GHSA-vgxq-6rcf-qwrw
angular-base64-upload vulnerable to unauthenticated remote code execution
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-base64-upload | affected | npm | angular-base64-upload | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 16 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
angular-base64-upload vulnerable to unauthenticated remote code execution
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-base64-upload | affected | npm | angular-base64-upload | — |
angular-base64-upload vulnerable to unauthenticated remote code execution
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-base64-upload | affected | npm | angular-base64-upload | — |
angular-base64-upload vulnerable to unauthenticated remote code execution
CVEs:CVE-2024-42640
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-base64-upload | affected | npm | angular-base64-upload | — |
angular-base64-upload vulnerable to unauthenticated remote code execution
CVEs:CVE-2024-42640
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-base64-upload | affected | npm | angular-base64-upload | — |
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through de...
CVEs:CVE-2024-42640
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
CVEs:CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
CVEs:CVE-2024-9680
CVEs:CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ES...
CVEs:CVE-2024-9680
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| firefox | affected | mozilla | — | — |
| thunderbird | affected | mozilla | — | — |
Updated chromium-browser-stable packages fix security vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.
CVEs:CVE-2024-44068
CVEs:CVE-2024-44068
An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.
CVEs:CVE-2024-44068
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| exynos_850_firmware | affected | samsung | — | — |
| exynos_980_firmware | affected | samsung | — | — |
| exynos_9820_firmware | affected | samsung | — | — |
| exynos_9825_firmware | affected | samsung | — | — |
| exynos_990_firmware | affected | samsung | — | — |
| exynos_w920_firmware | affected | samsung | — | — |
Use After Free in DSP Service
CVEs:CVE-2024-43047
Memory corruption while maintaining memory maps of HLOS memory.
CVEs:CVE-2024-43047
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| fastconnect_6700_firmware | affected | qualcomm | — | — |
| fastconnect_6800_firmware | affected | qualcomm | — | — |
| fastconnect_6900_firmware | affected | qualcomm | — | — |
| fastconnect_7800_firmware | affected | qualcomm | — | — |
| qam8295p_firmware | affected | qualcomm | — | — |
| qca6174a_firmware | affected | qualcomm | — | — |
| qca6391_firmware | affected | qualcomm | — | — |
| qca6426_firmware | affected | qualcomm | — | — |
| qca6436_firmware | affected | qualcomm | — | — |
| qca6574au_firmware | affected | qualcomm | — | — |
| qca6584au_firmware | affected | qualcomm | — | — |
| qca6595au_firmware | affected | qualcomm | — | — |
| qca6595_firmware | affected | qualcomm | — | — |
| qca6688aq_firmware | affected | qualcomm | — | — |
| qca6696_firmware | affected | qualcomm | — | — |
| qca6698aq_firmware | affected | qualcomm | — | — |
| qcs410_firmware | affected | qualcomm | — | — |
| qcs610_firmware | affected | qualcomm | — | — |
| qcs6490_firmware | affected | qualcomm | — | — |
| sa4150p_firmware | affected | qualcomm | — | — |
| sa4155p_firmware | affected | qualcomm | — | — |
| sa6145p_firmware | affected | qualcomm | — | — |
| sa6150p_firmware | affected | qualcomm | — | — |
| sa6155p_firmware | affected | qualcomm | — | — |
| sa8145p_firmware | affected | qualcomm | — | — |
| sa8150p_firmware | affected | qualcomm | — | — |
| sa8155p_firmware | affected | qualcomm | — | — |
| sa8195p_firmware | affected | qualcomm | — | — |
| sa8295p_firmware | affected | qualcomm | — | — |
| sd660_firmware | affected | qualcomm | — | — |
| sd865_5g_firmware | affected | qualcomm | — | — |
| sg4150p_firmware | affected | qualcomm | — | — |
| snapdragon_660_mobile_firmware | affected | qualcomm | — | — |
| snapdragon_680_4g_mobile_firmware | affected | qualcomm | — | — |
| snapdragon_685_4g_mobile_firmware | affected | qualcomm | — | — |
| snapdragon_865_5g_mobile_firmware | affected | qualcomm | — | — |
| snapdragon_865\+_5g_mobile_firmware | affected | qualcomm | — | — |
| snapdragon_870_5g_mobile_firmware | affected | qualcomm | — | — |
| snapdragon_888_5g_mobile_firmware | affected | qualcomm | — | — |
| snapdragon_888\+_5g_mobile_firmware | affected | qualcomm | — | — |
| snapdragon_8_gen_1_mobile_firmware | affected | qualcomm | — | — |
| snapdragon_auto_5g_modem-rf_firmware | affected | qualcomm | — | — |
| snapdragon_auto_5g_modem-rf_gen_2_firmware | affected | qualcomm | — | — |
| snapdragon_x55_5g_modem-rf_firmware | affected | qualcomm | — | — |
| snapdragon_xr2_5g_firmware | affected | qualcomm | — | — |
| sw5100_firmware | affected | qualcomm | — | — |
| sw5100p_firmware | affected | qualcomm | — | — |
| sxr2130_firmware | affected | qualcomm | — | — |
| video_collaboration_vc1_platform_firmware | affected | qualcomm | — | — |
| video_collaboration_vc3_platform_firmware | affected | qualcomm | — | — |
| wcd9335_firmware | affected | qualcomm | — | — |
| wcd9341_firmware | affected | qualcomm | — | — |
| wcd9370_firmware | affected | qualcomm | — | — |
| wcd9375_firmware | affected | qualcomm | — | — |
| wcd9380_firmware | affected | qualcomm | — | — |
| wcd9385_firmware | affected | qualcomm | — | — |
| wcn3950_firmware | affected | qualcomm | — | — |
| wcn3980_firmware | affected | qualcomm | — | — |
| wcn3988_firmware | affected | qualcomm | — | — |
| wcn3990_firmware | affected | qualcomm | — | — |
| wsa8810_firmware | affected | qualcomm | — | — |
| wsa8815_firmware | affected | qualcomm | — | — |
| wsa8830_firmware | affected | qualcomm | — | — |
| wsa8835_firmware | affected | qualcomm | — | — |
CVEs:CVE-2024-43047
VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-sigs/image-builder | affected | github.com | github.com/kubernetes-sigs/image-builder | — |
VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-sigs/image-builder | affected | github.com | github.com/kubernetes-sigs/image-builder | — |
VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-sigs/image-builder | affected | github.com | github.com/kubernetes-sigs/image-builder | — |
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, ...
CVEs:CVE-2024-9486
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| image_builder | affected | kubernetes-sigs | — | — |
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.
CVEs:CVE-2024-9486
VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder
CVEs:CVE-2024-9486
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-sigs/image-builder | affected | github.com | github.com/kubernetes-sigs/image-builder | — |
VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-sigs/image-builder | affected | github.com | github.com/kubernetes-sigs/image-builder | — |
VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-sigs/image-builder | affected | github.com | github.com/kubernetes-sigs/image-builder | — |
VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-sigs/image-builder | affected | github.com | github.com/kubernetes-sigs/image-builder | — |
VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder
CVEs:CVE-2024-9594
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes-sigs/image-builder | affected | github.com | github.com/kubernetes-sigs/image-builder | — |
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root acces...
CVEs:CVE-2024-9594
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| image_builder | affected | kubernetes-sigs | — | — |
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. The credentials are disabled at the conclusion of the image build process. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project. Because these images were vulnerable during the image build process, they are affected only if an attacker was able to reach the VM where the image build was happening and used the vulnerability to modify the image at the time the image build was occurring.
CVEs:CVE-2024-9594
REXML ReDoS vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rexml | affected | RubyGems | rexml | — |
REXML ReDoS vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| jruby-9.4 | affected | wolfi | jruby-9.4 | — |
| jruby-9.4 | affected | chainguard | jruby-9.4 | — |
| kube-fluentd-operator | affected | wolfi | kube-fluentd-operator | — |
| kube-fluentd-operator | affected | chainguard | kube-fluentd-operator | — |
| logstash-8 | affected | wolfi | logstash-8 | — |
| logstash-8 | affected | chainguard | logstash-8 | — |
| logstash-jre-bcfips | affected | chainguard | logstash-jre-bcfips | — |
| rexml | affected | RubyGems | rexml | — |
| rexml | affected | RubyGems | — | — |
| ruby-3.1 | affected | wolfi | ruby-3.1 | — |
| ruby-3.1 | affected | chainguard | ruby-3.1 | — |
| ruby3.1-fluentd-kubernetes-daemonset-1.16 | affected | chainguard | ruby3.1-fluentd-kubernetes-daemonset-1.16 | — |
| ruby3.1-fluentd-kubernetes-daemonset-1.17 | affected | chainguard | ruby3.1-fluentd-kubernetes-daemonset-1.17 | — |
| ruby3.1-fluentd-kubernetes-daemonset-1.17 | affected | wolfi | ruby3.1-fluentd-kubernetes-daemonset-1.17 | — |
| ruby-3.2 | affected | chainguard | ruby-3.2 | — |
| ruby-3.2 | affected | wolfi | ruby-3.2 | — |
| ruby3.2-fluentd-kubernetes-daemonset-1.16 | affected | chainguard | ruby3.2-fluentd-kubernetes-daemonset-1.16 | — |
| ruby3.2-fluentd-kubernetes-daemonset-1.17 | affected | wolfi | ruby3.2-fluentd-kubernetes-daemonset-1.17 | — |
| ruby3.2-fluentd-kubernetes-daemonset-1.17 | affected | chainguard | ruby3.2-fluentd-kubernetes-daemonset-1.17 | — |
| ruby-3.3 | affected | wolfi | ruby-3.3 | — |
| ruby-3.3 | affected | chainguard | ruby-3.3 | — |
| ruby3.3-fluentd-kubernetes-daemonset-1.16 | affected | chainguard | ruby3.3-fluentd-kubernetes-daemonset-1.16 | — |
| ruby3.4-fluentd-kubernetes-daemonset-1.16 | affected | chainguard | ruby3.4-fluentd-kubernetes-daemonset-1.16 | — |
| ruby3.4-fluentd-kubernetes-daemonset-1.17 | affected | wolfi | ruby3.4-fluentd-kubernetes-daemonset-1.17 | — |
| ruby3.4-fluentd-kubernetes-daemonset-1.17 | affected | chainguard | ruby3.4-fluentd-kubernetes-daemonset-1.17 | — |
Updated chromium-browser-stable packages fix security vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
ASB-A-359692772
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.5 | chromium | — |
| chromium | affected | openSUSE:Leap 15.6 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP5 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP6 | chromium | — |
chromedriver-129.0.6668.89-1.2 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Tumbleweed | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-7025
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-7025
CVEs:CVE-2024-7025
chromedriver-130.0.6723.69-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Tumbleweed | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP5 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP6 | chromium | — |
| chromium | affected | openSUSE:Leap 15.5 | chromium | — |
| chromium | affected | openSUSE:Leap 15.6 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
CVEs:CVE-2024-34665
Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
CVEs:CVE-2024-34665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-34666
Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
CVEs:CVE-2024-34666
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
CVEs:CVE-2024-34667
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-34667
CVEs:CVE-2024-34668
Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
CVEs:CVE-2024-34668
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-34669
Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
CVEs:CVE-2024-34669
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through <= 1.0.5.
