Vulnerability index

Browse CVEs

1,003 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.6
CVE-2020-6509

Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to pot…

Fix: 83.0.4103.116+
Fix from $2,300 2020-07-22
Chrome CRITICAL 9.6
CVE-2020-6522

Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a …

Fix: 84.0.4147.89+
Fix from $2,300 2020-07-22
Chrome CRITICAL 9.6
CVE-2020-6505

Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML…

Fix: 83.0.4103.106+
Fix from $2,300 2020-07-22
Android CRITICAL 9.8
CVE-2020-0224

In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion. This could lead to remote code executio…

Patch available
Fix from $2,300 2020-07-17
Android CRITICAL 9.8
CVE-2020-0225

In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to a missing bounds check. This…

Patch available
Fix from $2,300 2020-07-17
Android CRITICAL 9.8
CVE-2020-0230

There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156337262

Mitigation only
Fix from $2,300 2020-07-17
Android CRITICAL 9.8
CVE-2020-0231

There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156333727

Mitigation only
Fix from $2,300 2020-07-17
Oauth Client Library For Java CRITICAL 9.1
CVE-2020-7692

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by…

Fix: 1.31.0+
Fix from $2,300 2020-07-09
Android CRITICAL 9.8
CVE-2020-0223

This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-1351304…

Mitigation only
Fix from $2,300 2020-06-16
Android CRITICAL 9.8
CVE-2020-0232

Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it. A concurrent thread co…

Mitigation only
Fix from $2,300 2020-06-16
Android CRITICAL 9.8
CVE-2020-0235

In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_use…

Mitigation only
Fix from $2,300 2020-06-16
Android CRITICAL 9.8
CVE-2020-0217

In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Patch available
Fix from $2,300 2020-06-11
Android CRITICAL 9.8
CVE-2020-0201

In showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy. This could lead to remote escalation…

Patch available
Fix from $2,300 2020-06-11
Android CRITICAL 9.8
CVE-2020-0138

In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio…

Patch available
Fix from $2,300 2020-06-11
Android CRITICAL 9.8
CVE-2020-0117

In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluet…

Patch available
Fix from $2,300 2020-06-10
Android CRITICAL 9.8
CVE-2020-13839

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT comman…

Mitigation only
Fix from $2,300 2020-06-05
Android CRITICAL 9.8
CVE-2020-13840

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via an MTK AT command …

Mitigation only
Fix from $2,300 2020-06-05
Android CRITICAL 9.8
CVE-2020-13841

An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets). An AT command handler allows attackers to bypass intended acces…

Mitigation only
Fix from $2,300 2020-06-05
Android CRITICAL 9.8
CVE-2020-13831

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic Kinibi component allows arbit…

Mitigation only
Fix from $2,300 2020-06-04
Android CRITICAL 9.8
CVE-2020-13832

An issue was discovered on Samsung mobile devices with Q(10.0) (with TEEGRIS on Exynos chipsets) software. The Widevine Trustlet allows arbitrary cod…

Mitigation only
Fix from $2,300 2020-06-04
Android CRITICAL 9.8
CVE-2020-13835

An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user cr…

Mitigation only
Fix from $2,300 2020-06-04
Android CRITICAL 9.1
CVE-2020-13833

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a s…

Mitigation only
Fix from $2,300 2020-06-04
Chrome CRITICAL 9.6
CVE-2020-6493

Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 83.0.4103.97+
Fix from $2,300 2020-06-03
Chrome CRITICAL 9.6
CVE-2020-6471

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic…

Fix: 83.0.4103.61+
Fix from $2,300 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6461

Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially p…

Fix: 81.0.4044.129+
Fix from $2,300 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6462

Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to poten…

Fix: 81.0.4044.129+
Fix from $2,300 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6465

Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to…

Fix: 83.0.4103.61+
Fix from $2,300 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6466

Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perf…

Fix: 83.0.4103.61+
Fix from $2,300 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6469

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic…

Fix: 83.0.4103.61+
Fix from $2,300 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6457

Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 81.0.4044.113+
Fix from $2,300 2020-05-21