePoC exploitMEDIUM2024-10-21

Red Hat Security Advisory: go-toolset security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

RHSA-2024:5077

Open SourcePoC exploitMEDIUM2024-10-21

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:rhel_eus:8.8::appstream delve
delve-debuginfo affected Red Hat:rhel_eus:8.8::appstream delve-debuginfo
delve-debugsource affected Red Hat:rhel_eus:8.8::appstream delve-debugsource
golang affected Red Hat:rhel_eus:8.8::appstream golang
golang-bin affected Red Hat:rhel_eus:8.8::appstream golang-bin
golang-docs affected Red Hat:rhel_eus:8.8::appstream golang-docs
golang-misc affected Red Hat:rhel_eus:8.8::appstream golang-misc
golang-race affected Red Hat:rhel_eus:8.8::appstream golang-race
golang-src affected Red Hat:rhel_eus:8.8::appstream golang-src
golang-tests affected Red Hat:rhel_eus:8.8::appstream golang-tests
go-toolset affected Red Hat:rhel_eus:8.8::appstream go-toolset
Upstream advisory

RHSA-2024:5075

Open SourcePoC exploitMEDIUM2024-10-02

Red Hat Security Advisory: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:rhel_eus:9.2::appstream golang
golang-bin affected Red Hat:rhel_eus:9.2::appstream golang-bin
golang-docs affected Red Hat:rhel_eus:9.2::appstream golang-docs
golang-misc affected Red Hat:rhel_eus:9.2::appstream golang-misc
golang-race affected Red Hat:rhel_eus:9.2::appstream golang-race
golang-src affected Red Hat:rhel_eus:9.2::appstream golang-src
golang-tests affected Red Hat:rhel_eus:9.2::appstream golang-tests
Upstream advisory

RHSA-2024:4212

Open SourcePoC exploitMEDIUM2024-10-02

Red Hat Security Advisory: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:9::appstream golang
golang-bin affected Red Hat:enterprise_linux:9::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:9::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:9::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:9::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:9::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:9::appstream go-toolset
Upstream advisory

RHSA-2024:6908

Open SourcePoC exploitHIGH2024-10-22

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

RHSA-2024:6912

Open SourcePoC exploitHIGH2024-10-22

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:rhel_eus:8.8::appstream delve
delve-debuginfo affected Red Hat:rhel_eus:8.8::appstream delve-debuginfo
delve-debugsource affected Red Hat:rhel_eus:8.8::appstream delve-debugsource
golang affected Red Hat:rhel_eus:8.8::appstream golang
golang-bin affected Red Hat:rhel_eus:8.8::appstream golang-bin
golang-docs affected Red Hat:rhel_eus:8.8::appstream golang-docs
golang-misc affected Red Hat:rhel_eus:8.8::appstream golang-misc
golang-race affected Red Hat:rhel_eus:8.8::appstream golang-race
golang-src affected Red Hat:rhel_eus:8.8::appstream golang-src
golang-tests affected Red Hat:rhel_eus:8.8::appstream golang-tests
go-toolset affected Red Hat:rhel_eus:8.8::appstream go-toolset
Upstream advisory

RHSA-2024:6913

Open SourcePoC exploitHIGH2024-10-02

Red Hat Security Advisory: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:9::appstream golang
golang-bin affected Red Hat:enterprise_linux:9::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:9::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:9::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:9::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:9::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:9::appstream go-toolset
Upstream advisory

RHSA-2024:6914

Open SourcePoC exploitHIGH2024-10-02

Red Hat Security Advisory: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:rhel_eus:9.2::appstream golang
golang-bin affected Red Hat:rhel_eus:9.2::appstream golang-bin
golang-docs affected Red Hat:rhel_eus:9.2::appstream golang-docs
golang-misc affected Red Hat:rhel_eus:9.2::appstream golang-misc
golang-race affected Red Hat:rhel_eus:9.2::appstream golang-race
golang-src affected Red Hat:rhel_eus:9.2::appstream golang-src
golang-tests affected Red Hat:rhel_eus:9.2::appstream golang-tests
Upstream advisory

DEBIAN-CVE-2024-9676

Open SourcePoC exploitHIGH2024-10-15

DEBIAN-CVE-2024-9676

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-storage affected Debian:11 golang-github-containers-storage
golang-github-containers-storage affected Debian:12 golang-github-containers-storage
golang-github-containers-storage affected Debian:13 golang-github-containers-storage
golang-github-containers-storage affected Debian:14 golang-github-containers-storage
Upstream advisory

RHSA-2024:7487

Open SourcePoC exploitHIGH2024-10-22

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:rhel_aus:8.6::appstream delve
delve affected Red Hat:rhel_e4s:8.6::appstream delve
delve affected Red Hat:rhel_tus:8.6::appstream delve
delve-debuginfo affected Red Hat:rhel_e4s:8.6::appstream delve-debuginfo
delve-debuginfo affected Red Hat:rhel_aus:8.6::appstream delve-debuginfo
delve-debuginfo affected Red Hat:rhel_tus:8.6::appstream delve-debuginfo
delve-debugsource affected Red Hat:rhel_e4s:8.6::appstream delve-debugsource
delve-debugsource affected Red Hat:rhel_tus:8.6::appstream delve-debugsource
delve-debugsource affected Red Hat:rhel_aus:8.6::appstream delve-debugsource
golang affected Red Hat:rhel_tus:8.6::appstream golang
golang affected Red Hat:rhel_aus:8.6::appstream golang
golang affected Red Hat:rhel_e4s:8.6::appstream golang
golang-bin affected Red Hat:rhel_e4s:8.6::appstream golang-bin
golang-bin affected Red Hat:rhel_aus:8.6::appstream golang-bin
golang-bin affected Red Hat:rhel_tus:8.6::appstream golang-bin
golang-docs affected Red Hat:rhel_e4s:8.6::appstream golang-docs
golang-docs affected Red Hat:rhel_aus:8.6::appstream golang-docs
golang-docs affected Red Hat:rhel_tus:8.6::appstream golang-docs
golang-misc affected Red Hat:rhel_aus:8.6::appstream golang-misc
golang-misc affected Red Hat:rhel_e4s:8.6::appstream golang-misc
golang-misc affected Red Hat:rhel_tus:8.6::appstream golang-misc
golang-race affected Red Hat:rhel_aus:8.6::appstream golang-race
golang-race affected Red Hat:rhel_e4s:8.6::appstream golang-race
golang-race affected Red Hat:rhel_tus:8.6::appstream golang-race
golang-src affected Red Hat:rhel_tus:8.6::appstream golang-src
golang-src affected Red Hat:rhel_e4s:8.6::appstream golang-src
golang-src affected Red Hat:rhel_aus:8.6::appstream golang-src
golang-tests affected Red Hat:rhel_e4s:8.6::appstream golang-tests
golang-tests affected Red Hat:rhel_tus:8.6::appstream golang-tests
golang-tests affected Red Hat:rhel_aus:8.6::appstream golang-tests
go-toolset affected Red Hat:rhel_tus:8.6::appstream go-toolset
go-toolset affected Red Hat:rhel_aus:8.6::appstream go-toolset
go-toolset affected Red Hat:rhel_e4s:8.6::appstream go-toolset
Upstream advisory