CVEs:CVE-2024-50486
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| flutter_api | affected | acnoo | — | — |
CVEs:CVE-2024-50486
GHSA-3hjp-j522-245f
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-10229
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)
CVEs:CVE-2024-10229
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)
CVEs:CVE-2024-10229
CVEs:CVE-2024-10229
DEBIAN-CVE-2024-44337
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-gomarkdown-markdown | affected | Debian:12 | golang-github-gomarkdown-markdown | — |
| golang-github-gomarkdown-markdown | affected | Debian:13 | golang-github-gomarkdown-markdown | — |
| golang-github-gomarkdown-markdown | affected | Debian:14 | golang-github-gomarkdown-markdown | — |
GHSA-3wfx-mj93-vf8v
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-10231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-10231
Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-10231
Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-10231
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2024-43577
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2024-43577
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
DEBIAN-CVE-2024-9675
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-containers-buildah | affected | Debian:11 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:12 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:13 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:14 | golang-github-containers-buildah | — |
Lack of JWT issuer and signer validation in github.com/awslabs/aws-alb-route-directive-adapter-for-istio
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| awslabs/aws-alb-route-directive-adapter-for-istio | affected | github.com | github.com/awslabs/aws-alb-route-directive-adapter-for-istio | — |
CVEs:CVE-2024-20103
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001358...
CVEs:CVE-2024-20103
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| software_development_kit | affected | mediatek | — | — |
CVEs:CVE-2024-20100
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; ...
CVEs:CVE-2024-20100
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| iot_yocto | affected | mediatek | — | — |
| software_development_kit | affected | mediatek | — | — |
ASB-A-359692770
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-359699097
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; ...
CVEs:CVE-2024-20101
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| software_development_kit | affected | mediatek | — | — |
CVEs:CVE-2024-20101
ASB-A-359699100
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-335031447
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998892; ...
CVEs:CVE-2024-20102
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-20102
DEBIAN-CVE-2024-9407
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-containers-buildah | affected | Debian:11 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:12 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:13 | golang-github-containers-buildah | — |
| golang-github-containers-buildah | affected | Debian:14 | golang-github-containers-buildah | — |
In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed....
CVEs:CVE-2024-40673
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-40673
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DotsquaresLtd Google Map Locations google-map-locations allows Reflected XSS.This issue affects Google Map Locations: from n/a through <= 1.0.
CVEs:CVE-2024-49606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_map_locations | affected | dotsquares | — | — |
CVEs:CVE-2024-49606
CVEs:CVE-2024-39438
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
CVEs:CVE-2024-39438
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
CVEs:CVE-2024-39437
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-39437
CVEs:CVE-2024-39436
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
CVEs:CVE-2024-39436
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47014
Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.
CVEs:CVE-2024-47014
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-330537292
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-47023
there is a possible man-in-the-middle attack due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-47023
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-335031446
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction...
CVEs:CVE-2024-40674
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-40674
CVEs:CVE-2024-49672
Cross-Site Request Forgery (CSRF) vulnerability in giffordcheung Google Docs RSVP google-docs-rsvp-guestlist allows Stored XSS.This issue affects Google Docs RSVP: from n/a through <= 2.0.1.
CVEs:CVE-2024-49672
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_docs_rsvp | affected | gief | — | — |
CVEs:CVE-2024-40676
In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges neede...
CVEs:CVE-2024-40676
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-49335
Cross-Site Request Forgery (CSRF) vulnerability in sh4d0w28 GoogleDrive folder list googledrive-folder-list allows Stored XSS.This issue affects GoogleDrive folder list: from n/a through <= 2.2.2.
CVEs:CVE-2024-49335
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| googledrive_folder_list | affected | edush_maxim | — | — |
CVEs:CVE-2024-44097
According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to ...
CVEs:CVE-2024-44097
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nest_cam_\(indoor\,_wired\)_firmware | affected | — | — | |
| nest_cam_\(outdoor_or_indoor\,_battery\)_firmware | affected | — | — | |
| nest_cam_with_floodlight_firmware | affected | — | — | |
| nest_doorbell_\(battery\)_firmware | affected | — | — |
ASB-A-350500647
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
| vendor/qcom/opensource/graphics-kernel | affected | platform | platform/vendor/qcom/opensource/graphics-kernel | — |
CVEs:CVE-2024-34662
Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors.
CVEs:CVE-2024-34662
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2024-34664
Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment.
CVEs:CVE-2024-34664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-20093
In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: M...
CVEs:CVE-2024-20093
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-359692902
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-359699091
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-359699094
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-359699096
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: M...
CVEs:CVE-2024-20097
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-20097
In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996900; Issue ID: MS...
CVEs:CVE-2024-20096
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-20096
CVEs:CVE-2024-20095
In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996894; Issue ID: MS...
CVEs:CVE-2024-20095
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47030
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-315191818.
CVEs:CVE-2024-47030
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-315191818
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-47027
In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2024-47027
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-326444917
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2024-34733
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-34733
CVEs:CVE-2024-34748
In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not ...
CVEs:CVE-2024-34748
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-340329532
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-346640884
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-20090
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID:...
CVEs:CVE-2024-20090
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-40649
In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-40649
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-40651
In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-40651
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-346633576
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-346635977
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2024-40672
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-40672
In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed....
CVEs:CVE-2024-40677
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-40677
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID:...
CVEs:CVE-2024-20092
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-20092
CVEs:CVE-2024-20091
In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: M...
CVEs:CVE-2024-20091
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-40669
In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-40669
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-40670
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-40670
ASB-A-354263469
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-354268756
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-47017
In ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-47017
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID: MSV-1625.
CVEs:CVE-2024-20099
CVEs:CVE-2024-20099
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID...
CVEs:CVE-2024-20099
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | linuxfoundation | — | — |
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID...
CVEs:CVE-2024-20098
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| yocto | affected | linuxfoundation | — | — |
CVEs:CVE-2024-20098
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID: MSV-1626.
CVEs:CVE-2024-20098
PUB-A-330389917
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.
CVEs:CVE-2024-34663
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-34663
CVEs:CVE-2024-47035
In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVEs:CVE-2024-47035
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-341120728
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-47015
In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interacti...
CVEs:CVE-2024-47015
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-39440
In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2024-39440
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
CVEs:CVE-2024-39439
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-39439
PUB-A-331672131
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-47024
In vring_size of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2024-47024
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47041
In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-47041
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-319710920
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-340720879
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2024-47013
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47013
CVEs:CVE-2024-47016
there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-47016
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-47033
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47033
PUB-A-328221525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-330607706
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-349428550
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-47028
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47028
PUB-A-329334922
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-47026
In gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-47026
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution priv...
