Vulnerability index

Browse CVEs

1,003 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.1
CVE-2016-5202

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 …

Fix: 54.0.2840.98 / 54.0.2840.99+
Fix from $2,300 2019-10-25
Android CRITICAL 9.8
CVE-2019-9459

In libttspico, there is a possible OOB write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional exec…

Mitigation only
Fix from $2,300 2019-09-27
Android CRITICAL 9.8
CVE-2019-9365

In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional…

Mitigation only
Fix from $2,300 2019-09-27
Android CRITICAL 9.8
CVE-2019-9301

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional executi…

Mitigation only
Fix from $2,300 2019-09-27
Nest Cam Iq Indoor Firmware CRITICAL 9.0
CVE-2019-5035

An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set …

No fix yet
Fix from $2,300 2019-08-20
Android CRITICAL 9.8
CVE-2019-2130

In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type confusion. This could lead to escalation of priv…

Mitigation only
Fix from $2,300 2019-08-20
Voice Builder CRITICAL 9.8
CVE-2019-1010200

Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is affected by: CWE-78: Improper …

Patch available
Fix from $2,300 2019-07-23
Android CRITICAL 9.8
CVE-2019-2111

In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remote code execution in the netd…

Mitigation only
Fix from $2,300 2019-07-08
Android CRITICAL 9.8
CVE-2019-2006

In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of priv…

Mitigation only
Fix from $2,300 2019-06-19
Android CRITICAL 9.8
CVE-2019-2007

In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to l…

Mitigation only
Fix from $2,300 2019-06-19
Android CRITICAL 9.8
CVE-2019-2097

In HAliasAnalyzer.Query of hydrogen-alias-analysis.h, there is possible memory corruption due to type confusion. This could lead to remote code execu…

Mitigation only
Fix from $2,300 2019-06-07
Android CRITICAL 9.8
CVE-2019-2047

In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy a…

Mitigation only
Fix from $2,300 2019-05-08
Android CRITICAL 9.8
CVE-2019-2045

In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote code execution in the proxy a…

Mitigation only
Fix from $2,300 2019-05-08
Android CRITICAL 9.8
CVE-2019-2046

In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. This could lead to remote code…

Mitigation only
Fix from $2,300 2019-05-08
Tensorflow CRITICAL 9.8
CVE-2018-7575

Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.

Fix: after 1.7.0
Fix from $2,300 2019-04-24
Android CRITICAL 9.8
CVE-2019-2030

In removeInterfaceAddress of NetworkController.cpp, there is a possible use after free. This could lead to remote code execution with no additional e…

Patch available
Fix from $2,300 2019-04-19
Chrome CRITICAL 9.6
CVE-2019-5759

Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentiall…

Fix: 72.0.3626.81+
Fix from $2,300 2019-02-19
Android CRITICAL 9.8
CVE-2018-9583

In bta_ag_parse_cmer of bta_ag_cmd.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out-o…

Mitigation only
Fix from $2,300 2019-02-11
Chrome CRITICAL 9.6
CVE-2018-6127

Early free of object in use in IndexDB in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to p…

Fix: 67.0.3396.62+
Fix from $2,300 2019-01-09
Chrome CRITICAL 9.6
CVE-2018-16068

Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM…

Fix: 69.0.3497.81+
Fix from $2,300 2019-01-09
Chrome CRITICAL 9.6
CVE-2017-15402

Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same proces…

Fix: 62.0.3202.74+
Fix from $2,300 2019-01-09
Android CRITICAL 9.8
CVE-2018-9578

In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write due to a missing bounds check. This could lead t…

Mitigation only
Fix from $2,300 2018-12-07
Android CRITICAL 9.8
CVE-2018-11905

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buffer overflow in WLAN function …

Patch available
Fix from $2,300 2018-12-07
Android CRITICAL 9.8
CVE-2018-9556

In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalatio…

Patch available
Fix from $2,300 2018-12-06
Chrome CRITICAL 9.6
CVE-2018-6152

The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome pri…

Fix: 66.0.3359.106+
Fix from $2,300 2018-12-04
Gvisor CRITICAL 9.8
CVE-2018-19333

pkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in processes running as root (but not …

Fix: 2018-11-01+
Fix from $2,300 2018-11-17
Android CRITICAL 9.8
CVE-2018-9580

A Elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-76222002.

No fix yet
Fix from $2,300 2018-11-14
Chrome CRITICAL 9.6
CVE-2018-17462

Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox escape via a crafted HTML pag…

Fix: 70.0.3538.67+
Fix from $2,300 2018-11-14
Chrome CRITICAL 9.6
CVE-2018-17472

Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the <if…

Fix: 70.0.3538.67+
Fix from $2,300 2018-11-14
Android CRITICAL 9.8
CVE-2018-9446

In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This could lead to remote code exe…

Patch available
Fix from $2,300 2018-11-06