RHSA-2024:7488

Open SourcePoC exploitHIGH2024-10-22

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:rhel_tus:8.4::appstream delve
delve affected Red Hat:rhel_e4s:8.4::appstream delve
delve affected Red Hat:rhel_aus:8.4::appstream delve
delve-debuginfo affected Red Hat:rhel_e4s:8.4::appstream delve-debuginfo
delve-debuginfo affected Red Hat:rhel_aus:8.4::appstream delve-debuginfo
delve-debuginfo affected Red Hat:rhel_tus:8.4::appstream delve-debuginfo
delve-debugsource affected Red Hat:rhel_tus:8.4::appstream delve-debugsource
delve-debugsource affected Red Hat:rhel_e4s:8.4::appstream delve-debugsource
delve-debugsource affected Red Hat:rhel_aus:8.4::appstream delve-debugsource
golang affected Red Hat:rhel_tus:8.4::appstream golang
golang affected Red Hat:rhel_aus:8.4::appstream golang
golang affected Red Hat:rhel_e4s:8.4::appstream golang
golang-bin affected Red Hat:rhel_e4s:8.4::appstream golang-bin
golang-bin affected Red Hat:rhel_aus:8.4::appstream golang-bin
golang-bin affected Red Hat:rhel_tus:8.4::appstream golang-bin
golang-docs affected Red Hat:rhel_aus:8.4::appstream golang-docs
golang-docs affected Red Hat:rhel_tus:8.4::appstream golang-docs
golang-docs affected Red Hat:rhel_e4s:8.4::appstream golang-docs
golang-misc affected Red Hat:rhel_tus:8.4::appstream golang-misc
golang-misc affected Red Hat:rhel_aus:8.4::appstream golang-misc
golang-misc affected Red Hat:rhel_e4s:8.4::appstream golang-misc
golang-race affected Red Hat:rhel_tus:8.4::appstream golang-race
golang-race affected Red Hat:rhel_e4s:8.4::appstream golang-race
golang-race affected Red Hat:rhel_aus:8.4::appstream golang-race
golang-src affected Red Hat:rhel_aus:8.4::appstream golang-src
golang-src affected Red Hat:rhel_tus:8.4::appstream golang-src
golang-src affected Red Hat:rhel_e4s:8.4::appstream golang-src
golang-tests affected Red Hat:rhel_aus:8.4::appstream golang-tests
golang-tests affected Red Hat:rhel_e4s:8.4::appstream golang-tests
golang-tests affected Red Hat:rhel_tus:8.4::appstream golang-tests
go-toolset affected Red Hat:rhel_aus:8.4::appstream go-toolset
go-toolset affected Red Hat:rhel_tus:8.4::appstream go-toolset
go-toolset affected Red Hat:rhel_e4s:8.4::appstream go-toolset
Upstream advisory

SUSE-SU-2024:3458-1

Open SourcePoC exploit2024-10-04

Security update for kubernetes1.24

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.24 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS kubernetes1.24
kubernetes1.24 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS kubernetes1.24
kubernetes1.24 affected SUSE:Linux Enterprise Server 15 SP4-LTSS kubernetes1.24
kubernetes1.24 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP4 kubernetes1.24
Upstream advisory

SUSE-SU-2024:3453-1

Open SourcePoC exploit2024-10-04

Security update for kubernetes1.24

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.24 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.24
kubernetes1.24 affected openSUSE:Leap 15.5 kubernetes1.24
kubernetes1.24 affected openSUSE:Leap 15.6 kubernetes1.24
Upstream advisory

SUSE-SU-2024:3459-1

Open SourcePoC exploit2024-10-02

Security update for kubernetes1.24

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.24 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kubernetes1.24
kubernetes1.24 affected SUSE:Enterprise Storage 7.1 kubernetes1.24
kubernetes1.24 affected SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kubernetes1.24
kubernetes1.24 affected SUSE:Linux Enterprise Server 15 SP3-LTSS kubernetes1.24
Upstream advisory

SUSE-SU-2024:3457-1

Open SourcePoC exploit2024-10-02

Security update for kubernetes1.25

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.25 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP4 kubernetes1.25
kubernetes1.25 affected openSUSE:Leap 15.6 kubernetes1.25
kubernetes1.25 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.25
kubernetes1.25 affected SUSE:Linux Enterprise Module for Containers 15 SP6 kubernetes1.25
kubernetes1.25 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS kubernetes1.25
kubernetes1.25 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS kubernetes1.25
kubernetes1.25 affected SUSE:Linux Enterprise Server 15 SP4-LTSS kubernetes1.25
kubernetes1.25 affected openSUSE:Leap 15.5 kubernetes1.25
Upstream advisory

SUSE-SU-2024:3456-1

Open SourcePoC exploit2024-10-02

Security update for kubernetes1.26

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.26 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.26
kubernetes1.26 affected SUSE:Linux Enterprise Module for Containers 15 SP6 kubernetes1.26
kubernetes1.26 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS kubernetes1.26
kubernetes1.26 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS kubernetes1.26
kubernetes1.26 affected SUSE:Linux Enterprise Server 15 SP4-LTSS kubernetes1.26
kubernetes1.26 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP4 kubernetes1.26
kubernetes1.26 affected openSUSE:Leap 15.5 kubernetes1.26
kubernetes1.26 affected openSUSE:Leap 15.6 kubernetes1.26
Upstream advisory

SUSE-SU-2024:3455-1

Open SourcePoC exploit2024-10-02

Security update for kubernetes1.27

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.27 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.27
kubernetes1.27 affected SUSE:Linux Enterprise Module for Containers 15 SP6 kubernetes1.27
kubernetes1.27 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS kubernetes1.27
kubernetes1.27 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS kubernetes1.27
kubernetes1.27 affected SUSE:Linux Enterprise Server 15 SP4-LTSS kubernetes1.27
kubernetes1.27 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP4 kubernetes1.27
kubernetes1.27 affected openSUSE:Leap 15.5 kubernetes1.27
kubernetes1.27 affected openSUSE:Leap 15.6 kubernetes1.27
Upstream advisory

SUSE-SU-2024:3454-1

Open SourcePoC exploit2024-10-02

Security update for kubernetes1.28

Affected products

ProductStatusVendorPackageEcosystem
kubernetes1.28 affected SUSE:Linux Enterprise Module for Containers 15 SP5 kubernetes1.28
kubernetes1.28 affected SUSE:Linux Enterprise Module for Containers 15 SP6 kubernetes1.28
kubernetes1.28 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS kubernetes1.28
kubernetes1.28 affected SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS kubernetes1.28
kubernetes1.28 affected SUSE:Linux Enterprise Server 15 SP4-LTSS kubernetes1.28
kubernetes1.28 affected SUSE:Linux Enterprise Server for SAP Applications 15 SP4 kubernetes1.28
kubernetes1.28 affected openSUSE:Leap 15.5 kubernetes1.28
kubernetes1.28 affected openSUSE:Leap 15.6 kubernetes1.28
Upstream advisory

RHSA-2024:7485

Open SourcePoC exploitHIGH2024-10-02

Red Hat Security Advisory: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:rhel_e4s:9.0::appstream golang
golang-bin affected Red Hat:rhel_e4s:9.0::appstream golang-bin
golang-docs affected Red Hat:rhel_e4s:9.0::appstream golang-docs
golang-misc affected Red Hat:rhel_e4s:9.0::appstream golang-misc
golang-race affected Red Hat:rhel_e4s:9.0::appstream golang-race
golang-src affected Red Hat:rhel_e4s:9.0::appstream golang-src
golang-tests affected Red Hat:rhel_e4s:9.0::appstream golang-tests
Upstream advisory

GHSA-qh8g-58pp-2wxh

GooglePoC exploitMEDIUM2024-10-14

Eclipse Jetty URI parsing of invalid authority

Affected products

ProductStatusVendorPackageEcosystem
org.eclipse.jetty:jetty-http affected Maven org.eclipse.jetty:jetty-http
Upstream advisory