CVEs:CVE-2024-47029
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47029
there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-47034
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47034
PUB-A-310937217
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-331483147
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-340527441
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-47025
In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-47025
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-306211423
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:rhel_eus:8.8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:rhel_eus:8.8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:rhel_eus:8.8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:rhel_eus:8.8::appstream | golang | — |
| golang-bin | affected | Red Hat:rhel_eus:8.8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:rhel_eus:8.8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:rhel_eus:8.8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:rhel_eus:8.8::appstream | golang-race | — |
| golang-src | affected | Red Hat:rhel_eus:8.8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:rhel_eus:8.8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:rhel_eus:8.8::appstream | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:rhel_eus:8.6::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:rhel_eus:8.6::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:rhel_eus:8.6::appstream | delve-debugsource | — |
| golang | affected | Red Hat:rhel_eus:8.6::appstream | golang | — |
| golang-bin | affected | Red Hat:rhel_eus:8.6::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:rhel_eus:8.6::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:rhel_eus:8.6::appstream | golang-misc | — |
| golang-race | affected | Red Hat:rhel_eus:8.6::appstream | golang-race | — |
| golang-src | affected | Red Hat:rhel_eus:8.6::appstream | golang-src | — |
| golang-tests | affected | Red Hat:rhel_eus:8.6::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:rhel_eus:8.6::appstream | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
etcd-for-k8s1.28-3.5.15-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| etcd-for-k8s1.28 | affected | openSUSE:Tumbleweed | etcd-for-k8s1.28 | — |
etcd-for-k8s1.30-3.5.15-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| etcd-for-k8s1.30 | affected | openSUSE:Tumbleweed | etcd-for-k8s1.30 | — |
Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:8::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:8::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security, bug fix, and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:8::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
chromedriver-130.0.6723.58-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Tumbleweed | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP5 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP6 | chromium | — |
| chromium | affected | openSUSE:Leap 15.5 | chromium | — |
| chromium | affected | openSUSE:Leap 15.6 | chromium | — |
Red Hat Security Advisory: go-toolset:rhel8 security and bug fix update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:8::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:8::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security, bug fix, and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:8::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Security update for protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openSUSE:Leap 15.5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Installer Updates 15 SP5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Micro 5.5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Basesystem 15 SP5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Development Tools 15 SP5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Package Hub 15 SP5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Python 3 15 SP5 | protobuf | — |
| protobuf | affected | openSUSE:Leap Micro 5.5 | protobuf | — |
Security update for protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | SUSE:Linux Enterprise Server 15 SP4-LTSS | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP4 | protobuf | — |
| protobuf | affected | SUSE:Manager Server 4.3 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Installer Updates 15 SP4 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Micro 5.3 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Micro 5.4 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS | protobuf | — |
Security update for protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | SUSE:Linux Enterprise Module for Basesystem 15 SP6 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Development Tools 15 SP6 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Package Hub 15 SP6 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Python 3 15 SP6 | protobuf | — |
| protobuf | affected | openSUSE:Leap 15.6 | protobuf | — |
Fix CVE(s): CVE-2023-27043
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:18.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:18.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:18.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:18.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:18.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:18.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:18.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:18.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:18.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:18.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:18.04 | python2.7-minimal | — |
Fix CVE(s): CVE-2023-27043
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.6 | affected | TuxCare:Ubuntu:18.04 | idle-python3.6 | — |
| libpython3.6 | affected | TuxCare:Ubuntu:18.04 | libpython3.6 | — |
| libpython3.6-dev | affected | TuxCare:Ubuntu:18.04 | libpython3.6-dev | — |
| libpython3.6-minimal | affected | TuxCare:Ubuntu:18.04 | libpython3.6-minimal | — |
| libpython3.6-stdlib | affected | TuxCare:Ubuntu:18.04 | libpython3.6-stdlib | — |
| libpython3.6-testsuite | affected | TuxCare:Ubuntu:18.04 | libpython3.6-testsuite | — |
| python3.6 | affected | TuxCare:Ubuntu:18.04 | python3.6 | — |
| python3.6-dev | affected | TuxCare:Ubuntu:18.04 | python3.6-dev | — |
| python3.6-doc | affected | TuxCare:Ubuntu:18.04 | python3.6-doc | — |
| python3.6-examples | affected | TuxCare:Ubuntu:18.04 | python3.6-examples | — |
| python3.6-minimal | affected | TuxCare:Ubuntu:18.04 | python3.6-minimal | — |
| python3.6-venv | affected | TuxCare:Ubuntu:18.04 | python3.6-venv | — |
Fix CVE(s): CVE-2023-27043
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.5 | affected | TuxCare:Ubuntu:16.04 | idle-python3.5 | — |
| libpython3.5 | affected | TuxCare:Ubuntu:16.04 | libpython3.5 | — |
| libpython3.5-dev | affected | TuxCare:Ubuntu:16.04 | libpython3.5-dev | — |
| libpython3.5-minimal | affected | TuxCare:Ubuntu:16.04 | libpython3.5-minimal | — |
| libpython3.5-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython3.5-stdlib | — |
| libpython3.5-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython3.5-testsuite | — |
| python3.5 | affected | TuxCare:Ubuntu:16.04 | python3.5 | — |
| python3.5-dev | affected | TuxCare:Ubuntu:16.04 | python3.5-dev | — |
| python3.5-doc | affected | TuxCare:Ubuntu:16.04 | python3.5-doc | — |
| python3.5-examples | affected | TuxCare:Ubuntu:16.04 | python3.5-examples | — |
| python3.5-minimal | affected | TuxCare:Ubuntu:16.04 | python3.5-minimal | — |
| python3.5-venv | affected | TuxCare:Ubuntu:16.04 | python3.5-venv | — |
Fix CVE(s): CVE-2023-27043
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:16.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:16.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:16.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:16.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:16.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:16.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:16.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:16.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:16.04 | python2.7-minimal | — |
Fix CVE(s): CVE-2024-6232, CVE-2024-7592
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:18.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:18.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:18.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:18.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:18.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:18.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:18.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:18.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:18.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:18.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:18.04 | python2.7-minimal | — |
Fix CVE(s): CVE-2024-6232, CVE-2024-7592
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python2.7 | affected | TuxCare:Ubuntu:16.04 | idle-python2.7 | — |
| libpython2.7 | affected | TuxCare:Ubuntu:16.04 | libpython2.7 | — |
| libpython2.7-dev | affected | TuxCare:Ubuntu:16.04 | libpython2.7-dev | — |
| libpython2.7-minimal | affected | TuxCare:Ubuntu:16.04 | libpython2.7-minimal | — |
| libpython2.7-stdlib | affected | TuxCare:Ubuntu:16.04 | libpython2.7-stdlib | — |
| libpython2.7-testsuite | affected | TuxCare:Ubuntu:16.04 | libpython2.7-testsuite | — |
| python2.7 | affected | TuxCare:Ubuntu:16.04 | python2.7 | — |
| python2.7-dev | affected | TuxCare:Ubuntu:16.04 | python2.7-dev | — |
| python2.7-doc | affected | TuxCare:Ubuntu:16.04 | python2.7-doc | — |
| python2.7-examples | affected | TuxCare:Ubuntu:16.04 | python2.7-examples | — |
| python2.7-minimal | affected | TuxCare:Ubuntu:16.04 | python2.7-minimal | — |
Red Hat Security Advisory: go-toolset security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:rhel_eus:8.8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:rhel_eus:8.8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:rhel_eus:8.8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:rhel_eus:8.8::appstream | golang | — |
| golang-bin | affected | Red Hat:rhel_eus:8.8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:rhel_eus:8.8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:rhel_eus:8.8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:rhel_eus:8.8::appstream | golang-race | — |
| golang-src | affected | Red Hat:rhel_eus:8.8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:rhel_eus:8.8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:rhel_eus:8.8::appstream | go-toolset | — |
Red Hat Security Advisory: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Red Hat:rhel_eus:9.2::appstream | golang | — |
| golang-bin | affected | Red Hat:rhel_eus:9.2::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:rhel_eus:9.2::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:rhel_eus:9.2::appstream | golang-misc | — |
| golang-race | affected | Red Hat:rhel_eus:9.2::appstream | golang-race | — |
| golang-src | affected | Red Hat:rhel_eus:9.2::appstream | golang-src | — |
| golang-tests | affected | Red Hat:rhel_eus:9.2::appstream | golang-tests | — |
