Vulnerability index

Browse CVEs

1,004 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Android CRITICAL 9.8
CVE-2016-6725

A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary …

Fix: after 7.0
Fix from $2,300 2016-11-25
Android CRITICAL 9.8
CVE-2016-7990

On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS mes…

Mitigation only
Fix from $2,300 2016-10-31
Android CRITICAL 9.8
CVE-2016-6696

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-6695

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-6693

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-6694

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-6692

drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm MDSS driver in Android before 2016-10-05 allows attackers to cause a denial of service (invalid …

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-6691

service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a …

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-3929

Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P devices has unknown impact and attack vectors, aka …

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-3927

Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P devices has unknown impact and attack vectors, aka …

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-3926

Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5, 5X, 6, and 6P devices has unknown impact and attack vector…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-3877

Unspecified vulnerability in Android before 2016-09-01 has unknown impact and attack vectors.

Fix: after 7.0
Fix from $2,300 2016-09-11
Chrome CRITICAL 9.8
CVE-2016-5146

Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact…

Fix: after 52.0.2743.82
Fix from $2,300 2016-08-07
Chrome CRITICAL 9.8
CVE-2016-5144

The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase…

Fix: after 52.0.2743.82
Fix from $2,300 2016-08-07
Chrome CRITICAL 9.8
CVE-2016-5143

The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase…

Fix: after 52.0.2743.82
Fix from $2,300 2016-08-07
Chrome CRITICAL 9.8
CVE-2016-5142

The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does not properly copy data buffers,…

Fix: after 52.0.2743.82
Fix from $2,300 2016-08-07
Chrome CRITICAL 9.8
CVE-2016-5140

Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allo…

Fix: after 52.0.2743.82
Fix from $2,300 2016-08-07
Android CRITICAL 9.8
CVE-2016-3840

Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-05 does not properly identify session reuse, wh…

Patch available
Fix from $2,300 2016-08-05
Android CRITICAL 9.8
CVE-2016-3821

libmedia in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 has certain incorrect declarat…

Patch available
Fix from $2,300 2016-08-05
Android CRITICAL 9.8
CVE-2016-3820

The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 mishandles slice numbers, which allows remote attackers to execute arbitrary code …

Patch available
Fix from $2,300 2016-08-05
Android CRITICAL 9.8
CVE-2016-3819

Integer overflow in codecs/on2/h264dec/source/h264bsd_dpb.c in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x b…

Patch available
Fix from $2,300 2016-08-05
Android CRITICAL 9.8
CVE-2014-9902

Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows …

Fix: after 6.0.1
Fix from $2,300 2016-08-05
Chrome CRITICAL 9.6
CVE-2016-1706

The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should h…

Fix: after 51.0.2704.106
Fix from $2,300 2016-07-23
Android CRITICAL 9.8
CVE-2016-3745

Multiple buffer overflows in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attacke…

Mitigation only
Fix from $2,300 2016-07-11
Android CRITICAL 9.8
CVE-2016-3743

decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-07-01 does not initialize certain data structures, which allows remote attackers to ex…

Mitigation only
Fix from $2,300 2016-07-11
Android CRITICAL 9.8
CVE-2016-3742

decoder/ih264d_process_intra_mb.c in mediaserver in Android 6.x before 2016-07-01 mishandles intra mode, which allows remote attackers to execute arb…

Mitigation only
Fix from $2,300 2016-07-11
Android CRITICAL 9.8
CVE-2016-3741

The H.264 decoder in mediaserver in Android 6.x before 2016-07-01 does not initialize certain slice data, which allows remote attackers to execute ar…

Mitigation only
Fix from $2,300 2016-07-11
Android CRITICAL 9.8
CVE-2016-2506

DRMExtractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does…

Mitigation only
Fix from $2,300 2016-07-11
Android CRITICAL 9.8
CVE-2016-2496

The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrar…

Patch available
Fix from $2,300 2016-06-13
Android CRITICAL 9.8
CVE-2016-2473

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka i…

Fix: after 6.0.1
Fix from $2,300 2016-06-13