GHSA-qh8g-58pp-2wxh

Open SourcePoC exploitMEDIUM2024-10-14

Eclipse Jetty URI parsing of invalid authority

Affected products

ProductStatusVendorPackageEcosystem
akhq affected wolfi akhq
akhq affected chainguard akhq
apache-nifi affected chainguard apache-nifi
apache-nifi affected wolfi apache-nifi
apache-pulsar affected chainguard apache-pulsar
apache-pulsar affected wolfi apache-pulsar
apache-pulsar-4.0 affected chainguard apache-pulsar-4.0
apache-pulsar-fips-4.0 affected chainguard apache-pulsar-fips-4.0
apache-tika-3.0 affected chainguard apache-tika-3.0
apache-tika-3.1 affected wolfi apache-tika-3.1
apache-tika-3.1 affected chainguard apache-tika-3.1
apache-tika-3.2 affected wolfi apache-tika-3.2
apache-tika-3.2 affected chainguard apache-tika-3.2
apache-tika-3.3 affected chainguard apache-tika-3.3
apache-tika-3.3 affected wolfi apache-tika-3.3
apache-tika-fips-3.0 affected chainguard apache-tika-fips-3.0
apache-tika-fips-3.1 affected chainguard apache-tika-fips-3.1
apache-tika-fips-3.2 affected chainguard apache-tika-fips-3.2
apache-tika-fips-3.3 affected chainguard apache-tika-fips-3.3
cassandra-reaper affected wolfi cassandra-reaper
cassandra-reaper affected chainguard cassandra-reaper
celeborn-0.5 affected chainguard celeborn-0.5
clojure affected chainguard clojure
clojure-tools affected chainguard clojure-tools
cloudwatch-exporter affected wolfi cloudwatch-exporter
cloudwatch-exporter affected chainguard cloudwatch-exporter
confluent-kafka affected chainguard confluent-kafka
confluent-kafka affected wolfi confluent-kafka
confluent-kafka-jre-bcfips affected chainguard confluent-kafka-jre-bcfips
cruise-control affected chainguard cruise-control
cruise-control-fips affected chainguard cruise-control-fips
druid affected chainguard druid
druid affected wolfi druid
hadoop-client-modules affected chainguard hadoop-client-modules
kafka-jre-bcfips affected chainguard kafka-jre-bcfips
kayenta-fips-2026.2 affected chainguard kayenta-fips-2026.2
neo4j-5.26 affected chainguard neo4j-5.26
neo4j-5.26 affected wolfi neo4j-5.26
org.eclipse.jetty:jetty-http affected Maven org.eclipse.jetty:jetty-http
pinot affected chainguard pinot
pinot-fips affected chainguard pinot-fips
reposilite affected chainguard reposilite
solr affected chainguard solr
solr affected wolfi solr
spark-3.5 affected chainguard spark-3.5
spark-4.0 affected chainguard spark-4.0
spark-4.0 affected wolfi spark-4.0
spark-4.1 affected wolfi spark-4.1
spark-4.1 affected chainguard spark-4.1
spark-fips-3.5 affected chainguard spark-fips-3.5
spark-kubernetes-operator affected chainguard spark-kubernetes-operator
spark-kubernetes-operator-fips affected chainguard spark-kubernetes-operator-fips
strimzi-kafka-operator-fips affected chainguard strimzi-kafka-operator-fips
trino affected chainguard trino
trino affected wolfi trino
wso2is affected chainguard wso2is
zaproxy affected chainguard zaproxy
zookeeper-3.8 affected chainguard zookeeper-3.8
zookeeper-3.9 affected wolfi zookeeper-3.9
zookeeper-3.9 affected chainguard zookeeper-3.9
zookeeper-fips-3.8 affected chainguard zookeeper-fips-3.8
zookeeper-fips-3.9 affected chainguard zookeeper-fips-3.9
Upstream advisory

GHSA-w2p9-j475-2wp5

Open SourcePoC exploitHIGH2024-10-15

GHSA-w2p9-j475-2wp5

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-9956

GooglePoC exploitHIGH2024-10-15

Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9956

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-9956

GooglePoC exploit2024-10-15

Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9956

Upstream advisory

DEBIAN-CVE-2024-9956

Open SourcePoC exploitHIGH2024-10-15

DEBIAN-CVE-2024-9956

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

RLSA-2024:7550

Open SourcePoC exploit2024-10-25

Moderate: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Rocky Linux:9 golang
Upstream advisory

RLSA-2024:7502

Open SourcePoC exploit2024-10-25

Moderate: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

RHSA-2024:7502

Open SourcePoC exploitMEDIUM2024-10-22

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

GO-2024-3167

Open SourcePoC exploitCRITICAL2024-10-09

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability in github.com/golang-fips/openssl

Affected products

ProductStatusVendorPackageEcosystem
golang-fips/openssl affected github.com github.com/golang-fips/openssl
Upstream advisory

RHSA-2024:7550

Open SourcePoC exploitMEDIUM2024-10-03

Red Hat Security Advisory: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:9::appstream golang
golang-bin affected Red Hat:enterprise_linux:9::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:9::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:9::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:9::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:9::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:9::appstream go-toolset
Upstream advisory

ALSA-2024:7502

Open SourcePoC exploit2024-10-02

Moderate: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected AlmaLinux:8 delve
golang affected AlmaLinux:8 golang
golang-bin affected AlmaLinux:8 golang-bin
golang-docs affected AlmaLinux:8 golang-docs
golang-misc affected AlmaLinux:8 golang-misc
golang-src affected AlmaLinux:8 golang-src
golang-tests affected AlmaLinux:8 golang-tests
go-toolset affected AlmaLinux:8 go-toolset
go-toolset affected AlmaLinux
Upstream advisory

ALSA-2024:7550

Open SourcePoC exploit2024-10-02

Moderate: golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected AlmaLinux:9 golang
golang-bin affected AlmaLinux:9 golang-bin
golang-docs affected AlmaLinux:9 golang-docs
golang-misc affected AlmaLinux:9 golang-misc
golang-src affected AlmaLinux:9 golang-src
golang-tests affected AlmaLinux:9 golang-tests
go-toolset affected AlmaLinux:9 go-toolset
Upstream advisory

GHSA-3h3x-2hwv-hr52

Open SourcePoC exploitCRITICAL2024-10-01

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang-fips/openssl affected github.com
golang-fips/openssl affected github.com github.com/golang-fips/openssl
Upstream advisory

GHSA-3h3x-2hwv-hr52

Open SourcePoC exploitCRITICAL2024-10-01

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang-fips/openssl affected github.com github.com/golang-fips/openssl
Upstream advisory

AZL-52774

Open SourcePoC exploitCRITICAL2024-10-01

CVE-2024-9355 affecting package golang for versions less than 1.22.9-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2024-9355

Open SourcePoC exploitHIGH2024-10-01

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVEs:CVE-2024-9355

Affected products

ProductStatusVendorPackageEcosystem
golang-fips/openssl affected github.com github.com/golang-fips/openssl
Upstream advisory

CVE-2024-9355

Open SourcePoC exploitCRITICAL2024-06-05

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match betw...

CVEs:CVE-2024-9355

Affected products

ProductStatusVendorPackageEcosystem
golang-fips/openssl affected github.com
Upstream advisory

CVE-2024-9355

Open SourcePoC exploitHIGH2024-06-05

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVEs:CVE-2024-9355

Affected products

ProductStatusVendorPackageEcosystem
golang-fips/openssl affected github.com github.com/golang-fips/openssl
Upstream advisory

GHSA-gj3r-7jjv-636h

Open SourceCoalition ESS 30-63%CRITICAL2024-10-15

GHSA-gj3r-7jjv-636h

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-9955

GoogleCoalition ESS 30-63%2024-10-15

Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9955

Upstream advisory

CVE-2024-9955

GoogleCoalition ESS 30-63%CRITICAL2024-10-15

Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9955

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-9955

Open SourceCoalition ESS 30-63%CRITICAL2024-10-15

DEBIAN-CVE-2024-9955

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2024:0335-1

Open SourceCoalition ESS 30-63%2024-10-14

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP5 chromium
chromium affected SUSE:Package Hub 15 SP6 chromium
chromium affected openSUSE:Leap 15.5 chromium
chromium affected openSUSE:Leap 15.6 chromium
Upstream advisory

