Vulnerability index

Browse CVEs

617 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Android HIGH 10.0
CVE-2015-6608

mediaserver in Android 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of servi…

Fix: 5.1.1+
Fix from $1,950 2015-11-03
Android HIGH 10.0
CVE-2015-7716

libstagefright in Android 5.x before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-6604

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-6603

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-6601

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-6600

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-6599

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3877

Skia, as used in Android before 5.1.1 LMY48T, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3875

libutils in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf…

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3874

The Sonivox components in Android before 5.1.1 LMY48T allow remote attackers to execute arbitrary code or cause a denial of service (memory corruptio…

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3873

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3872

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3871

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3869

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3870

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3868

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3867

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3823

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 9.3
CVE-2015-3842

Multiple heap-based buffer overflows in libeffects in the Audio Policy Service in mediaserver in Android before 5.1.1 LMY48I allow attackers to execu…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3835

Buffer overflow in the OMXNodeInstance::emptyBuffer function in omx/OMXNodeInstance.cpp in libstagefright in Android before 5.1.1 LMY48I allows attac…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3832

Multiple buffer overflows in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3831

Buffer overflow in the readAt function in BpMediaHTTPConnection in media/libmedia/IMediaHTTPConnection.cpp in the mediaserver service in Android befo…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3828EPSS 85%

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3827EPSS 81%

The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relationship bet…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android MEDIUM 5.0
CVE-2015-3826EPSS 74%

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size…

Fix: after 5.1
Fix from $1,600 2015-10-01
Android HIGH 10.0
CVE-2015-3824EPSS 90%

The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size additi…

Fix: after 5.1
Fix from $1,950 2015-10-01
Chrome HIGH 7.5
CVE-2015-1280

SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) o…

Fix: after 43.0.2357.134
Fix from $1,950 2015-07-23
Chrome MEDIUM 6.8
CVE-2015-1271

PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cau…

Fix: after 43.0.2357.134
Fix from $1,600 2015-07-23
Chrome HIGH 7.5
CVE-2015-1252

common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sand…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Chrome HIGH 7.5
CVE-2015-1238

Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspe…

Fix: after 42.0.2311.60
Fix from $1,950 2015-04-19