Vulnerability index

Browse CVEs

1,003 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2020-6509 Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to pot… Chrome 83.0.4103.116+ Fix from $2,3002020-07-22 CRITICAL 9.6 CVE-2020-6522 Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a … Chrome 84.0.4147.89+ Fix from $2,3002020-07-22 CRITICAL 9.6 CVE-2020-6505 Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML… Chrome 83.0.4103.106+ Fix from $2,3002020-07-22 CRITICAL 9.8 CVE-2020-0224 In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion. This could lead to remote code executio… Android Patch available Fix from $2,3002020-07-17 CRITICAL 9.8 CVE-2020-0225 In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to a missing bounds check. This… Android Patch available Fix from $2,3002020-07-17 CRITICAL 9.8 CVE-2020-0230 There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156337262 Android Mitigation only Fix from $2,3002020-07-17 CRITICAL 9.8 CVE-2020-0231 There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156333727 Android Mitigation only Fix from $2,3002020-07-17 CRITICAL 9.1 CVE-2020-7692 PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by… Oauth Client Library For Java 1.31.0+ Fix from $2,3002020-07-09 CRITICAL 9.8 CVE-2020-0223 This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-1351304… Android Mitigation only Fix from $2,3002020-06-16 CRITICAL 9.8 CVE-2020-0232 Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it. A concurrent thread co… Android Mitigation only Fix from $2,3002020-06-16 CRITICAL 9.8 CVE-2020-0235 In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_use… Android Mitigation only Fix from $2,3002020-06-16 CRITICAL 9.8 CVE-2020-0217 In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution … Android Patch available Fix from $2,3002020-06-11 CRITICAL 9.8 CVE-2020-0201 In showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy. This could lead to remote escalation… Android Patch available Fix from $2,3002020-06-11 CRITICAL 9.8 CVE-2020-0138 In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio… Android Patch available Fix from $2,3002020-06-11 CRITICAL 9.8 CVE-2020-0117 In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluet… Android Patch available Fix from $2,3002020-06-10 CRITICAL 9.8 CVE-2020-13839 An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT comman… Android Mitigation only Fix from $2,3002020-06-05 CRITICAL 9.8 CVE-2020-13840 An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via an MTK AT command … Android Mitigation only Fix from $2,3002020-06-05 CRITICAL 9.8 CVE-2020-13841 An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets). An AT command handler allows attackers to bypass intended acces… Android Mitigation only Fix from $2,3002020-06-05 CRITICAL 9.8 CVE-2020-13831 An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic Kinibi component allows arbit… Android Mitigation only Fix from $2,3002020-06-04 CRITICAL 9.8 CVE-2020-13832 An issue was discovered on Samsung mobile devices with Q(10.0) (with TEEGRIS on Exynos chipsets) software. The Widevine Trustlet allows arbitrary cod… Android Mitigation only Fix from $2,3002020-06-04 CRITICAL 9.8 CVE-2020-13835 An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user cr… Android Mitigation only Fix from $2,3002020-06-04 CRITICAL 9.1 CVE-2020-13833 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a s… Android Mitigation only Fix from $2,3002020-06-04 CRITICAL 9.6 CVE-2020-6493 Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to pote… Chrome 83.0.4103.97+ Fix from $2,3002020-06-03 CRITICAL 9.6 CVE-2020-6471 Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic… Chrome 83.0.4103.61+ Fix from $2,3002020-05-21 CRITICAL 9.6 CVE-2020-6461 Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially p… Chrome 81.0.4044.129+ Fix from $2,3002020-05-21 CRITICAL 9.6 CVE-2020-6462 Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to poten… Chrome 81.0.4044.129+ Fix from $2,3002020-05-21 CRITICAL 9.6 CVE-2020-6465 Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to… Chrome 83.0.4103.61+ Fix from $2,3002020-05-21 CRITICAL 9.6 CVE-2020-6466 Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perf… Chrome 83.0.4103.61+ Fix from $2,3002020-05-21 CRITICAL 9.6 CVE-2020-6469 Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic… Chrome 83.0.4103.61+ Fix from $2,3002020-05-21 CRITICAL 9.6 CVE-2020-6457 Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a c… Chrome 81.0.4044.113+ Fix from $2,3002020-05-21