DSA-5787-1

Open SourceCoalition ESS 30-63%2024-10-09

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

GHSA-h72p-7xmw-gpp8

Open SourceCoalition ESS 30-63%CRITICAL2024-10-30

GHSA-h72p-7xmw-gpp8

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-10487

GoogleCoalition ESS 30-63%CRITICAL2024-10-29

Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2024-10487

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-10487

GoogleCoalition ESS 30-63%2024-10-29

Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2024-10487

Upstream advisory

DEBIAN-CVE-2024-10487

Open SourceCoalition ESS 30-63%CRITICAL2024-10-29

DEBIAN-CVE-2024-10487

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-92m3-m5pw-p2x9

Open SourceCoalition ESS 30-63%HIGH2024-10-09

GHSA-92m3-m5pw-p2x9

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-9603

Open SourceCoalition ESS 30-63%HIGH2024-10-08

DEBIAN-CVE-2024-9603

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-9603

GoogleCoalition ESS 30-63%2024-10-08

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-9603

Upstream advisory

CVE-2024-9603

GoogleCoalition ESS 30-63%HIGH2024-10-08

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-9603

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-q8jf-j34w-q74g

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

GHSA-q8jf-j34w-q74g

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-9954

GoogleCoalition ESS < 30%CRITICAL2024-10-15

Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-9954

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-9954

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

DEBIAN-CVE-2024-9954

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

RHSA-2022:4798

GoogleCoalition ESS < 30%CRITICAL2024-10-22

Red Hat Security Advisory: maven:3.5 security update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected Red Hat:rhel_eus:8.4::appstream aopalliance
aopalliance affected Red Hat:enterprise_linux:8::appstream aopalliance
aopalliance affected Red Hat:rhel_eus:8.2::appstream aopalliance
apache-commons-cli affected Red Hat:rhel_eus:8.2::appstream apache-commons-cli
apache-commons-cli affected Red Hat:enterprise_linux:8::appstream apache-commons-cli
apache-commons-cli affected Red Hat:rhel_eus:8.4::appstream apache-commons-cli
apache-commons-codec affected Red Hat:rhel_eus:8.2::appstream apache-commons-codec
apache-commons-codec affected Red Hat:rhel_eus:8.4::appstream apache-commons-codec
apache-commons-codec affected Red Hat:enterprise_linux:8::appstream apache-commons-codec
apache-commons-io affected Red Hat:enterprise_linux:8::appstream apache-commons-io
apache-commons-io affected Red Hat:rhel_eus:8.4::appstream apache-commons-io
apache-commons-io affected Red Hat:rhel_eus:8.2::appstream apache-commons-io
apache-commons-lang3 affected Red Hat:enterprise_linux:8::appstream apache-commons-lang3
apache-commons-lang3 affected Red Hat:rhel_eus:8.2::appstream apache-commons-lang3
apache-commons-lang3 affected Red Hat:rhel_eus:8.4::appstream apache-commons-lang3
apache-commons-logging affected Red Hat:enterprise_linux:8::appstream apache-commons-logging
apache-commons-logging affected Red Hat:rhel_eus:8.2::appstream apache-commons-logging
apache-commons-logging affected Red Hat:rhel_eus:8.4::appstream apache-commons-logging
atinject affected Red Hat:rhel_eus:8.2::appstream atinject
atinject affected Red Hat:enterprise_linux:8::appstream atinject
atinject affected Red Hat:rhel_eus:8.4::appstream atinject
cdi-api affected Red Hat:rhel_eus:8.2::appstream cdi-api
cdi-api affected Red Hat:rhel_eus:8.4::appstream cdi-api
cdi-api affected Red Hat:enterprise_linux:8::appstream cdi-api
geronimo-annotation affected Red Hat:enterprise_linux:8::appstream geronimo-annotation
geronimo-annotation affected Red Hat:rhel_eus:8.2::appstream geronimo-annotation
geronimo-annotation affected Red Hat:rhel_eus:8.4::appstream geronimo-annotation
glassfish-el affected Red Hat:enterprise_linux:8::appstream glassfish-el
glassfish-el affected Red Hat:rhel_eus:8.2::appstream glassfish-el
glassfish-el affected Red Hat:rhel_eus:8.4::appstream glassfish-el
glassfish-el-api affected Red Hat:enterprise_linux:8::appstream glassfish-el-api
glassfish-el-api affected Red Hat:rhel_eus:8.4::appstream glassfish-el-api
glassfish-el-api affected Red Hat:rhel_eus:8.2::appstream glassfish-el-api
google-guice affected Red Hat:rhel_eus:8.4::appstream google-guice
google-guice affected Red Hat:enterprise_linux:8::appstream google-guice
google-guice affected Red Hat:rhel_eus:8.2::appstream google-guice
guava20 affected Red Hat:rhel_eus:8.4::appstream guava20
guava20 affected Red Hat:rhel_eus:8.2::appstream guava20
guava20 affected Red Hat:enterprise_linux:8::appstream guava20
hawtjni affected Red Hat:rhel_eus:8.2::appstream hawtjni
hawtjni affected Red Hat:rhel_eus:8.4::appstream hawtjni
hawtjni affected Red Hat:enterprise_linux:8::appstream hawtjni
hawtjni-runtime affected Red Hat:enterprise_linux:8::appstream hawtjni-runtime
hawtjni-runtime affected Red Hat:rhel_eus:8.4::appstream hawtjni-runtime
hawtjni-runtime affected Red Hat:rhel_eus:8.2::appstream hawtjni-runtime
httpcomponents-client affected Red Hat:rhel_eus:8.2::appstream httpcomponents-client
httpcomponents-client affected Red Hat:rhel_eus:8.4::appstream httpcomponents-client
httpcomponents-client affected Red Hat:enterprise_linux:8::appstream httpcomponents-client
httpcomponents-core affected Red Hat:rhel_eus:8.2::appstream httpcomponents-core
httpcomponents-core affected Red Hat:rhel_eus:8.4::appstream httpcomponents-core
httpcomponents-core affected Red Hat:enterprise_linux:8::appstream httpcomponents-core
jansi affected Red Hat:enterprise_linux:8::appstream jansi
jansi affected Red Hat:rhel_eus:8.2::appstream jansi
jansi affected Red Hat:rhel_eus:8.4::appstream jansi
jansi-native affected Red Hat:rhel_eus:8.4::appstream jansi-native
jansi-native affected Red Hat:rhel_eus:8.2::appstream jansi-native
jansi-native affected Red Hat:enterprise_linux:8::appstream jansi-native
jboss-interceptors-1.2-api affected Red Hat:rhel_eus:8.4::appstream jboss-interceptors-1.2-api
jboss-interceptors-1.2-api affected Red Hat:rhel_eus:8.2::appstream jboss-interceptors-1.2-api
jboss-interceptors-1.2-api affected Red Hat:enterprise_linux:8::appstream jboss-interceptors-1.2-api
jcl-over-slf4j affected Red Hat:enterprise_linux:8::appstream jcl-over-slf4j
