‼ CVE-2021-3684 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-20911 ‼
📖 Read
via "National Vulnerability Database".
In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242537498📖 Read
via "National Vulnerability Database".
‼ CVE-2023-20970 ‼
📖 Read
via "National Vulnerability Database".
In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262236005📖 Read
via "National Vulnerability Database".
‼ CVE-2023-21073 ‼
📖 Read
via "National Vulnerability Database".
In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257290396References: N/A📖 Read
via "National Vulnerability Database".
‼ CVE-2023-21049 ‼
📖 Read
via "National Vulnerability Database".
In append_camera_metadata of camera_metadata.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-236688120References: N/A📖 Read
via "National Vulnerability Database".
‼ CVE-2023-21048 ‼
📖 Read
via "National Vulnerability Database".
In handleEvent of nan.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259304053References: N/A📖 Read
via "National Vulnerability Database".
‼ CVE-2023-21039 ‼
📖 Read
via "National Vulnerability Database".
In dumpstateBoard of Dumpstate.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-263783650References: N/A📖 Read
via "National Vulnerability Database".
‼ CVE-2023-21054 ‼
📖 Read
via "National Vulnerability Database".
In EUTRAN_LCS_ConvertLCS_MOLRReq of LPP_CommonUtil.c, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-244556535References: N/A📖 Read
via "National Vulnerability Database".
‼ CVE-2023-21031 ‼
📖 Read
via "National Vulnerability Database".
In Display::setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-242688355📖 Read
via "National Vulnerability Database".
‼ CVE-2023-20947 ‼
📖 Read
via "National Vulnerability Database".
In getGroupState of GrantPermissionsViewModel.kt, there is a possible way to keep a one-time permission granted due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237405974📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25675 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.Bincount` segfaults when given a parameter `weights` that is neither the same shape as parameter `arr` nor a length-0 tensor. A fix is included in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25667 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, integer overflow occurs when `2^31 <= num_frames * height * width * channels < 2^32`, for example Full HD screencast of at least 346 frames. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25801 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first and fourth elements of their parameter `pooling_ratio` to be equal to 1.0, as pooling on batch and channel dimensions is not supported. A fix is included in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25664 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25673 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a Floating Point Exception in TensorListSplit with XLA. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25658 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, an out of bounds read is in GRUBlockCellGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25662 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overflow in EditDistance. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25670 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-28437 ‼
📖 Read
via "National Vulnerability Database".
Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25660 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `summarize` of `tf.raw_ops.Print` is zero, the new method `SummarizeArray<bool>` will reference to a nullptr, leading to a seg fault. A fix is included in TensorFlow version 2.12 and version 2.11.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25663 ‼
📖 Read
via "National Vulnerability Database".
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `ctx->step_containter()` is a null ptr, the Lookup function will be executed with a null pointer. A fix is included in TensorFlow 2.12.0 and 2.11.1.📖 Read
via "National Vulnerability Database".