Red Hat Security Advisory: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Red Hat:enterprise_linux:9::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:9::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:9::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:9::appstream | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:9::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:9::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:9::appstream | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:rhel_eus:8.8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:rhel_eus:8.8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:rhel_eus:8.8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:rhel_eus:8.8::appstream | golang | — |
| golang-bin | affected | Red Hat:rhel_eus:8.8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:rhel_eus:8.8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:rhel_eus:8.8::appstream | golang-misc | — |
| golang-race | affected | Red Hat:rhel_eus:8.8::appstream | golang-race | — |
| golang-src | affected | Red Hat:rhel_eus:8.8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:rhel_eus:8.8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:rhel_eus:8.8::appstream | go-toolset | — |
Red Hat Security Advisory: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Red Hat:enterprise_linux:9::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:9::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:9::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:9::appstream | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:9::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:9::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:9::appstream | go-toolset | — |
Red Hat Security Advisory: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Red Hat:rhel_eus:9.2::appstream | golang | — |
| golang-bin | affected | Red Hat:rhel_eus:9.2::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:rhel_eus:9.2::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:rhel_eus:9.2::appstream | golang-misc | — |
| golang-race | affected | Red Hat:rhel_eus:9.2::appstream | golang-race | — |
| golang-src | affected | Red Hat:rhel_eus:9.2::appstream | golang-src | — |
| golang-tests | affected | Red Hat:rhel_eus:9.2::appstream | golang-tests | — |
DEBIAN-CVE-2024-9676
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-containers-storage | affected | Debian:11 | golang-github-containers-storage | — |
| golang-github-containers-storage | affected | Debian:12 | golang-github-containers-storage | — |
| golang-github-containers-storage | affected | Debian:13 | golang-github-containers-storage | — |
| golang-github-containers-storage | affected | Debian:14 | golang-github-containers-storage | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:rhel_aus:8.6::appstream | delve | — |
| delve | affected | Red Hat:rhel_e4s:8.6::appstream | delve | — |
| delve | affected | Red Hat:rhel_tus:8.6::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:rhel_e4s:8.6::appstream | delve-debuginfo | — |
| delve-debuginfo | affected | Red Hat:rhel_aus:8.6::appstream | delve-debuginfo | — |
| delve-debuginfo | affected | Red Hat:rhel_tus:8.6::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:rhel_e4s:8.6::appstream | delve-debugsource | — |
| delve-debugsource | affected | Red Hat:rhel_tus:8.6::appstream | delve-debugsource | — |
| delve-debugsource | affected | Red Hat:rhel_aus:8.6::appstream | delve-debugsource | — |
| golang | affected | Red Hat:rhel_tus:8.6::appstream | golang | — |
| golang | affected | Red Hat:rhel_aus:8.6::appstream | golang | — |
| golang | affected | Red Hat:rhel_e4s:8.6::appstream | golang | — |
| golang-bin | affected | Red Hat:rhel_e4s:8.6::appstream | golang-bin | — |
| golang-bin | affected | Red Hat:rhel_aus:8.6::appstream | golang-bin | — |
| golang-bin | affected | Red Hat:rhel_tus:8.6::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:rhel_e4s:8.6::appstream | golang-docs | — |
| golang-docs | affected | Red Hat:rhel_aus:8.6::appstream | golang-docs | — |
| golang-docs | affected | Red Hat:rhel_tus:8.6::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:rhel_aus:8.6::appstream | golang-misc | — |
| golang-misc | affected | Red Hat:rhel_e4s:8.6::appstream | golang-misc | — |
| golang-misc | affected | Red Hat:rhel_tus:8.6::appstream | golang-misc | — |
| golang-race | affected | Red Hat:rhel_aus:8.6::appstream | golang-race | — |
| golang-race | affected | Red Hat:rhel_e4s:8.6::appstream | golang-race | — |
| golang-race | affected | Red Hat:rhel_tus:8.6::appstream | golang-race | — |
| golang-src | affected | Red Hat:rhel_tus:8.6::appstream | golang-src | — |
| golang-src | affected | Red Hat:rhel_e4s:8.6::appstream | golang-src | — |
| golang-src | affected | Red Hat:rhel_aus:8.6::appstream | golang-src | — |
| golang-tests | affected | Red Hat:rhel_e4s:8.6::appstream | golang-tests | — |
| golang-tests | affected | Red Hat:rhel_tus:8.6::appstream | golang-tests | — |
| golang-tests | affected | Red Hat:rhel_aus:8.6::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:rhel_tus:8.6::appstream | go-toolset | — |
| go-toolset | affected | Red Hat:rhel_aus:8.6::appstream | go-toolset | — |
| go-toolset | affected | Red Hat:rhel_e4s:8.6::appstream | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:rhel_tus:8.4::appstream | delve | — |
| delve | affected | Red Hat:rhel_e4s:8.4::appstream | delve | — |
| delve | affected | Red Hat:rhel_aus:8.4::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:rhel_e4s:8.4::appstream | delve-debuginfo | — |
| delve-debuginfo | affected | Red Hat:rhel_aus:8.4::appstream | delve-debuginfo | — |
| delve-debuginfo | affected | Red Hat:rhel_tus:8.4::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:rhel_tus:8.4::appstream | delve-debugsource | — |
| delve-debugsource | affected | Red Hat:rhel_e4s:8.4::appstream | delve-debugsource | — |
| delve-debugsource | affected | Red Hat:rhel_aus:8.4::appstream | delve-debugsource | — |
| golang | affected | Red Hat:rhel_tus:8.4::appstream | golang | — |
| golang | affected | Red Hat:rhel_aus:8.4::appstream | golang | — |
| golang | affected | Red Hat:rhel_e4s:8.4::appstream | golang | — |
| golang-bin | affected | Red Hat:rhel_e4s:8.4::appstream | golang-bin | — |
| golang-bin | affected | Red Hat:rhel_aus:8.4::appstream | golang-bin | — |
| golang-bin | affected | Red Hat:rhel_tus:8.4::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:rhel_aus:8.4::appstream | golang-docs | — |
| golang-docs | affected | Red Hat:rhel_tus:8.4::appstream | golang-docs | — |
| golang-docs | affected | Red Hat:rhel_e4s:8.4::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:rhel_tus:8.4::appstream | golang-misc | — |
| golang-misc | affected | Red Hat:rhel_aus:8.4::appstream | golang-misc | — |
| golang-misc | affected | Red Hat:rhel_e4s:8.4::appstream | golang-misc | — |
| golang-race | affected | Red Hat:rhel_tus:8.4::appstream | golang-race | — |
| golang-race | affected | Red Hat:rhel_e4s:8.4::appstream | golang-race | — |
| golang-race | affected | Red Hat:rhel_aus:8.4::appstream | golang-race | — |
| golang-src | affected | Red Hat:rhel_aus:8.4::appstream | golang-src | — |
| golang-src | affected | Red Hat:rhel_tus:8.4::appstream | golang-src | — |
| golang-src | affected | Red Hat:rhel_e4s:8.4::appstream | golang-src | — |
| golang-tests | affected | Red Hat:rhel_aus:8.4::appstream | golang-tests | — |
| golang-tests | affected | Red Hat:rhel_e4s:8.4::appstream | golang-tests | — |
| golang-tests | affected | Red Hat:rhel_tus:8.4::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:rhel_aus:8.4::appstream | go-toolset | — |
| go-toolset | affected | Red Hat:rhel_tus:8.4::appstream | go-toolset | — |
| go-toolset | affected | Red Hat:rhel_e4s:8.4::appstream | go-toolset | — |
Security update for kubernetes1.24
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.24 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS | kubernetes1.24 | — |
| kubernetes1.24 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS | kubernetes1.24 | — |
| kubernetes1.24 | affected | SUSE:Linux Enterprise Server 15 SP4-LTSS | kubernetes1.24 | — |
| kubernetes1.24 | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP4 | kubernetes1.24 | — |
Security update for kubernetes1.24
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.24 | affected | SUSE:Linux Enterprise Module for Containers 15 SP5 | kubernetes1.24 | — |
| kubernetes1.24 | affected | openSUSE:Leap 15.5 | kubernetes1.24 | — |
| kubernetes1.24 | affected | openSUSE:Leap 15.6 | kubernetes1.24 | — |
Security update for kubernetes1.24
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.24 | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP3 | kubernetes1.24 | — |
| kubernetes1.24 | affected | SUSE:Enterprise Storage 7.1 | kubernetes1.24 | — |
| kubernetes1.24 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS | kubernetes1.24 | — |
| kubernetes1.24 | affected | SUSE:Linux Enterprise Server 15 SP3-LTSS | kubernetes1.24 | — |
Security update for kubernetes1.25
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.25 | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP4 | kubernetes1.25 | — |
| kubernetes1.25 | affected | openSUSE:Leap 15.6 | kubernetes1.25 | — |
| kubernetes1.25 | affected | SUSE:Linux Enterprise Module for Containers 15 SP5 | kubernetes1.25 | — |
| kubernetes1.25 | affected | SUSE:Linux Enterprise Module for Containers 15 SP6 | kubernetes1.25 | — |
| kubernetes1.25 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS | kubernetes1.25 | — |
| kubernetes1.25 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS | kubernetes1.25 | — |
| kubernetes1.25 | affected | SUSE:Linux Enterprise Server 15 SP4-LTSS | kubernetes1.25 | — |
| kubernetes1.25 | affected | openSUSE:Leap 15.5 | kubernetes1.25 | — |
Security update for kubernetes1.26
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.26 | affected | SUSE:Linux Enterprise Module for Containers 15 SP5 | kubernetes1.26 | — |
| kubernetes1.26 | affected | SUSE:Linux Enterprise Module for Containers 15 SP6 | kubernetes1.26 | — |
| kubernetes1.26 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS | kubernetes1.26 | — |
| kubernetes1.26 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS | kubernetes1.26 | — |
| kubernetes1.26 | affected | SUSE:Linux Enterprise Server 15 SP4-LTSS | kubernetes1.26 | — |
| kubernetes1.26 | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP4 | kubernetes1.26 | — |
| kubernetes1.26 | affected | openSUSE:Leap 15.5 | kubernetes1.26 | — |
| kubernetes1.26 | affected | openSUSE:Leap 15.6 | kubernetes1.26 | — |
Security update for kubernetes1.27
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.27 | affected | SUSE:Linux Enterprise Module for Containers 15 SP5 | kubernetes1.27 | — |
| kubernetes1.27 | affected | SUSE:Linux Enterprise Module for Containers 15 SP6 | kubernetes1.27 | — |
| kubernetes1.27 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS | kubernetes1.27 | — |
| kubernetes1.27 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS | kubernetes1.27 | — |
| kubernetes1.27 | affected | SUSE:Linux Enterprise Server 15 SP4-LTSS | kubernetes1.27 | — |
| kubernetes1.27 | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP4 | kubernetes1.27 | — |
| kubernetes1.27 | affected | openSUSE:Leap 15.5 | kubernetes1.27 | — |
| kubernetes1.27 | affected | openSUSE:Leap 15.6 | kubernetes1.27 | — |
Security update for kubernetes1.28
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.28 | affected | SUSE:Linux Enterprise Module for Containers 15 SP5 | kubernetes1.28 | — |