jcl-over-slf4j affected Red Hat:rhel_eus:8.4::appstream jcl-over-slf4j
jcl-over-slf4j affected Red Hat:rhel_eus:8.2::appstream jcl-over-slf4j
jsoup affected Red Hat:rhel_eus:8.2::appstream jsoup
jsoup affected Red Hat:rhel_eus:8.4::appstream jsoup
jsoup affected Red Hat:enterprise_linux:8::appstream jsoup
maven affected Red Hat:rhel_eus:8.2::appstream maven
maven affected Red Hat:enterprise_linux:8::appstream maven
maven affected Red Hat:rhel_eus:8.4::appstream maven
maven-lib affected Red Hat:rhel_eus:8.2::appstream maven-lib
maven-lib affected Red Hat:rhel_eus:8.4::appstream maven-lib
maven-lib affected Red Hat:enterprise_linux:8::appstream maven-lib
maven-resolver affected Red Hat:rhel_eus:8.2::appstream maven-resolver
maven-resolver affected Red Hat:rhel_eus:8.4::appstream maven-resolver
maven-resolver affected Red Hat:enterprise_linux:8::appstream maven-resolver
maven-resolver-api affected Red Hat:enterprise_linux:8::appstream maven-resolver-api
maven-resolver-api affected Red Hat:rhel_eus:8.4::appstream maven-resolver-api
maven-resolver-api affected Red Hat:rhel_eus:8.2::appstream maven-resolver-api
maven-resolver-connector-basic affected Red Hat:rhel_eus:8.4::appstream maven-resolver-connector-basic
maven-resolver-connector-basic affected Red Hat:rhel_eus:8.2::appstream maven-resolver-connector-basic
maven-resolver-connector-basic affected Red Hat:enterprise_linux:8::appstream maven-resolver-connector-basic
maven-resolver-impl affected Red Hat:rhel_eus:8.2::appstream maven-resolver-impl
maven-resolver-impl affected Red Hat:rhel_eus:8.4::appstream maven-resolver-impl
maven-resolver-impl affected Red Hat:enterprise_linux:8::appstream maven-resolver-impl
maven-resolver-spi affected Red Hat:enterprise_linux:8::appstream maven-resolver-spi
maven-resolver-spi affected Red Hat:rhel_eus:8.2::appstream maven-resolver-spi
maven-resolver-spi affected Red Hat:rhel_eus:8.4::appstream maven-resolver-spi
maven-resolver-transport-wagon affected Red Hat:enterprise_linux:8::appstream maven-resolver-transport-wagon
maven-resolver-transport-wagon affected Red Hat:rhel_eus:8.2::appstream maven-resolver-transport-wagon
maven-resolver-transport-wagon affected Red Hat:rhel_eus:8.4::appstream maven-resolver-transport-wagon
maven-resolver-util affected Red Hat:rhel_eus:8.2::appstream maven-resolver-util
maven-resolver-util affected Red Hat:enterprise_linux:8::appstream maven-resolver-util
maven-resolver-util affected Red Hat:rhel_eus:8.4::appstream maven-resolver-util
maven-shared-utils affected Red Hat:rhel_eus:8.4::appstream maven-shared-utils
maven-shared-utils affected Red Hat:rhel_eus:8.2::appstream maven-shared-utils
maven-shared-utils affected Red Hat:enterprise_linux:8::appstream maven-shared-utils
maven-wagon affected Red Hat:rhel_eus:8.2::appstream maven-wagon
maven-wagon affected Red Hat:rhel_eus:8.4::appstream maven-wagon
maven-wagon affected Red Hat:enterprise_linux:8::appstream maven-wagon
maven-wagon-file affected Red Hat:rhel_eus:8.2::appstream maven-wagon-file
maven-wagon-file affected Red Hat:rhel_eus:8.4::appstream maven-wagon-file
maven-wagon-file affected Red Hat:enterprise_linux:8::appstream maven-wagon-file
maven-wagon-http affected Red Hat:rhel_eus:8.4::appstream maven-wagon-http
maven-wagon-http affected Red Hat:enterprise_linux:8::appstream maven-wagon-http
maven-wagon-http affected Red Hat:rhel_eus:8.2::appstream maven-wagon-http
maven-wagon-http-shared affected Red Hat:rhel_eus:8.4::appstream maven-wagon-http-shared
maven-wagon-http-shared affected Red Hat:rhel_eus:8.2::appstream maven-wagon-http-shared
maven-wagon-http-shared affected Red Hat:enterprise_linux:8::appstream maven-wagon-http-shared
maven-wagon-provider-api affected Red Hat:rhel_eus:8.2::appstream maven-wagon-provider-api
maven-wagon-provider-api affected Red Hat:rhel_eus:8.4::appstream maven-wagon-provider-api
maven-wagon-provider-api affected Red Hat:enterprise_linux:8::appstream maven-wagon-provider-api
plexus-cipher affected Red Hat:rhel_eus:8.2::appstream plexus-cipher
plexus-cipher affected Red Hat:enterprise_linux:8::appstream plexus-cipher
plexus-cipher affected Red Hat:rhel_eus:8.4::appstream plexus-cipher
plexus-classworlds affected Red Hat:rhel_eus:8.4::appstream plexus-classworlds
plexus-classworlds affected Red Hat:enterprise_linux:8::appstream plexus-classworlds
plexus-classworlds affected Red Hat:rhel_eus:8.2::appstream plexus-classworlds
plexus-containers affected Red Hat:rhel_eus:8.4::appstream plexus-containers
plexus-containers affected Red Hat:enterprise_linux:8::appstream plexus-containers
plexus-containers affected Red Hat:rhel_eus:8.2::appstream plexus-containers
plexus-containers-component-annotations affected Red Hat:rhel_eus:8.2::appstream plexus-containers-component-annotations
plexus-containers-component-annotations affected Red Hat:enterprise_linux:8::appstream plexus-containers-component-annotations
plexus-containers-component-annotations affected Red Hat:rhel_eus:8.4::appstream plexus-containers-component-annotations
plexus-interpolation affected Red Hat:enterprise_linux:8::appstream plexus-interpolation
plexus-interpolation affected Red Hat:rhel_eus:8.4::appstream plexus-interpolation
plexus-interpolation affected Red Hat:rhel_eus:8.2::appstream plexus-interpolation
plexus-sec-dispatcher affected Red Hat:rhel_eus:8.2::appstream plexus-sec-dispatcher
plexus-sec-dispatcher affected Red Hat:enterprise_linux:8::appstream plexus-sec-dispatcher
plexus-sec-dispatcher affected Red Hat:rhel_eus:8.4::appstream plexus-sec-dispatcher
plexus-utils affected Red Hat:rhel_eus:8.4::appstream plexus-utils
plexus-utils affected Red Hat:rhel_eus:8.2::appstream plexus-utils
plexus-utils affected Red Hat:enterprise_linux:8::appstream plexus-utils
sisu affected Red Hat:rhel_eus:8.4::appstream sisu
sisu affected Red Hat:rhel_eus:8.2::appstream sisu
sisu affected Red Hat:enterprise_linux:8::appstream sisu
sisu-inject affected Red Hat:rhel_eus:8.4::appstream sisu-inject
sisu-inject affected Red Hat:rhel_eus:8.2::appstream sisu-inject
sisu-inject affected Red Hat:enterprise_linux:8::appstream sisu-inject
sisu-plexus affected Red Hat:rhel_eus:8.2::appstream sisu-plexus
sisu-plexus affected Red Hat:enterprise_linux:8::appstream sisu-plexus
sisu-plexus affected Red Hat:rhel_eus:8.4::appstream sisu-plexus
slf4j affected Red Hat:enterprise_linux:8::appstream slf4j
slf4j affected Red Hat:rhel_eus:8.4::appstream slf4j
slf4j affected Red Hat:rhel_eus:8.2::appstream slf4j
Upstream advisory

