Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Chrome HIGH 8.1
CVE-2019-5755

Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform arbitrary read/write via a craf…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Android HIGH 7.8
CVE-2014-9924

In 1x in all Android releases from CAF using the Linux kernel, a Signed to Unsigned Conversion Error could potentially occur.

Patch available
Fix from $1,950 2017-06-06
Android HIGH 7.8
CVE-2015-9002

In TrustZone an out-of-range pointer offset vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux ker…

Patch available
Fix from $1,950 2017-05-16
Android HIGH 7.8
CVE-2014-9876

drivers/char/diag/diagfwd.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices mishandles certain in…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2016-2507

Integer overflow in codecs/on2/h264dec/source/h264bsd_storage.c in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2015-8891

Multiple integer overflows in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attacke…

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2015-8888

Integer overflow in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allows attackers to bypass intended …

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2014-9801

Multiple integer overflows in lib/libfdt/fdt_rw.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allow attackers to gain …

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2014-9800

Integer overflow in lib/heap/heap.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attackers to gain …

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2014-9795

app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices does not properly check for an integer overflow, which a…

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2014-9792

arch/arm/mach-msm/ipc_router.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices uses an incorrect integer data type, which …

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2014-9787

Integer overflow in drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices allows attackers to gain…

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 8.4
CVE-2016-2463

Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 8.4
CVE-2016-0849

Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01…

Patch available
Fix from $1,950 2016-04-18
Android HIGH 7.8
CVE-2016-0827

Multiple integer overflows in libeffects in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allow attacke…

Mitigation only
Fix from $1,950 2016-03-12
Chrome HIGH 8.8
CVE-2015-8664EPSS 5%

Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote at…

Fix: after 47.0.2526.80
Fix from $1,950 2015-12-24
Chrome HIGH 7.5
CVE-2015-6781

Integer overflow in the FontData::Bound function in data/font_data.cc in Google sfntly, as used in Google Chrome before 47.0.2526.73, allows remote a…

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Picasa HIGH 10.0
CVE-2015-8221

Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, wh…

Fix: after 3.9.140
Fix from $1,950 2015-11-17
Picasa HIGH 10.0
CVE-2015-8096

Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related t…

Mitigation only
Fix from $1,950 2015-11-09
Android HIGH 10.0
CVE-2015-6575

SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly consider integer promotion, which allows remote attackers to execu…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3864EPSS 87%

Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M al…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3863

Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android MEDIUM 5.0
CVE-2015-3861

Multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in libstagefright in mediaserver in Android before 5.…

Fix: after 5.1
Fix from $1,600 2015-10-01
Android HIGH 10.0
CVE-2015-3836

The Parse_wave function in arm-wt-22k/lib_src/eas_mdls.c in the Sonivox DLS-to-EAS converter in Android before 5.1.1 LMY48I does not reject a negativ…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3834

Multiple integer overflows in the BnHDCP::onTransact function in media/libmedia/IHDCP.cpp in libstagefright in Android before 5.1.1 LMY48I allow atta…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3829EPSS 90%

Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote atta…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3828EPSS 85%

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3827EPSS 81%

The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relationship bet…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android MEDIUM 5.0
CVE-2015-3826EPSS 74%

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size…

Fix: after 5.1
Fix from $1,600 2015-10-01
Android HIGH 10.0
CVE-2015-1539EPSS 86%

Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attacke…

Fix: after 5.1
Fix from $1,950 2015-10-01