| kubernetes1.28 | affected | SUSE:Linux Enterprise Module for Containers 15 SP6 | kubernetes1.28 | — |
| kubernetes1.28 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS | kubernetes1.28 | — |
| kubernetes1.28 | affected | SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS | kubernetes1.28 | — |
| kubernetes1.28 | affected | SUSE:Linux Enterprise Server 15 SP4-LTSS | kubernetes1.28 | — |
| kubernetes1.28 | affected | SUSE:Linux Enterprise Server for SAP Applications 15 SP4 | kubernetes1.28 | — |
| kubernetes1.28 | affected | openSUSE:Leap 15.5 | kubernetes1.28 | — |
| kubernetes1.28 | affected | openSUSE:Leap 15.6 | kubernetes1.28 | — |
Red Hat Security Advisory: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Red Hat:rhel_e4s:9.0::appstream | golang | — |
| golang-bin | affected | Red Hat:rhel_e4s:9.0::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:rhel_e4s:9.0::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:rhel_e4s:9.0::appstream | golang-misc | — |
| golang-race | affected | Red Hat:rhel_e4s:9.0::appstream | golang-race | — |
| golang-src | affected | Red Hat:rhel_e4s:9.0::appstream | golang-src | — |
| golang-tests | affected | Red Hat:rhel_e4s:9.0::appstream | golang-tests | — |
Eclipse Jetty URI parsing of invalid authority
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.eclipse.jetty:jetty-http | affected | Maven | org.eclipse.jetty:jetty-http | — |
Eclipse Jetty URI parsing of invalid authority
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| akhq | affected | wolfi | akhq | — |
| akhq | affected | chainguard | akhq | — |
| apache-nifi | affected | chainguard | apache-nifi | — |
| apache-nifi | affected | wolfi | apache-nifi | — |
| apache-pulsar | affected | chainguard | apache-pulsar | — |
| apache-pulsar | affected | wolfi | apache-pulsar | — |
| apache-pulsar-4.0 | affected | chainguard | apache-pulsar-4.0 | — |
| apache-pulsar-fips-4.0 | affected | chainguard | apache-pulsar-fips-4.0 | — |
| apache-tika-3.0 | affected | chainguard | apache-tika-3.0 | — |
| apache-tika-3.1 | affected | wolfi | apache-tika-3.1 | — |
| apache-tika-3.1 | affected | chainguard | apache-tika-3.1 | — |
| apache-tika-3.2 | affected | wolfi | apache-tika-3.2 | — |
| apache-tika-3.2 | affected | chainguard | apache-tika-3.2 | — |
| apache-tika-3.3 | affected | chainguard | apache-tika-3.3 | — |
| apache-tika-3.3 | affected | wolfi | apache-tika-3.3 | — |
| apache-tika-fips-3.0 | affected | chainguard | apache-tika-fips-3.0 | — |
| apache-tika-fips-3.1 | affected | chainguard | apache-tika-fips-3.1 | — |
| apache-tika-fips-3.2 | affected | chainguard | apache-tika-fips-3.2 | — |
| apache-tika-fips-3.3 | affected | chainguard | apache-tika-fips-3.3 | — |
| cassandra-reaper | affected | wolfi | cassandra-reaper | — |
| cassandra-reaper | affected | chainguard | cassandra-reaper | — |
| celeborn-0.5 | affected | chainguard | celeborn-0.5 | — |
| clojure | affected | chainguard | clojure | — |
| clojure-tools | affected | chainguard | clojure-tools | — |
| cloudwatch-exporter | affected | wolfi | cloudwatch-exporter | — |
| cloudwatch-exporter | affected | chainguard | cloudwatch-exporter | — |
| confluent-kafka | affected | chainguard | confluent-kafka | — |
| confluent-kafka | affected | wolfi | confluent-kafka | — |
| confluent-kafka-jre-bcfips | affected | chainguard | confluent-kafka-jre-bcfips | — |
| cruise-control | affected | chainguard | cruise-control | — |
| cruise-control-fips | affected | chainguard | cruise-control-fips | — |
| druid | affected | chainguard | druid | — |
| druid | affected | wolfi | druid | — |
| hadoop-client-modules | affected | chainguard | hadoop-client-modules | — |
| kafka-jre-bcfips | affected | chainguard | kafka-jre-bcfips | — |
| kayenta-fips-2026.2 | affected | chainguard | kayenta-fips-2026.2 | — |
| neo4j-5.26 | affected | chainguard | neo4j-5.26 | — |
| neo4j-5.26 | affected | wolfi | neo4j-5.26 | — |
| org.eclipse.jetty:jetty-http | affected | Maven | org.eclipse.jetty:jetty-http | — |
| pinot | affected | chainguard | pinot | — |
| pinot-fips | affected | chainguard | pinot-fips | — |
| reposilite | affected | chainguard | reposilite | — |
| solr | affected | chainguard | solr | — |
| solr | affected | wolfi | solr | — |
| spark-3.5 | affected | chainguard | spark-3.5 | — |
| spark-4.0 | affected | chainguard | spark-4.0 | — |
| spark-4.0 | affected | wolfi | spark-4.0 | — |
| spark-4.1 | affected | wolfi | spark-4.1 | — |
| spark-4.1 | affected | chainguard | spark-4.1 | — |
| spark-fips-3.5 | affected | chainguard | spark-fips-3.5 | — |
| spark-kubernetes-operator | affected | chainguard | spark-kubernetes-operator | — |
| spark-kubernetes-operator-fips | affected | chainguard | spark-kubernetes-operator-fips | — |
| strimzi-kafka-operator-fips | affected | chainguard | strimzi-kafka-operator-fips | — |
| trino | affected | chainguard | trino | — |
| trino | affected | wolfi | trino | — |
| wso2is | affected | chainguard | wso2is | — |
| zaproxy | affected | chainguard | zaproxy | — |
| zookeeper-3.8 | affected | chainguard | zookeeper-3.8 | — |
| zookeeper-3.9 | affected | wolfi | zookeeper-3.9 | — |
| zookeeper-3.9 | affected | chainguard | zookeeper-3.9 | — |
| zookeeper-fips-3.8 | affected | chainguard | zookeeper-fips-3.8 | — |
| zookeeper-fips-3.9 | affected | chainguard | zookeeper-fips-3.9 | — |
GHSA-w2p9-j475-2wp5
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9956
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2024-9956
Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9956
DEBIAN-CVE-2024-9956
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Moderate: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Rocky Linux:9 | golang | — |
Moderate: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability in github.com/golang-fips/openssl
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-fips/openssl | affected | github.com | github.com/golang-fips/openssl | — |
Red Hat Security Advisory: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Red Hat:enterprise_linux:9::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:9::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:9::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:9::appstream | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:9::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:9::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:9::appstream | go-toolset | — |
Moderate: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | AlmaLinux:8 | delve | — |
| golang | affected | AlmaLinux:8 | golang | — |
| golang-bin | affected | AlmaLinux:8 | golang-bin | — |
| golang-docs | affected | AlmaLinux:8 | golang-docs | — |
| golang-misc | affected | AlmaLinux:8 | golang-misc | — |
| golang-src | affected | AlmaLinux:8 | golang-src | — |
| golang-tests | affected | AlmaLinux:8 | golang-tests | — |
| go-toolset | affected | AlmaLinux:8 | go-toolset | — |
| go-toolset | affected | AlmaLinux | — | — |
Moderate: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | AlmaLinux:9 | golang | — |
| golang-bin | affected | AlmaLinux:9 | golang-bin | — |
| golang-docs | affected | AlmaLinux:9 | golang-docs | — |
| golang-misc | affected | AlmaLinux:9 | golang-misc | — |
| golang-src | affected | AlmaLinux:9 | golang-src | — |
| golang-tests | affected | AlmaLinux:9 | golang-tests | — |
| go-toolset | affected | AlmaLinux:9 | go-toolset | — |
Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-fips/openssl | affected | github.com | — | — |
| golang-fips/openssl | affected | github.com | github.com/golang-fips/openssl | — |
Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-fips/openssl | affected | github.com | github.com/golang-fips/openssl | — |
CVE-2024-9355 affecting package golang for versions less than 1.22.9-1
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:3 | golang | — |
Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability
CVEs:CVE-2024-9355
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-fips/openssl | affected | github.com | github.com/golang-fips/openssl | — |
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match betw...
CVEs:CVE-2024-9355
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-fips/openssl | affected | github.com | — | — |
Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability
CVEs:CVE-2024-9355
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-fips/openssl | affected | github.com | github.com/golang-fips/openssl | — |
GHSA-gj3r-7jjv-636h
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2024-9955
Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9955
Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9955
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2024-9955
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP5 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP6 | chromium | — |
| chromium | affected | openSUSE:Leap 15.5 | chromium | — |
| chromium | affected | openSUSE:Leap 15.6 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
GHSA-h72p-7xmw-gpp8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2024-10487
Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
CVEs:CVE-2024-10487
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
CVEs:CVE-2024-10487
DEBIAN-CVE-2024-10487
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
GHSA-92m3-m5pw-p2x9
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-9603
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-9603
Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-9603
Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-9603
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
GHSA-q8jf-j34w-q74g
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2024-9954
Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-9954
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2024-9954
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Red Hat Security Advisory: maven:3.5 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | Red Hat:rhel_eus:8.4::appstream | aopalliance | — |
| aopalliance | affected | Red Hat:enterprise_linux:8::appstream | aopalliance | — |
| aopalliance | affected | Red Hat:rhel_eus:8.2::appstream | aopalliance | — |
| apache-commons-cli | affected | Red Hat:rhel_eus:8.2::appstream | apache-commons-cli | — |
| apache-commons-cli | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-cli | — |
| apache-commons-cli | affected | Red Hat:rhel_eus:8.4::appstream | apache-commons-cli | — |
| apache-commons-codec | affected | Red Hat:rhel_eus:8.2::appstream | apache-commons-codec | — |
| apache-commons-codec | affected | Red Hat:rhel_eus:8.4::appstream | apache-commons-codec | — |
| apache-commons-codec | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-codec | — |
| apache-commons-io | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-io | — |
| apache-commons-io | affected | Red Hat:rhel_eus:8.4::appstream | apache-commons-io | — |
| apache-commons-io | affected | Red Hat:rhel_eus:8.2::appstream | apache-commons-io | — |
| apache-commons-lang3 | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-lang3 | — |
| apache-commons-lang3 | affected | Red Hat:rhel_eus:8.2::appstream | apache-commons-lang3 | — |
| apache-commons-lang3 | affected | Red Hat:rhel_eus:8.4::appstream | apache-commons-lang3 | — |
| apache-commons-logging | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-logging | — |