RHSA-2022:4797

GoogleCoalition ESS < 30%CRITICAL2024-10-22

Red Hat Security Advisory: maven:3.6 security update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected Red Hat:enterprise_linux:8::appstream aopalliance
aopalliance affected Red Hat:rhel_eus:8.2::appstream aopalliance
aopalliance affected Red Hat:rhel_eus:8.4::appstream aopalliance
apache-commons-cli affected Red Hat:rhel_eus:8.4::appstream apache-commons-cli
apache-commons-cli affected Red Hat:rhel_eus:8.2::appstream apache-commons-cli
apache-commons-cli affected Red Hat:enterprise_linux:8::appstream apache-commons-cli
apache-commons-codec affected Red Hat:rhel_eus:8.4::appstream apache-commons-codec
apache-commons-codec affected Red Hat:rhel_eus:8.2::appstream apache-commons-codec
apache-commons-codec affected Red Hat:enterprise_linux:8::appstream apache-commons-codec
apache-commons-io affected Red Hat:enterprise_linux:8::appstream apache-commons-io
apache-commons-io affected Red Hat:rhel_eus:8.4::appstream apache-commons-io
apache-commons-io affected Red Hat:rhel_eus:8.2::appstream apache-commons-io
apache-commons-lang3 affected Red Hat:rhel_eus:8.4::appstream apache-commons-lang3
apache-commons-lang3 affected Red Hat:rhel_eus:8.2::appstream apache-commons-lang3
apache-commons-lang3 affected Red Hat:enterprise_linux:8::appstream apache-commons-lang3
atinject affected Red Hat:rhel_eus:8.4::appstream atinject
atinject affected Red Hat:rhel_eus:8.2::appstream atinject
atinject affected Red Hat:enterprise_linux:8::appstream atinject
cdi-api affected Red Hat:enterprise_linux:8::appstream cdi-api
cdi-api affected Red Hat:rhel_eus:8.2::appstream cdi-api
cdi-api affected Red Hat:rhel_eus:8.4::appstream cdi-api
geronimo-annotation affected Red Hat:rhel_eus:8.4::appstream geronimo-annotation
geronimo-annotation affected Red Hat:rhel_eus:8.2::appstream geronimo-annotation
geronimo-annotation affected Red Hat:enterprise_linux:8::appstream geronimo-annotation
google-guice affected Red Hat:rhel_eus:8.2::appstream google-guice
google-guice affected Red Hat:enterprise_linux:8::appstream google-guice
google-guice affected Red Hat:rhel_eus:8.4::appstream google-guice
guava affected Red Hat:rhel_eus:8.2::appstream guava
guava affected Red Hat:rhel_eus:8.4::appstream guava
guava affected Red Hat:enterprise_linux:8::appstream guava
httpcomponents-client affected Red Hat:rhel_eus:8.2::appstream httpcomponents-client
httpcomponents-client affected Red Hat:enterprise_linux:8::appstream httpcomponents-client
httpcomponents-client affected Red Hat:rhel_eus:8.4::appstream httpcomponents-client
httpcomponents-core affected Red Hat:enterprise_linux:8::appstream httpcomponents-core
httpcomponents-core affected Red Hat:rhel_eus:8.4::appstream httpcomponents-core
httpcomponents-core affected Red Hat:rhel_eus:8.2::appstream httpcomponents-core
jansi affected Red Hat:rhel_eus:8.4::appstream jansi
jansi affected Red Hat:rhel_eus:8.2::appstream jansi
jansi affected Red Hat:enterprise_linux:8::appstream jansi
jcl-over-slf4j affected Red Hat:enterprise_linux:8::appstream jcl-over-slf4j
jcl-over-slf4j affected Red Hat:rhel_eus:8.2::appstream jcl-over-slf4j
jcl-over-slf4j affected Red Hat:rhel_eus:8.4::appstream jcl-over-slf4j
jsoup affected Red Hat:enterprise_linux:8::appstream jsoup
jsoup affected Red Hat:rhel_eus:8.4::appstream jsoup
jsoup affected Red Hat:rhel_eus:8.2::appstream jsoup
jsr-305 affected Red Hat:rhel_eus:8.4::appstream jsr-305
jsr-305 affected Red Hat:enterprise_linux:8::appstream jsr-305
jsr-305 affected Red Hat:rhel_eus:8.2::appstream jsr-305
maven affected Red Hat:enterprise_linux:8::appstream maven
maven affected Red Hat:rhel_eus:8.4::appstream maven
maven affected Red Hat:rhel_eus:8.2::appstream maven
maven-lib affected Red Hat:enterprise_linux:8::appstream maven-lib
maven-lib affected Red Hat:rhel_eus:8.2::appstream maven-lib
maven-lib affected Red Hat:rhel_eus:8.4::appstream maven-lib
maven-openjdk11 affected Red Hat:enterprise_linux:8::appstream maven-openjdk11
maven-openjdk11 affected Red Hat:rhel_eus:8.2::appstream maven-openjdk11
maven-openjdk11 affected Red Hat:rhel_eus:8.4::appstream maven-openjdk11
maven-openjdk17 affected Red Hat:enterprise_linux:8::appstream maven-openjdk17
maven-openjdk8 affected Red Hat:enterprise_linux:8::appstream maven-openjdk8
maven-openjdk8 affected Red Hat:rhel_eus:8.2::appstream maven-openjdk8
maven-openjdk8 affected Red Hat:rhel_eus:8.4::appstream maven-openjdk8
maven-resolver affected Red Hat:rhel_eus:8.2::appstream maven-resolver
maven-resolver affected Red Hat:rhel_eus:8.4::appstream maven-resolver
maven-resolver affected Red Hat:enterprise_linux:8::appstream maven-resolver
maven-shared-utils affected Red Hat:rhel_eus:8.4::appstream maven-shared-utils
maven-shared-utils affected Red Hat:rhel_eus:8.2::appstream maven-shared-utils
maven-shared-utils affected Red Hat:enterprise_linux:8::appstream maven-shared-utils
maven-wagon affected Red Hat:rhel_eus:8.4::appstream maven-wagon
maven-wagon affected Red Hat:enterprise_linux:8::appstream maven-wagon
maven-wagon affected Red Hat:rhel_eus:8.2::appstream maven-wagon
plexus-cipher affected Red Hat:enterprise_linux:8::appstream plexus-cipher
plexus-cipher affected Red Hat:rhel_eus:8.4::appstream plexus-cipher
plexus-cipher affected Red Hat:rhel_eus:8.2::appstream plexus-cipher
plexus-classworlds affected Red Hat:rhel_eus:8.2::appstream plexus-classworlds
plexus-classworlds affected Red Hat:enterprise_linux:8::appstream plexus-classworlds
plexus-classworlds affected Red Hat:rhel_eus:8.4::appstream plexus-classworlds
plexus-containers affected Red Hat:enterprise_linux:8::appstream plexus-containers
plexus-containers affected Red Hat:rhel_eus:8.4::appstream plexus-containers
plexus-containers affected Red Hat:rhel_eus:8.2::appstream plexus-containers
plexus-containers-component-annotations affected Red Hat:rhel_eus:8.2::appstream plexus-containers-component-annotations
plexus-containers-component-annotations affected Red Hat:rhel_eus:8.4::appstream plexus-containers-component-annotations
plexus-containers-component-annotations affected Red Hat:enterprise_linux:8::appstream plexus-containers-component-annotations
plexus-interpolation affected Red Hat:rhel_eus:8.4::appstream plexus-interpolation
plexus-interpolation affected Red Hat:enterprise_linux:8::appstream plexus-interpolation
plexus-interpolation affected Red Hat:rhel_eus:8.2::appstream plexus-interpolation
plexus-sec-dispatcher affected Red Hat:enterprise_linux:8::appstream plexus-sec-dispatcher
plexus-sec-dispatcher affected Red Hat:rhel_eus:8.4::appstream plexus-sec-dispatcher
plexus-sec-dispatcher affected Red Hat:rhel_eus:8.2::appstream plexus-sec-dispatcher
plexus-utils affected Red Hat:rhel_eus:8.2::appstream plexus-utils
plexus-utils affected Red Hat:rhel_eus:8.4::appstream plexus-utils
plexus-utils affected Red Hat:enterprise_linux:8::appstream plexus-utils
sisu affected Red Hat:rhel_eus:8.2::appstream sisu
sisu affected Red Hat:rhel_eus:8.4::appstream sisu
sisu affected Red Hat:enterprise_linux:8::appstream sisu
slf4j affected Red Hat:rhel_eus:8.4::appstream slf4j
slf4j affected Red Hat:enterprise_linux:8::appstream slf4j
slf4j affected Red Hat:rhel_eus:8.2::appstream slf4j
Upstream advisory

