Vulnerability index

Browse CVEs

617 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
HIGH 7.5 CVE-2015-1232 Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows … Chrome after 40.0.2214.115 Fix from $1,9502015-03-09 MEDIUM 5.0 CVE-2015-1225 PDFium, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vecto… Chrome after 40.0.2214.115 Fix from $1,6002015-03-09 HIGH 7.5 CVE-2015-1213 The SkBitmap::ReadRawPixels function in core/SkBitmap.cpp in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows… Chrome after 40.0.2214.115 Fix from $1,9502015-03-09 HIGH 7.5 CVE-2015-1360 Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif… Chrome after 40.0.2214.85 Fix from $1,9502015-01-27 MEDIUM 5.0 CVE-2014-7946 The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrome before 40.0.2214.91, skips … Chrome after 40.0.2214.85 Fix from $1,6002015-01-22 MEDIUM 5.0 CVE-2014-7947 OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds re… Chrome after 40.0.2214.85 Fix from $1,6002015-01-22 MEDIUM 5.0 CVE-2014-7945 OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds re… Chrome after 40.0.2214.85 Fix from $1,6002015-01-22 MEDIUM 5.0 CVE-2014-7944 The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 40.0.2214.91, does not properly handle o… Chrome after 40.0.2214.85 Fix from $1,6002015-01-22 HIGH 7.5 CVE-2014-7938 The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly ha… Chrome after 40.0.2214.85 Fix from $1,9502015-01-22 HIGH 7.5 CVE-2014-7937 Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to … Chrome after 40.0.2214.85 Fix from $1,9502015-01-22 HIGH 7.5 CVE-2014-7904 Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecif… Chrome after 39.0.2171.45 Fix from $1,9502014-11-19 HIGH 7.5 CVE-2014-7903 Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of servic… Chrome after 39.0.2171.45 Fix from $1,9502014-11-19 MEDIUM 5.0 CVE-2014-3201 core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a c… Chrome after 38.0.2125.101 Fix from $1,6002014-10-10 MEDIUM 5.0 CVE-2014-3198 The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 valu… Chrome after 38.0.2125.7 Fix from $1,6002014-10-08 MEDIUM 5.0 CVE-2014-3173 The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls interact properly with the state of a draw buffer, whi… Chrome after 37.0.2062.93 Fix from $1,6002014-08-27 MEDIUM 5.0 CVE-2014-3174 modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly co… Chrome after 37.0.2062.93 Fix from $1,6002014-08-27 MEDIUM 5.1 CVE-2014-3100 Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arb… Android No fix yet Fix from $1,6002014-07-02 HIGH 9.3 CVE-2013-3662EPSS 32% Timbre SketchUp (formerly Google SketchUp) before 8 Maintenance 2 allows remote attackers to execute arbitrary code via a crafted color palette table… Sketchup after 8.0 Fix from $1,9502014-07-01 HIGH 9.3 CVE-2013-3664EPSS 30% Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette tab… Sketchup after 8.0 Fix from $1,9502014-07-01 HIGH 9.3 CVE-2013-7388EPSS 13% Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to ex… Sketchup after 8.0 Fix from $1,9502014-07-01 HIGH 9.3 CVE-2013-3663EPSS 32% Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 8 Maintenance 3, allows remote attackers to exe… Sketchup after 8.0 Fix from $1,9502014-06-13 HIGH 7.5 CVE-2014-3156 Buffer overflow in the clipboard implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibl… Chrome after 35.0.1916.152 Fix from $1,9502014-06-11 HIGH 7.5 CVE-2014-3157 Heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function in media/filters/ffmpeg_video_decoder.cc in Google Chrome before 35.0.1… Chrome after 35.0.1916.152 Fix from $1,9502014-06-11 MEDIUM 5.0 CVE-2014-1746 The InMemoryUrlProtocol::Read function in media/filters/in_memory_url_protocol.cc in Google Chrome before 35.0.1916.114 relies on an insufficiently l… Chrome after 35.0.1916.113 Fix from $1,6002014-05-21 HIGH 7.5 CVE-2014-1710 The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS befo… Chrome Os after 33.0.1750.149 Fix from $1,9502014-03-16 HIGH 7.5 CVE-2014-1711 The GPU driver in the kernel in Google Chrome OS before 33.0.1750.152 allows remote attackers to cause a denial of service (out-of-bounds write) or p… Chrome Os after 33.0.1750.149 Fix from $1,9502014-03-16 HIGH 7.5 CVE-2013-6665 Heap-based buffer overflow in the ResourceProvider::InitializeSoftware function in cc/resources/resource_provider.cc in Google Chrome before 33.0.175… Chrome after 33.0.1750.144 Fix from $1,9502014-03-05 HIGH 7.5 CVE-2013-5349 Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag … Picasa Mitigation only Fix from $1,9502014-01-09 HIGH 7.5 CVE-2013-5357 Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that… Picasa Mitigation only Fix from $1,9502014-01-09 HIGH 7.5 CVE-2013-5358 Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to trigger memory corruption via a crafted TIFF tag, as demonstrated u… Picasa Mitigation only Fix from $1,9502014-01-09