Vulnerability index

Browse CVEs

1,003 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Android CRITICAL 9.8
CVE-2022-20237

In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code e…

Mitigation only
Fix from $2,300 2022-08-11
Android CRITICAL 9.8
CVE-2022-20361

In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. Th…

Patch available
Fix from $2,300 2022-08-10
Android CRITICAL 9.8
CVE-2022-20239

remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be contr…

Mitigation only
Fix from $2,300 2022-08-10
Android CRITICAL 9.8
CVE-2022-33719

Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

Mitigation only
Fix from $2,300 2022-08-05
Google Play Services Software Development Kit CRITICAL 9.8
CVE-2022-1799

Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SD…

Fix: 18.0.2+
Fix from $2,300 2022-07-29
Chrome CRITICAL 9.3
CVE-2022-2010

Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 102.0.5005.115+
Fix from $2,300 2022-07-28
Chrome CRITICAL 9.6
CVE-2022-1853

Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Fix: 102.0.5005.61+
Fix from $2,300 2022-07-27
Chrome CRITICAL 9.6
CVE-2022-1309

Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox…

Fix: 100.0.4896.88+
Fix from $2,300 2022-07-25
Chrome CRITICAL 9.6
CVE-2022-1312

Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potent…

Fix: 100.0.4896.88+
Fix from $2,300 2022-07-25
Chrome CRITICAL 9.6
CVE-2022-0977

Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific…

Fix: 99.0.4844.74+
Fix from $2,300 2022-07-21
Chrome CRITICAL 9.6
CVE-2022-0973

Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 99.0.4844.74+
Fix from $2,300 2022-07-21
Android CRITICAL 9.8
CVE-2022-20222

In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution wit…

Patch available
Fix from $2,300 2022-07-13
Android CRITICAL 9.8
CVE-2022-20229

In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead…

Patch available
Fix from $2,300 2022-07-13
Android CRITICAL 9.8
CVE-2022-20238

'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be cont…

Patch available
Fix from $2,300 2022-07-13
Android CRITICAL 9.8
CVE-2022-20216

android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.sprd.firewall has set exporte…

Mitigation only
Fix from $2,300 2022-07-13
Android CRITICAL 9.8
CVE-2022-20210

The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in inte…

Mitigation only
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20167

Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A

No fix yet
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20170

Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A

No fix yet
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20171

Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A

No fix yet
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20173

Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A

No fix yet
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20191

Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A

No fix yet
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20140EPSS 9%

In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of pr…

Mitigation only
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20145EPSS 7%

In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to r…

Mitigation only
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20160

Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A

No fix yet
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20164

Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A

No fix yet
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20127EPSS 7%

In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no add…

Mitigation only
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20130EPSS 9%

In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote co…

Mitigation only
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-30722

Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Ac…

Mitigation only
Fix from $2,300 2022-06-07
Android CRITICAL 9.1
CVE-2022-30711

Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $2,300 2022-06-07
Android CRITICAL 9.1
CVE-2022-30712

Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

No fix yet
Fix from $2,300 2022-06-07