| apache-commons-logging | affected | Red Hat:rhel_eus:8.2::appstream | apache-commons-logging | — |
| apache-commons-logging | affected | Red Hat:rhel_eus:8.4::appstream | apache-commons-logging | — |
| atinject | affected | Red Hat:rhel_eus:8.2::appstream | atinject | — |
| atinject | affected | Red Hat:enterprise_linux:8::appstream | atinject | — |
| atinject | affected | Red Hat:rhel_eus:8.4::appstream | atinject | — |
| cdi-api | affected | Red Hat:rhel_eus:8.2::appstream | cdi-api | — |
| cdi-api | affected | Red Hat:rhel_eus:8.4::appstream | cdi-api | — |
| cdi-api | affected | Red Hat:enterprise_linux:8::appstream | cdi-api | — |
| geronimo-annotation | affected | Red Hat:enterprise_linux:8::appstream | geronimo-annotation | — |
| geronimo-annotation | affected | Red Hat:rhel_eus:8.2::appstream | geronimo-annotation | — |
| geronimo-annotation | affected | Red Hat:rhel_eus:8.4::appstream | geronimo-annotation | — |
| glassfish-el | affected | Red Hat:enterprise_linux:8::appstream | glassfish-el | — |
| glassfish-el | affected | Red Hat:rhel_eus:8.2::appstream | glassfish-el | — |
| glassfish-el | affected | Red Hat:rhel_eus:8.4::appstream | glassfish-el | — |
| glassfish-el-api | affected | Red Hat:enterprise_linux:8::appstream | glassfish-el-api | — |
| glassfish-el-api | affected | Red Hat:rhel_eus:8.4::appstream | glassfish-el-api | — |
| glassfish-el-api | affected | Red Hat:rhel_eus:8.2::appstream | glassfish-el-api | — |
| google-guice | affected | Red Hat:rhel_eus:8.4::appstream | google-guice | — |
| google-guice | affected | Red Hat:enterprise_linux:8::appstream | google-guice | — |
| google-guice | affected | Red Hat:rhel_eus:8.2::appstream | google-guice | — |
| guava20 | affected | Red Hat:rhel_eus:8.4::appstream | guava20 | — |
| guava20 | affected | Red Hat:rhel_eus:8.2::appstream | guava20 | — |
| guava20 | affected | Red Hat:enterprise_linux:8::appstream | guava20 | — |
| hawtjni | affected | Red Hat:rhel_eus:8.2::appstream | hawtjni | — |
| hawtjni | affected | Red Hat:rhel_eus:8.4::appstream | hawtjni | — |
| hawtjni | affected | Red Hat:enterprise_linux:8::appstream | hawtjni | — |
| hawtjni-runtime | affected | Red Hat:enterprise_linux:8::appstream | hawtjni-runtime | — |
| hawtjni-runtime | affected | Red Hat:rhel_eus:8.4::appstream | hawtjni-runtime | — |
| hawtjni-runtime | affected | Red Hat:rhel_eus:8.2::appstream | hawtjni-runtime | — |
| httpcomponents-client | affected | Red Hat:rhel_eus:8.2::appstream | httpcomponents-client | — |
| httpcomponents-client | affected | Red Hat:rhel_eus:8.4::appstream | httpcomponents-client | — |
| httpcomponents-client | affected | Red Hat:enterprise_linux:8::appstream | httpcomponents-client | — |
| httpcomponents-core | affected | Red Hat:rhel_eus:8.2::appstream | httpcomponents-core | — |
| httpcomponents-core | affected | Red Hat:rhel_eus:8.4::appstream | httpcomponents-core | — |
| httpcomponents-core | affected | Red Hat:enterprise_linux:8::appstream | httpcomponents-core | — |
| jansi | affected | Red Hat:enterprise_linux:8::appstream | jansi | — |
| jansi | affected | Red Hat:rhel_eus:8.2::appstream | jansi | — |
| jansi | affected | Red Hat:rhel_eus:8.4::appstream | jansi | — |
| jansi-native | affected | Red Hat:rhel_eus:8.4::appstream | jansi-native | — |
| jansi-native | affected | Red Hat:rhel_eus:8.2::appstream | jansi-native | — |
| jansi-native | affected | Red Hat:enterprise_linux:8::appstream | jansi-native | — |
| jboss-interceptors-1.2-api | affected | Red Hat:rhel_eus:8.4::appstream | jboss-interceptors-1.2-api | — |
| jboss-interceptors-1.2-api | affected | Red Hat:rhel_eus:8.2::appstream | jboss-interceptors-1.2-api | — |
| jboss-interceptors-1.2-api | affected | Red Hat:enterprise_linux:8::appstream | jboss-interceptors-1.2-api | — |
| jcl-over-slf4j | affected | Red Hat:enterprise_linux:8::appstream | jcl-over-slf4j | — |
| jcl-over-slf4j | affected | Red Hat:rhel_eus:8.4::appstream | jcl-over-slf4j | — |
| jcl-over-slf4j | affected | Red Hat:rhel_eus:8.2::appstream | jcl-over-slf4j | — |
| jsoup | affected | Red Hat:rhel_eus:8.2::appstream | jsoup | — |
| jsoup | affected | Red Hat:rhel_eus:8.4::appstream | jsoup | — |
| jsoup | affected | Red Hat:enterprise_linux:8::appstream | jsoup | — |
| maven | affected | Red Hat:rhel_eus:8.2::appstream | maven | — |
| maven | affected | Red Hat:enterprise_linux:8::appstream | maven | — |
| maven | affected | Red Hat:rhel_eus:8.4::appstream | maven | — |
| maven-lib | affected | Red Hat:rhel_eus:8.2::appstream | maven-lib | — |
| maven-lib | affected | Red Hat:rhel_eus:8.4::appstream | maven-lib | — |
| maven-lib | affected | Red Hat:enterprise_linux:8::appstream | maven-lib | — |
| maven-resolver | affected | Red Hat:rhel_eus:8.2::appstream | maven-resolver | — |
| maven-resolver | affected | Red Hat:rhel_eus:8.4::appstream | maven-resolver | — |
| maven-resolver | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver | — |
| maven-resolver-api | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-api | — |
| maven-resolver-api | affected | Red Hat:rhel_eus:8.4::appstream | maven-resolver-api | — |
| maven-resolver-api | affected | Red Hat:rhel_eus:8.2::appstream | maven-resolver-api | — |
| maven-resolver-connector-basic | affected | Red Hat:rhel_eus:8.4::appstream | maven-resolver-connector-basic | — |
| maven-resolver-connector-basic | affected | Red Hat:rhel_eus:8.2::appstream | maven-resolver-connector-basic | — |
| maven-resolver-connector-basic | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-connector-basic | — |
| maven-resolver-impl | affected | Red Hat:rhel_eus:8.2::appstream | maven-resolver-impl | — |
| maven-resolver-impl | affected | Red Hat:rhel_eus:8.4::appstream | maven-resolver-impl | — |
| maven-resolver-impl | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-impl | — |
| maven-resolver-spi | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-spi | — |
| maven-resolver-spi | affected | Red Hat:rhel_eus:8.2::appstream | maven-resolver-spi | — |
| maven-resolver-spi | affected | Red Hat:rhel_eus:8.4::appstream | maven-resolver-spi | — |
| maven-resolver-transport-wagon | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-transport-wagon | — |
| maven-resolver-transport-wagon | affected | Red Hat:rhel_eus:8.2::appstream | maven-resolver-transport-wagon | — |
| maven-resolver-transport-wagon | affected | Red Hat:rhel_eus:8.4::appstream | maven-resolver-transport-wagon | — |
| maven-resolver-util | affected | Red Hat:rhel_eus:8.2::appstream | maven-resolver-util | — |
| maven-resolver-util | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver-util | — |
| maven-resolver-util | affected | Red Hat:rhel_eus:8.4::appstream | maven-resolver-util | — |
| maven-shared-utils | affected | Red Hat:rhel_eus:8.4::appstream | maven-shared-utils | — |
| maven-shared-utils | affected | Red Hat:rhel_eus:8.2::appstream | maven-shared-utils | — |
| maven-shared-utils | affected | Red Hat:enterprise_linux:8::appstream | maven-shared-utils | — |
| maven-wagon | affected | Red Hat:rhel_eus:8.2::appstream | maven-wagon | — |
| maven-wagon | affected | Red Hat:rhel_eus:8.4::appstream | maven-wagon | — |
| maven-wagon | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon | — |
| maven-wagon-file | affected | Red Hat:rhel_eus:8.2::appstream | maven-wagon-file | — |
| maven-wagon-file | affected | Red Hat:rhel_eus:8.4::appstream | maven-wagon-file | — |
| maven-wagon-file | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon-file | — |
| maven-wagon-http | affected | Red Hat:rhel_eus:8.4::appstream | maven-wagon-http | — |
| maven-wagon-http | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon-http | — |
| maven-wagon-http | affected | Red Hat:rhel_eus:8.2::appstream | maven-wagon-http | — |
| maven-wagon-http-shared | affected | Red Hat:rhel_eus:8.4::appstream | maven-wagon-http-shared | — |
| maven-wagon-http-shared | affected | Red Hat:rhel_eus:8.2::appstream | maven-wagon-http-shared | — |
| maven-wagon-http-shared | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon-http-shared | — |
| maven-wagon-provider-api | affected | Red Hat:rhel_eus:8.2::appstream | maven-wagon-provider-api | — |
| maven-wagon-provider-api | affected | Red Hat:rhel_eus:8.4::appstream | maven-wagon-provider-api | — |
| maven-wagon-provider-api | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon-provider-api | — |
| plexus-cipher | affected | Red Hat:rhel_eus:8.2::appstream | plexus-cipher | — |
| plexus-cipher | affected | Red Hat:enterprise_linux:8::appstream | plexus-cipher | — |
| plexus-cipher | affected | Red Hat:rhel_eus:8.4::appstream | plexus-cipher | — |
| plexus-classworlds | affected | Red Hat:rhel_eus:8.4::appstream | plexus-classworlds | — |
| plexus-classworlds | affected | Red Hat:enterprise_linux:8::appstream | plexus-classworlds | — |
| plexus-classworlds | affected | Red Hat:rhel_eus:8.2::appstream | plexus-classworlds | — |
| plexus-containers | affected | Red Hat:rhel_eus:8.4::appstream | plexus-containers | — |
| plexus-containers | affected | Red Hat:enterprise_linux:8::appstream | plexus-containers | — |
| plexus-containers | affected | Red Hat:rhel_eus:8.2::appstream | plexus-containers | — |
| plexus-containers-component-annotations | affected | Red Hat:rhel_eus:8.2::appstream | plexus-containers-component-annotations | — |
| plexus-containers-component-annotations | affected | Red Hat:enterprise_linux:8::appstream | plexus-containers-component-annotations | — |
| plexus-containers-component-annotations | affected | Red Hat:rhel_eus:8.4::appstream | plexus-containers-component-annotations | — |
| plexus-interpolation | affected | Red Hat:enterprise_linux:8::appstream | plexus-interpolation | — |
| plexus-interpolation | affected | Red Hat:rhel_eus:8.4::appstream | plexus-interpolation | — |
| plexus-interpolation | affected | Red Hat:rhel_eus:8.2::appstream | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | Red Hat:rhel_eus:8.2::appstream | plexus-sec-dispatcher | — |
| plexus-sec-dispatcher | affected | Red Hat:enterprise_linux:8::appstream | plexus-sec-dispatcher | — |
| plexus-sec-dispatcher | affected | Red Hat:rhel_eus:8.4::appstream | plexus-sec-dispatcher | — |
| plexus-utils | affected | Red Hat:rhel_eus:8.4::appstream | plexus-utils | — |
| plexus-utils | affected | Red Hat:rhel_eus:8.2::appstream | plexus-utils | — |
| plexus-utils | affected | Red Hat:enterprise_linux:8::appstream | plexus-utils | — |
| sisu | affected | Red Hat:rhel_eus:8.4::appstream | sisu | — |
| sisu | affected | Red Hat:rhel_eus:8.2::appstream | sisu | — |
| sisu | affected | Red Hat:enterprise_linux:8::appstream | sisu | — |
| sisu-inject | affected | Red Hat:rhel_eus:8.4::appstream | sisu-inject | — |
| sisu-inject | affected | Red Hat:rhel_eus:8.2::appstream | sisu-inject | — |
| sisu-inject | affected | Red Hat:enterprise_linux:8::appstream | sisu-inject | — |
| sisu-plexus | affected | Red Hat:rhel_eus:8.2::appstream | sisu-plexus | — |
| sisu-plexus | affected | Red Hat:enterprise_linux:8::appstream | sisu-plexus | — |
| sisu-plexus | affected | Red Hat:rhel_eus:8.4::appstream | sisu-plexus | — |
| slf4j | affected | Red Hat:enterprise_linux:8::appstream | slf4j | — |
| slf4j | affected | Red Hat:rhel_eus:8.4::appstream | slf4j | — |
| slf4j | affected | Red Hat:rhel_eus:8.2::appstream | slf4j | — |
Red Hat Security Advisory: maven:3.6 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | Red Hat:enterprise_linux:8::appstream | aopalliance | — |