RHSA-2022:4699

GoogleCoalition ESS < 30%CRITICAL2024-10-22

Red Hat Security Advisory: maven:3.5 security update

Affected products

ProductStatusVendorPackageEcosystem
aopalliance affected Red Hat:rhel_e4s:8.1::appstream aopalliance
apache-commons-cli affected Red Hat:rhel_e4s:8.1::appstream apache-commons-cli
apache-commons-codec affected Red Hat:rhel_e4s:8.1::appstream apache-commons-codec
apache-commons-io affected Red Hat:rhel_e4s:8.1::appstream apache-commons-io
apache-commons-lang3 affected Red Hat:rhel_e4s:8.1::appstream apache-commons-lang3
apache-commons-logging affected Red Hat:rhel_e4s:8.1::appstream apache-commons-logging
atinject affected Red Hat:rhel_e4s:8.1::appstream atinject
cdi-api affected Red Hat:rhel_e4s:8.1::appstream cdi-api
geronimo-annotation affected Red Hat:rhel_e4s:8.1::appstream geronimo-annotation
glassfish-el affected Red Hat:rhel_e4s:8.1::appstream glassfish-el
glassfish-el-api affected Red Hat:rhel_e4s:8.1::appstream glassfish-el-api
google-guice affected Red Hat:rhel_e4s:8.1::appstream google-guice
guava20 affected Red Hat:rhel_e4s:8.1::appstream guava20
hawtjni affected Red Hat:rhel_e4s:8.1::appstream hawtjni
hawtjni-runtime affected Red Hat:rhel_e4s:8.1::appstream hawtjni-runtime
httpcomponents-client affected Red Hat:rhel_e4s:8.1::appstream httpcomponents-client
httpcomponents-core affected Red Hat:rhel_e4s:8.1::appstream httpcomponents-core
jansi affected Red Hat:rhel_e4s:8.1::appstream jansi
jansi-native affected Red Hat:rhel_e4s:8.1::appstream jansi-native
jboss-interceptors-1.2-api affected Red Hat:rhel_e4s:8.1::appstream jboss-interceptors-1.2-api
jcl-over-slf4j affected Red Hat:rhel_e4s:8.1::appstream jcl-over-slf4j
jsoup affected Red Hat:rhel_e4s:8.1::appstream jsoup
maven affected Red Hat:rhel_e4s:8.1::appstream maven
maven-lib affected Red Hat:rhel_e4s:8.1::appstream maven-lib
maven-resolver affected Red Hat:rhel_e4s:8.1::appstream maven-resolver
maven-resolver-api affected Red Hat:rhel_e4s:8.1::appstream maven-resolver-api
maven-resolver-connector-basic affected Red Hat:rhel_e4s:8.1::appstream maven-resolver-connector-basic
maven-resolver-impl affected Red Hat:rhel_e4s:8.1::appstream maven-resolver-impl
maven-resolver-spi affected Red Hat:rhel_e4s:8.1::appstream maven-resolver-spi
maven-resolver-transport-wagon affected Red Hat:rhel_e4s:8.1::appstream maven-resolver-transport-wagon
maven-resolver-util affected Red Hat:rhel_e4s:8.1::appstream maven-resolver-util
maven-shared-utils affected Red Hat:rhel_e4s:8.1::appstream maven-shared-utils
maven-wagon affected Red Hat:rhel_e4s:8.1::appstream maven-wagon
maven-wagon-file affected Red Hat:rhel_e4s:8.1::appstream maven-wagon-file
maven-wagon-http affected Red Hat:rhel_e4s:8.1::appstream maven-wagon-http
maven-wagon-http-shared affected Red Hat:rhel_e4s:8.1::appstream maven-wagon-http-shared
maven-wagon-provider-api affected Red Hat:rhel_e4s:8.1::appstream maven-wagon-provider-api
plexus-cipher affected Red Hat:rhel_e4s:8.1::appstream plexus-cipher
plexus-classworlds affected Red Hat:rhel_e4s:8.1::appstream plexus-classworlds
plexus-containers affected Red Hat:rhel_e4s:8.1::appstream plexus-containers
plexus-containers-component-annotations affected Red Hat:rhel_e4s:8.1::appstream plexus-containers-component-annotations
plexus-interpolation affected Red Hat:rhel_e4s:8.1::appstream plexus-interpolation
plexus-sec-dispatcher affected Red Hat:rhel_e4s:8.1::appstream plexus-sec-dispatcher
plexus-utils affected Red Hat:rhel_e4s:8.1::appstream plexus-utils
sisu affected Red Hat:rhel_e4s:8.1::appstream sisu
sisu-inject affected Red Hat:rhel_e4s:8.1::appstream sisu-inject
sisu-plexus affected Red Hat:rhel_e4s:8.1::appstream sisu-plexus
slf4j affected Red Hat:rhel_e4s:8.1::appstream slf4j
Upstream advisory

RHSA-2024:1472

Open SourceCoalition ESS < 30%HIGH2024-10-21

Red Hat Security Advisory: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:8::appstream delve
delve-debuginfo affected Red Hat:enterprise_linux:8::appstream delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:8::appstream delve-debugsource
golang affected Red Hat:enterprise_linux:8::appstream golang
golang-bin affected Red Hat:enterprise_linux:8::appstream golang-bin
golang-docs affected Red Hat:enterprise_linux:8::appstream golang-docs
golang-misc affected Red Hat:enterprise_linux:8::appstream golang-misc
golang-src affected Red Hat:enterprise_linux:8::appstream golang-src
golang-tests affected Red Hat:enterprise_linux:8::appstream golang-tests
go-toolset affected Red Hat:enterprise_linux:8::appstream go-toolset
Upstream advisory

CVE-2024-43566

Open SourceCoalition ESS < 30%CRITICAL2024-10-08

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2024-43566

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2024-9341

Open SourceCoalition ESS < 30%HIGH2024-10-01

DEBIAN-CVE-2024-9341

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-common affected Debian:11 golang-github-containers-common
golang-github-containers-common affected Debian:12 golang-github-containers-common
golang-github-containers-common affected Debian:13 golang-github-containers-common
golang-github-containers-common affected Debian:14 golang-github-containers-common
Upstream advisory

CVE-2024-43595

Open SourceCoalition ESS < 30%CRITICAL2024-10-08

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2024-43595

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2024-43596

Open SourceCoalition ESS < 30%CRITICAL2024-10-08

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2024-43596

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2024-43587

Open SourceCoalition ESS < 30%CRITICAL2024-10-08

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2024-43587

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-4v8q-vp3v-vvxh

Open SourceCoalition ESS < 30%HIGH2024-10-09

GHSA-4v8q-vp3v-vvxh

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-9602

Open SourceCoalition ESS < 30%HIGH2024-10-08

DEBIAN-CVE-2024-9602

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-9602

GoogleCoalition ESS < 30%2024-10-08

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-9602

Upstream advisory

CVE-2024-9602

GoogleCoalition ESS < 30%HIGH2024-10-08

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-9602

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-43578

Open SourceCoalition ESS < 30%CRITICAL2024-10-08

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2024-43578

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2024-43579

Open SourceCoalition ESS < 30%CRITICAL2024-10-08

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2024-43579

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2024-9369

GoogleCoalition ESS < 30%2024-10-01

Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-9369

Upstream advisory

CVE-2024-9369

GoogleCoalition ESS < 30%CRITICAL2024-10-01

Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-9369

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-g4gj-m346-585c

Open SourceCoalition ESS < 30%HIGH2024-10-23

GHSA-g4gj-m346-585c

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2024-10230

Open SourceCoalition ESS < 30%HIGH2024-10-22

DEBIAN-CVE-2024-10230

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-10230

GoogleCoalition ESS < 30%HIGH2024-10-22

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-10230

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-10230

GoogleCoalition ESS < 30%2024-10-22

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-10230

Upstream advisory

CVE-2024-9861

Open SourceCoalition ESS < 30%HIGH2024-10-17

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. Th...

CVEs:CVE-2024-9861

Affected products

ProductStatusVendorPackageEcosystem
otp_verification_with_firebase affected miniorange
Upstream advisory

CVE-2024-9862

Open SourceCoalition ESS < 30%CRITICAL2024-10-17

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass aut...

CVEs:CVE-2024-9862

Affected products

ProductStatusVendorPackageEcosystem
otp_verification_with_firebase affected miniorange
Upstream advisory

GHSA-p3wf-f274-7gx2

Open SourceCoalition ESS < 30%CRITICAL2024-10-30

GHSA-p3wf-f274-7gx2

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-10488

GoogleCoalition ESS < 30%CRITICAL2024-10-29

Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-10488

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-10488

GoogleCoalition ESS < 30%2024-10-29

Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-10488

Upstream advisory

DEBIAN-CVE-2024-10488

Open SourceCoalition ESS < 30%CRITICAL2024-10-29

DEBIAN-CVE-2024-10488

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-49023

Open SourceCoalition ESS < 30%CRITICAL2024-10-08

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2024-49023

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2021-4452

GoogleCoalition ESS < 30%HIGH2024-10-16

The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for a...

CVEs:CVE-2021-4452

Affected products

ProductStatusVendorPackageEcosystem
google_language_translator affected gtranslate
Upstream advisory

GHSA-7c7g-86f2-3w2x

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

GHSA-7c7g-86f2-3w2x

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-9965

GoogleCoalition ESS < 30%2024-10-15

Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-9965

Upstream advisory

CVE-2024-9965

GoogleCoalition ESS < 30%CRITICAL2024-10-15

Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity:...

