Vulnerability index

Browse CVEs

617 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Android MEDIUM 5.5
CVE-2022-42775

In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2022-12-06
Android MEDIUM 5.5
CVE-2022-39131

In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2022-12-06
Android MEDIUM 5.5
CVE-2022-38690

In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.

No fix yet
Fix from $1,600 2022-10-14
Android CRITICAL 9.8
CVE-2022-20238

'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be cont…

Patch available
Fix from $2,300 2022-07-13
Android HIGH 7.5
CVE-2022-20236

A drm driver have oob problem, could cause the system crash or EOPProduct: AndroidVersions: Android SoCAndroid ID: A-233124709

Patch available
Fix from $1,950 2022-07-13
Android HIGH 7.8
CVE-2021-39798

In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escala…

Mitigation only
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2021-39693

In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due to a logic error in the code. …

Patch available
Fix from $1,950 2022-03-16
Android CRITICAL 9.8
CVE-2022-25818

Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.

Mitigation only
Fix from $2,300 2022-03-10
Android MEDIUM 5.5
CVE-2021-39633

In gre_handle_offloads of ip_gre.c, there is a possible page fault due to an invalid memory access. This could lead to local information disclosure w…

Patch available
Fix from $1,600 2022-01-14
Android MEDIUM 6.7
CVE-2021-25518

An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.

Mitigation only
Fix from $1,600 2021-12-08
Android CRITICAL 9.8
CVE-2021-25449

An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in …

Mitigation only
Fix from $2,300 2021-09-09
Android CRITICAL 10.0
CVE-2021-25387

An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to exec…

Mitigation only
Fix from $2,300 2021-06-11
Android CRITICAL 9.8
CVE-2021-25383

An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers to execut…

Mitigation only
Fix from $2,300 2021-06-11
Android CRITICAL 9.8
CVE-2021-25385

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers …

Mitigation only
Fix from $2,300 2021-06-11
Android CRITICAL 9.8
CVE-2021-25386

An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers …

Mitigation only
Fix from $2,300 2021-06-11
Chrome HIGH 8.8
CVE-2021-30530

Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a…

Fix: 91.0.4472.77+
Fix from $1,950 2021-06-07
Tensorflow HIGH 7.8
CVE-2021-29576

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPool3DGradGrad` is vulnerable to a heap b…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29577

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.AvgPool3DGrad` is vulnerable to a heap buffe…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29578

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalAvgPoolGrad` is vulnerable to a he…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29579

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGrad` is vulnerable to a heap buffer …

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29575

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.ReverseSequence` allows for stack overflow a…

Fix: 2.2.3 / 2.3.3+
Fix from $1,600 2021-05-14
Chrome MEDIUM 6.8
CVE-2021-21140

Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a…

Fix: 88.0.705.74 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Chrome HIGH 8.8
CVE-2021-21118EPSS 17%

Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory acces…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,950 2021-02-09
Asylo HIGH 7.8
CVE-2020-8935

An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to reallocate untr…

Fix: after 0.6.0
Fix from $1,950 2020-12-15
Tensorflow HIGH 7.5
CVE-2020-15266

In Tensorflow before version 2.4.0, when the `boxes` argument of `tf.image.crop_and_resize` has a very large value, the CPU kernel implementation rec…

Fix: 2.4.0+
Fix from $1,950 2020-10-21
Tensorflow CRITICAL 9.8
CVE-2020-15205

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This a…

Fix: 1.15.4 / 2.0.3+
Fix from $2,300 2020-09-25
Tensorflow CRITICAL 9.0
CVE-2020-15207

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative values, TFLite uses `ResolveAxis` …

Fix: 1.15.4 / 2.0.3+
Fix from $2,300 2020-09-25
Tensorflow MEDIUM 5.4
CVE-2020-15198

In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tenso…

Fix: 2.3.1+
Fix from $1,600 2020-09-25
Tensorflow CRITICAL 9.9
CVE-2020-15196

In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate that the `weights` tensor has…

Patch available
Fix from $2,300 2020-09-25
Tensorflow HIGH 8.8
CVE-2020-15195

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` uses a double indexing pattern. …

Fix: 1.15.4 / 2.0.3+
Fix from $1,950 2020-09-25