| aopalliance | affected | Red Hat:rhel_eus:8.2::appstream | aopalliance | — |
| aopalliance | affected | Red Hat:rhel_eus:8.4::appstream | aopalliance | — |
| apache-commons-cli | affected | Red Hat:rhel_eus:8.4::appstream | apache-commons-cli | — |
| apache-commons-cli | affected | Red Hat:rhel_eus:8.2::appstream | apache-commons-cli | — |
| apache-commons-cli | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-cli | — |
| apache-commons-codec | affected | Red Hat:rhel_eus:8.4::appstream | apache-commons-codec | — |
| apache-commons-codec | affected | Red Hat:rhel_eus:8.2::appstream | apache-commons-codec | — |
| apache-commons-codec | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-codec | — |
| apache-commons-io | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-io | — |
| apache-commons-io | affected | Red Hat:rhel_eus:8.4::appstream | apache-commons-io | — |
| apache-commons-io | affected | Red Hat:rhel_eus:8.2::appstream | apache-commons-io | — |
| apache-commons-lang3 | affected | Red Hat:rhel_eus:8.4::appstream | apache-commons-lang3 | — |
| apache-commons-lang3 | affected | Red Hat:rhel_eus:8.2::appstream | apache-commons-lang3 | — |
| apache-commons-lang3 | affected | Red Hat:enterprise_linux:8::appstream | apache-commons-lang3 | — |
| atinject | affected | Red Hat:rhel_eus:8.4::appstream | atinject | — |
| atinject | affected | Red Hat:rhel_eus:8.2::appstream | atinject | — |
| atinject | affected | Red Hat:enterprise_linux:8::appstream | atinject | — |
| cdi-api | affected | Red Hat:enterprise_linux:8::appstream | cdi-api | — |
| cdi-api | affected | Red Hat:rhel_eus:8.2::appstream | cdi-api | — |
| cdi-api | affected | Red Hat:rhel_eus:8.4::appstream | cdi-api | — |
| geronimo-annotation | affected | Red Hat:rhel_eus:8.4::appstream | geronimo-annotation | — |
| geronimo-annotation | affected | Red Hat:rhel_eus:8.2::appstream | geronimo-annotation | — |
| geronimo-annotation | affected | Red Hat:enterprise_linux:8::appstream | geronimo-annotation | — |
| google-guice | affected | Red Hat:rhel_eus:8.2::appstream | google-guice | — |
| google-guice | affected | Red Hat:enterprise_linux:8::appstream | google-guice | — |
| google-guice | affected | Red Hat:rhel_eus:8.4::appstream | google-guice | — |
| guava | affected | Red Hat:rhel_eus:8.2::appstream | guava | — |
| guava | affected | Red Hat:rhel_eus:8.4::appstream | guava | — |
| guava | affected | Red Hat:enterprise_linux:8::appstream | guava | — |
| httpcomponents-client | affected | Red Hat:rhel_eus:8.2::appstream | httpcomponents-client | — |
| httpcomponents-client | affected | Red Hat:enterprise_linux:8::appstream | httpcomponents-client | — |
| httpcomponents-client | affected | Red Hat:rhel_eus:8.4::appstream | httpcomponents-client | — |
| httpcomponents-core | affected | Red Hat:enterprise_linux:8::appstream | httpcomponents-core | — |
| httpcomponents-core | affected | Red Hat:rhel_eus:8.4::appstream | httpcomponents-core | — |
| httpcomponents-core | affected | Red Hat:rhel_eus:8.2::appstream | httpcomponents-core | — |
| jansi | affected | Red Hat:rhel_eus:8.4::appstream | jansi | — |
| jansi | affected | Red Hat:rhel_eus:8.2::appstream | jansi | — |
| jansi | affected | Red Hat:enterprise_linux:8::appstream | jansi | — |
| jcl-over-slf4j | affected | Red Hat:enterprise_linux:8::appstream | jcl-over-slf4j | — |
| jcl-over-slf4j | affected | Red Hat:rhel_eus:8.2::appstream | jcl-over-slf4j | — |
| jcl-over-slf4j | affected | Red Hat:rhel_eus:8.4::appstream | jcl-over-slf4j | — |
| jsoup | affected | Red Hat:enterprise_linux:8::appstream | jsoup | — |
| jsoup | affected | Red Hat:rhel_eus:8.4::appstream | jsoup | — |
| jsoup | affected | Red Hat:rhel_eus:8.2::appstream | jsoup | — |
| jsr-305 | affected | Red Hat:rhel_eus:8.4::appstream | jsr-305 | — |
| jsr-305 | affected | Red Hat:enterprise_linux:8::appstream | jsr-305 | — |
| jsr-305 | affected | Red Hat:rhel_eus:8.2::appstream | jsr-305 | — |
| maven | affected | Red Hat:enterprise_linux:8::appstream | maven | — |
| maven | affected | Red Hat:rhel_eus:8.4::appstream | maven | — |
| maven | affected | Red Hat:rhel_eus:8.2::appstream | maven | — |
| maven-lib | affected | Red Hat:enterprise_linux:8::appstream | maven-lib | — |
| maven-lib | affected | Red Hat:rhel_eus:8.2::appstream | maven-lib | — |
| maven-lib | affected | Red Hat:rhel_eus:8.4::appstream | maven-lib | — |
| maven-openjdk11 | affected | Red Hat:enterprise_linux:8::appstream | maven-openjdk11 | — |
| maven-openjdk11 | affected | Red Hat:rhel_eus:8.2::appstream | maven-openjdk11 | — |
| maven-openjdk11 | affected | Red Hat:rhel_eus:8.4::appstream | maven-openjdk11 | — |
| maven-openjdk17 | affected | Red Hat:enterprise_linux:8::appstream | maven-openjdk17 | — |
| maven-openjdk8 | affected | Red Hat:enterprise_linux:8::appstream | maven-openjdk8 | — |
| maven-openjdk8 | affected | Red Hat:rhel_eus:8.2::appstream | maven-openjdk8 | — |
| maven-openjdk8 | affected | Red Hat:rhel_eus:8.4::appstream | maven-openjdk8 | — |
| maven-resolver | affected | Red Hat:rhel_eus:8.2::appstream | maven-resolver | — |
| maven-resolver | affected | Red Hat:rhel_eus:8.4::appstream | maven-resolver | — |
| maven-resolver | affected | Red Hat:enterprise_linux:8::appstream | maven-resolver | — |
| maven-shared-utils | affected | Red Hat:rhel_eus:8.4::appstream | maven-shared-utils | — |
| maven-shared-utils | affected | Red Hat:rhel_eus:8.2::appstream | maven-shared-utils | — |
| maven-shared-utils | affected | Red Hat:enterprise_linux:8::appstream | maven-shared-utils | — |
| maven-wagon | affected | Red Hat:rhel_eus:8.4::appstream | maven-wagon | — |
| maven-wagon | affected | Red Hat:enterprise_linux:8::appstream | maven-wagon | — |
| maven-wagon | affected | Red Hat:rhel_eus:8.2::appstream | maven-wagon | — |
| plexus-cipher | affected | Red Hat:enterprise_linux:8::appstream | plexus-cipher | — |
| plexus-cipher | affected | Red Hat:rhel_eus:8.4::appstream | plexus-cipher | — |
| plexus-cipher | affected | Red Hat:rhel_eus:8.2::appstream | plexus-cipher | — |
| plexus-classworlds | affected | Red Hat:rhel_eus:8.2::appstream | plexus-classworlds | — |
| plexus-classworlds | affected | Red Hat:enterprise_linux:8::appstream | plexus-classworlds | — |
| plexus-classworlds | affected | Red Hat:rhel_eus:8.4::appstream | plexus-classworlds | — |
| plexus-containers | affected | Red Hat:enterprise_linux:8::appstream | plexus-containers | — |
| plexus-containers | affected | Red Hat:rhel_eus:8.4::appstream | plexus-containers | — |
| plexus-containers | affected | Red Hat:rhel_eus:8.2::appstream | plexus-containers | — |
| plexus-containers-component-annotations | affected | Red Hat:rhel_eus:8.2::appstream | plexus-containers-component-annotations | — |
| plexus-containers-component-annotations | affected | Red Hat:rhel_eus:8.4::appstream | plexus-containers-component-annotations | — |
| plexus-containers-component-annotations | affected | Red Hat:enterprise_linux:8::appstream | plexus-containers-component-annotations | — |
| plexus-interpolation | affected | Red Hat:rhel_eus:8.4::appstream | plexus-interpolation | — |
| plexus-interpolation | affected | Red Hat:enterprise_linux:8::appstream | plexus-interpolation | — |
| plexus-interpolation | affected | Red Hat:rhel_eus:8.2::appstream | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | Red Hat:enterprise_linux:8::appstream | plexus-sec-dispatcher | — |
| plexus-sec-dispatcher | affected | Red Hat:rhel_eus:8.4::appstream | plexus-sec-dispatcher | — |
| plexus-sec-dispatcher | affected | Red Hat:rhel_eus:8.2::appstream | plexus-sec-dispatcher | — |
| plexus-utils | affected | Red Hat:rhel_eus:8.2::appstream | plexus-utils | — |
| plexus-utils | affected | Red Hat:rhel_eus:8.4::appstream | plexus-utils | — |
| plexus-utils | affected | Red Hat:enterprise_linux:8::appstream | plexus-utils | — |
| sisu | affected | Red Hat:rhel_eus:8.2::appstream | sisu | — |
| sisu | affected | Red Hat:rhel_eus:8.4::appstream | sisu | — |
| sisu | affected | Red Hat:enterprise_linux:8::appstream | sisu | — |
| slf4j | affected | Red Hat:rhel_eus:8.4::appstream | slf4j | — |
| slf4j | affected | Red Hat:enterprise_linux:8::appstream | slf4j | — |
| slf4j | affected | Red Hat:rhel_eus:8.2::appstream | slf4j | — |
Red Hat Security Advisory: maven:3.5 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aopalliance | affected | Red Hat:rhel_e4s:8.1::appstream | aopalliance | — |
| apache-commons-cli | affected | Red Hat:rhel_e4s:8.1::appstream | apache-commons-cli | — |
| apache-commons-codec | affected | Red Hat:rhel_e4s:8.1::appstream | apache-commons-codec | — |
| apache-commons-io | affected | Red Hat:rhel_e4s:8.1::appstream | apache-commons-io | — |
| apache-commons-lang3 | affected | Red Hat:rhel_e4s:8.1::appstream | apache-commons-lang3 | — |
| apache-commons-logging | affected | Red Hat:rhel_e4s:8.1::appstream | apache-commons-logging | — |
| atinject | affected | Red Hat:rhel_e4s:8.1::appstream | atinject | — |
| cdi-api | affected | Red Hat:rhel_e4s:8.1::appstream | cdi-api | — |
| geronimo-annotation | affected | Red Hat:rhel_e4s:8.1::appstream | geronimo-annotation | — |
| glassfish-el | affected | Red Hat:rhel_e4s:8.1::appstream | glassfish-el | — |
| glassfish-el-api | affected | Red Hat:rhel_e4s:8.1::appstream | glassfish-el-api | — |
| google-guice | affected | Red Hat:rhel_e4s:8.1::appstream | google-guice | — |
| guava20 | affected | Red Hat:rhel_e4s:8.1::appstream | guava20 | — |
| hawtjni | affected | Red Hat:rhel_e4s:8.1::appstream | hawtjni | — |
| hawtjni-runtime | affected | Red Hat:rhel_e4s:8.1::appstream | hawtjni-runtime | — |
| httpcomponents-client | affected | Red Hat:rhel_e4s:8.1::appstream | httpcomponents-client | — |
| httpcomponents-core | affected | Red Hat:rhel_e4s:8.1::appstream | httpcomponents-core | — |
| jansi | affected | Red Hat:rhel_e4s:8.1::appstream | jansi | — |
| jansi-native | affected | Red Hat:rhel_e4s:8.1::appstream | jansi-native | — |
| jboss-interceptors-1.2-api | affected | Red Hat:rhel_e4s:8.1::appstream | jboss-interceptors-1.2-api | — |
| jcl-over-slf4j | affected | Red Hat:rhel_e4s:8.1::appstream | jcl-over-slf4j | — |
| jsoup | affected | Red Hat:rhel_e4s:8.1::appstream | jsoup | — |
| maven | affected | Red Hat:rhel_e4s:8.1::appstream | maven | — |
| maven-lib | affected | Red Hat:rhel_e4s:8.1::appstream | maven-lib | — |
| maven-resolver | affected | Red Hat:rhel_e4s:8.1::appstream | maven-resolver | — |
| maven-resolver-api | affected | Red Hat:rhel_e4s:8.1::appstream | maven-resolver-api | — |
| maven-resolver-connector-basic | affected | Red Hat:rhel_e4s:8.1::appstream | maven-resolver-connector-basic | — |
| maven-resolver-impl | affected | Red Hat:rhel_e4s:8.1::appstream | maven-resolver-impl | — |
| maven-resolver-spi | affected | Red Hat:rhel_e4s:8.1::appstream | maven-resolver-spi | — |
| maven-resolver-transport-wagon | affected | Red Hat:rhel_e4s:8.1::appstream | maven-resolver-transport-wagon | — |
| maven-resolver-util | affected | Red Hat:rhel_e4s:8.1::appstream | maven-resolver-util | — |
| maven-shared-utils | affected | Red Hat:rhel_e4s:8.1::appstream | maven-shared-utils | — |
| maven-wagon | affected | Red Hat:rhel_e4s:8.1::appstream | maven-wagon | — |
| maven-wagon-file | affected | Red Hat:rhel_e4s:8.1::appstream | maven-wagon-file | — |
| maven-wagon-http | affected | Red Hat:rhel_e4s:8.1::appstream | maven-wagon-http | — |
| maven-wagon-http-shared | affected | Red Hat:rhel_e4s:8.1::appstream | maven-wagon-http-shared | — |