CVEs:CVE-2024-9965

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-9965

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

DEBIAN-CVE-2024-9965

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-j8x2-fpjj-2hvp

Open SourceCoalition ESS < 30%CRITICAL2024-10-11

GHSA-j8x2-fpjj-2hvp

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-9859

GoogleCoalition ESS < 30%CRITICAL2024-10-11

Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-9859

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-9859

GoogleCoalition ESS < 30%2024-10-11

Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2024-9859

Upstream advisory

DEBIAN-CVE-2024-9859

Open SourceCoalition ESS < 30%CRITICAL2024-10-11

DEBIAN-CVE-2024-9859

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-3j36-mj45-fgp4

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

GHSA-3j36-mj45-fgp4

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-9960

GoogleCoalition ESS < 30%CRITICAL2024-10-15

Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9960

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-9960

GoogleCoalition ESS < 30%2024-10-15

Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9960

Upstream advisory

DEBIAN-CVE-2024-9960

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

DEBIAN-CVE-2024-9960

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-89v2-8rj2-3464

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

GHSA-89v2-8rj2-3464

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

GHSA-c2h4-jx6m-jp2q

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

GHSA-c2h4-jx6m-jp2q

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-9957

GoogleCoalition ESS < 30%CRITICAL2024-10-15

Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9957

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-9961

GoogleCoalition ESS < 30%CRITICAL2024-10-15

Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity...

CVEs:CVE-2024-9961

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-9957

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

DEBIAN-CVE-2024-9957

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2024-9961

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

DEBIAN-CVE-2024-9961

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-43580

Open SourceCoalition ESS < 30%MEDIUM2024-10-08

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2024-43580

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

GHSA-7ppc-7q95-ccw3

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

GHSA-7ppc-7q95-ccw3

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-9966

GoogleCoalition ESS < 30%MEDIUM2024-10-15

Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2024-9966

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-9966

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

DEBIAN-CVE-2024-9966

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-h5h2-jj79-rjrp

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

GHSA-h5h2-jj79-rjrp

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

CVE-2024-9959

GoogleCoalition ESS < 30%2024-10-15

Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

CVEs:CVE-2024-9959

Upstream advisory

CVE-2024-9959

GoogleCoalition ESS < 30%CRITICAL2024-10-15

Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

CVEs:CVE-2024-9959

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-9959

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

DEBIAN-CVE-2024-9959

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-44101

Open SourceCoalition ESS < 30%HIGH2024-10-15

there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-44101

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-319834067

GoogleCoalition ESS < 30%MEDIUM2024-10-01

PUB-A-319834067

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-9pq2-vmj6-97q4

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

GHSA-9pq2-vmj6-97q4

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

GHSA-f8jx-5r24-p453

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

GHSA-f8jx-5r24-p453

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2024-9958

GoogleCoalition ESS < 30%MEDIUM2024-10-15

Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9958

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2024-9958

GoogleCoalition ESS < 30%2024-10-15

Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9958

Upstream advisory

CVE-2024-9962

GoogleCoalition ESS < 30%2024-10-15

Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9962

Upstream advisory

CVE-2024-9962

GoogleCoalition ESS < 30%MEDIUM2024-10-15

Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9962

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-9958

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

DEBIAN-CVE-2024-9958

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2024-9962

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

DEBIAN-CVE-2024-9962

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-40675

Open SourceCoalition ESS < 30%HIGH2024-10-07

In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-40675

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-j6j9-m952-pp68

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

GHSA-j6j9-m952-pp68

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

CVE-2024-9963

GoogleCoalition ESS < 30%MEDIUM2024-10-15

Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2024-9963

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-9963

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

DEBIAN-CVE-2024-9963

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-8qjp-f639-q7hx

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

GHSA-8qjp-f639-q7hx

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

CVE-2024-9964

GoogleCoalition ESS < 30%MEDIUM2024-10-15

Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)

CVEs:CVE-2024-9964

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2024-9964

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

DEBIAN-CVE-2024-9964

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2024-44100

Open SourceCoalition ESS < 30%HIGH2024-10-15

Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.

CVEs:CVE-2024-44100

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-299774545

GoogleCoalition ESS < 30%2024-10-01

PUB-A-299774545

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47021

Open SourceCoalition ESS < 30%HIGH2024-10-15

In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2024-47021

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-299775134

GoogleCoalition ESS < 30%MEDIUM2024-10-01

PUB-A-299775134

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-8912

GoogleCoalition ESS < 30%HIGH2024-10-11

An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users. There are two Looker versions that are hosted by Looker: * Looker (Google Cloud core) was found to be vulne...

CVEs:CVE-2024-8912

Affected products

ProductStatusVendorPackageEcosystem
cloud_looker affected google
Upstream advisory

CVE-2024-47020

Open SourceCoalition ESS < 30%HIGH2024-10-15

Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.

CVEs:CVE-2024-47020

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47022

Open SourceCoalition ESS < 30%HIGH2024-10-15

Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.

CVEs:CVE-2024-47022

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-331255656

GoogleCoalition ESS < 30%2024-10-01

PUB-A-331255656

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-331966488

GoogleCoalition ESS < 30%2024-10-01

PUB-A-331966488

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47031

Open SourceCoalition ESS < 30%CRITICAL2024-10-15

Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-329163861.

CVEs:CVE-2024-47031

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-329163861

GoogleCoalition ESS < 30%2024-10-01

PUB-A-329163861

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-44098

Open SourceCoalition ESS < 30%HIGH2024-10-15

In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2024-44098

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-323163451

GoogleCoalition ESS < 30%HIGH2024-10-01

PUB-A-323163451

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-47012

Open SourceCoalition ESS < 30%HIGH2024-10-15

In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2024-47012

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-322820753

GoogleCoalition ESS < 30%HIGH2024-10-01

PUB-A-322820753

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-44099

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-44099

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47018

Open SourceCoalition ESS < 30%HIGH2024-10-15

In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2024-47018

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-47019

Open SourceCoalition ESS < 30%MEDIUM2024-10-15

In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is no...

CVEs:CVE-2024-47019

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-322223729

GoogleCoalition ESS < 30%HIGH2024-10-01

PUB-A-322223729

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-325927059

GoogleCoalition ESS < 30%MEDIUM2024-10-01

PUB-A-325927059

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-331666405

GoogleCoalition ESS < 30%MEDIUM2024-10-01

PUB-A-331666405

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-34732

Open SourceCoalition ESS < 30%HIGH2024-10-07

In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2024-34732

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-340332428

GoogleCoalition ESS < 30%HIGH2024-10-01

ASB-A-340332428

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-9858

GoogleCoalition ESS < 30%HIGH2024-10-16

There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" or "generate"...

CVEs:CVE-2024-9858

Affected products

ProductStatusVendorPackageEcosystem
migrate_to_containers affected google
Upstream advisory

GO-2024-3212

Open SourceAll remainingCRITICAL2024-10-28

AWS Load Balancer Controller automatically detaches externally associated web ACL from Application Load Balancers in sigs.k8s.io/aws-load-balancer-controller

Affected products

ProductStatusVendorPackageEcosystem
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller affected sigs.k8s.io sigs.k8s.io/aws-load-balancer-controller
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
Upstream advisory

GHSA-rjfv-pjvx-mjgv

Open SourceAll remainingNONE2024-10-24

AWS Load Balancer Controller automatically detaches externally associated web ACL from Application Load Balancers

Affected products

ProductStatusVendorPackageEcosystem
aws-load-balancer-controller affected wolfi aws-load-balancer-controller
aws-load-balancer-controller affected sigs.k8s.io sigs.k8s.io/aws-load-balancer-controller
aws-load-balancer-controller affected sigs.k8s.io sigs.k8s.io/aws-load-balancer-controller
aws-load-balancer-controller affected chainguard aws-load-balancer-controller
aws-load-balancer-controller-fips affected chainguard aws-load-balancer-controller-fips
Upstream advisory

GHSA-rjfv-pjvx-mjgv

Open SourceAll remainingNONE2024-10-24

AWS Load Balancer Controller automatically detaches externally associated web ACL from Application Load Balancers

Affected products

ProductStatusVendorPackageEcosystem
aws-load-balancer-controller affected sigs.k8s.io sigs.k8s.io/aws-load-balancer-controller
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.