| maven-wagon-provider-api | affected | Red Hat:rhel_e4s:8.1::appstream | maven-wagon-provider-api | — |
| plexus-cipher | affected | Red Hat:rhel_e4s:8.1::appstream | plexus-cipher | — |
| plexus-classworlds | affected | Red Hat:rhel_e4s:8.1::appstream | plexus-classworlds | — |
| plexus-containers | affected | Red Hat:rhel_e4s:8.1::appstream | plexus-containers | — |
| plexus-containers-component-annotations | affected | Red Hat:rhel_e4s:8.1::appstream | plexus-containers-component-annotations | — |
| plexus-interpolation | affected | Red Hat:rhel_e4s:8.1::appstream | plexus-interpolation | — |
| plexus-sec-dispatcher | affected | Red Hat:rhel_e4s:8.1::appstream | plexus-sec-dispatcher | — |
| plexus-utils | affected | Red Hat:rhel_e4s:8.1::appstream | plexus-utils | — |
| sisu | affected | Red Hat:rhel_e4s:8.1::appstream | sisu | — |
| sisu-inject | affected | Red Hat:rhel_e4s:8.1::appstream | sisu-inject | — |
| sisu-plexus | affected | Red Hat:rhel_e4s:8.1::appstream | sisu-plexus | — |
| slf4j | affected | Red Hat:rhel_e4s:8.1::appstream | slf4j | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
CVEs:CVE-2024-43566
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2024-43566
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
DEBIAN-CVE-2024-9341
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-containers-common | affected | Debian:11 | golang-github-containers-common | — |
| golang-github-containers-common | affected | Debian:12 | golang-github-containers-common | — |
| golang-github-containers-common | affected | Debian:13 | golang-github-containers-common | — |
| golang-github-containers-common | affected | Debian:14 | golang-github-containers-common | — |
CVEs:CVE-2024-43595
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2024-43595
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2024-43596
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2024-43596
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2024-43587
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2024-43587
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
GHSA-4v8q-vp3v-vvxh
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-9602
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-9602
Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-9602
Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-9602
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2024-43578
CVEs:CVE-2024-43579
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2024-43578
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2024-43579
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2024-9369
Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-9369
Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-9369
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
GHSA-g4gj-m346-585c
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2024-10230
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-10230
Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-10230
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-10230
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. Th...
CVEs:CVE-2024-9861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| otp_verification_with_firebase | affected | miniorange | — | — |
CVEs:CVE-2024-9861
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass aut...
CVEs:CVE-2024-9862
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| otp_verification_with_firebase | affected | miniorange | — | — |
CVEs:CVE-2024-9862
GHSA-p3wf-f274-7gx2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-10488
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2024-10488
Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-10488
DEBIAN-CVE-2024-10488
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-49023
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVEs:CVE-2024-49023
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2021-4452
The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for a...
CVEs:CVE-2021-4452
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_language_translator | affected | gtranslate | — | — |
GHSA-7c7g-86f2-3w2x
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2024-9965
Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2024-9965
Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity:...
CVEs:CVE-2024-9965
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2024-9965
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
GHSA-j8x2-fpjj-2hvp
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-9859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2024-9859
Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2024-9859
DEBIAN-CVE-2024-9859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
GHSA-3j36-mj45-fgp4
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9960
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2024-9960
Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9960
DEBIAN-CVE-2024-9960
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
GHSA-89v2-8rj2-3464
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
GHSA-c2h4-jx6m-jp2q
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2024-9957
Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9957
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity...
CVEs:CVE-2024-9961
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2024-9961
DEBIAN-CVE-2024-9957
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2024-9961
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-43580
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2024-43580
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
GHSA-7ppc-7q95-ccw3
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2024-9966
Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2024-9966
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2024-9966
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
GHSA-h5h2-jj79-rjrp
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)
CVEs:CVE-2024-9959
CVEs:CVE-2024-9959
Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)
CVEs:CVE-2024-9959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2024-9959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-44101
there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-44101
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-319834067
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
GHSA-9pq2-vmj6-97q4
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
GHSA-f8jx-5r24-p453
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9958
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9958
CVEs:CVE-2024-9958
CVEs:CVE-2024-9962
Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9962
Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9962
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2024-9958
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2024-9962
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2024-40675
In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-40675
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
GHSA-j6j9-m952-pp68
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
CVEs:CVE-2024-9963
Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2024-9963
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2024-9963
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
GHSA-8qjp-f639-q7hx
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
CVEs:CVE-2024-9964
Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
CVEs:CVE-2024-9964
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2024-9964
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
CVEs:CVE-2024-44100
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-44100
PUB-A-299774545
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-47021
In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2024-47021
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-299775134
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-8912
An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users. There are two Looker versions that are hosted by Looker: * Looker (Google Cloud core) was found to be vulne...
CVEs:CVE-2024-8912
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cloud_looker | affected | — | — |
CVEs:CVE-2024-47020
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.
CVEs:CVE-2024-47020
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.
CVEs:CVE-2024-47022
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47022
PUB-A-331255656
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-331966488
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-329163861.
CVEs:CVE-2024-47031
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47031
PUB-A-329163861
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2024-44098
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-44098
PUB-A-323163451
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2024-47012
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47012
PUB-A-322820753
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2024-44099
There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-44099
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2024-47018
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47018
In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is no...
CVEs:CVE-2024-47019
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-47019
PUB-A-322223729
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-325927059
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-331666405
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2024-34732
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-34732
ASB-A-340332428
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" or "generate"...
CVEs:CVE-2024-9858
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| migrate_to_containers | affected | — | — |
CVEs:CVE-2024-9858
AWS Load Balancer Controller automatically detaches externally associated web ACL from Application Load Balancers in sigs.k8s.io/aws-load-balancer-controller
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aws-load-balancer-controller | affected | chainguard | aws-load-balancer-controller | — |
| aws-load-balancer-controller | affected | sigs.k8s.io | sigs.k8s.io/aws-load-balancer-controller | — |
| aws-load-balancer-controller | affected | wolfi | aws-load-balancer-controller | — |
| aws-load-balancer-controller-fips | affected | chainguard | aws-load-balancer-controller-fips | — |
AWS Load Balancer Controller automatically detaches externally associated web ACL from Application Load Balancers
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aws-load-balancer-controller | affected | wolfi | aws-load-balancer-controller | — |
| aws-load-balancer-controller | affected | sigs.k8s.io | sigs.k8s.io/aws-load-balancer-controller | — |
| aws-load-balancer-controller | affected | sigs.k8s.io | sigs.k8s.io/aws-load-balancer-controller | — |
| aws-load-balancer-controller | affected | chainguard | aws-load-balancer-controller | — |
| aws-load-balancer-controller-fips | affected | chainguard | aws-load-balancer-controller-fips | — |
AWS Load Balancer Controller automatically detaches externally associated web ACL from Application Load Balancers
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aws-load-balancer-controller | affected | sigs.k8s.io | sigs.k8s.io/aws-load-balancer-controller | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.