Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android MEDIUM 5.5
CVE-2022-20592

In ppmp_validate_secbuf of drm_fw.c, there is a possible information disclosure due to improper input validation. This could lead to local informatio…

Mitigation only
Fix from $1,600 2022-12-16
Android HIGH 7.5
CVE-2022-20545

In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input validation. This could lead to re…

Patch available
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20507

In onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due to a missing bounds check. Thi…

Patch available
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20512

In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation. This cou…

Mitigation only
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20470

In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation…

Mitigation only
Fix from $1,950 2022-12-13
Tensorflow HIGH 7.5
CVE-2022-41909

TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVariant` tensor will trigger a seg…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41908

TensorFlow is an open source platform for machine learning. An input `token` that is not a UTF-8 bytestring will trigger a `CHECK` fail in `tf.raw_op…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41901

TensorFlow is an open source platform for machine learning. An input `sparse_matrix` that is not a matrix with a shape with rank 0 will trigger a `CH…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41898

TensorFlow is an open source platform for machine learning. If `SparseFillEmptyRowsGrad` is given empty inputs, TensorFlow will crash. We have patche…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41899

TensorFlow is an open source platform for machine learning. Inputs `dense_features` or `example_state_data` not of rank 2 will trigger a `CHECK` fail…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41896

TensorFlow is an open source platform for machine learning. If `ThreadUnsafeUnigramCandidateSampler` is given input `filterbank_channel_count` greate…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41891

TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListConcat` is given `element_shape=[]`, it results segmentation fau…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41888

TensorFlow is an open source platform for machine learning. When running on GPU, `tf.image.generate_bounding_box_proposals` receives a `scores` input…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Android MEDIUM 6.7
CVE-2022-20459

In (TBD) of (TBD), there is a possible way to redirect code execution due to improper input validation. This could lead to local escalation of privil…

No fix yet
Fix from $1,600 2022-11-17
Android HIGH 7.8
CVE-2022-39880

Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code exec…

Mitigation only
Fix from $1,950 2022-11-09
Android MEDIUM 5.5
CVE-2022-20457

In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to improper input validation. This …

Mitigation only
Fix from $1,600 2022-11-08
Chrome HIGH 8.8
CVE-2022-3656

Insufficient data validation in File System in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass file system restrictions via …

Fix: 107.0.5304.62+
Fix from $1,950 2022-11-01
Google Protobuf HIGH 7.5
CVE-2022-3171

A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service a…

Fix: 3.16.3 / 3.19.6+
Fix from $1,950 2022-10-12
Android HIGH 7.5
CVE-2022-32591

In ril, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service with no additional execution p…

Mitigation only
Fix from $1,950 2022-10-07
Chrome CRITICAL 9.6
CVE-2022-3075 KEVEPSS 6%

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to p…

Fix: 105.0.5195.102+
Fix from $2,300 2022-09-26
Chrome MEDIUM 5.4
CVE-2022-3201

Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user…

Fix: 105.0.5195.125+
Fix from $1,600 2022-09-26
Chrome MEDIUM 6.5
CVE-2022-2856 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily br…

Fix: 104.0.5112.101 / 104.0.5112.102+
Fix from $1,600 2022-09-26
Tensorflow HIGH 7.5
CVE-2022-36017

TensorFlow is an open source platform for machine learning. If `Requantize` is given `input_min`, `input_max`, `requested_output_min`, `requested_out…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-36027

TensorFlow is an open source platform for machine learning. When converting transposed convolutions using per-channel weight quantization the convert…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35979

TensorFlow is an open source platform for machine learning. If `QuantizedRelu` or `QuantizedRelu6` are given nonscalar inputs for `min_features` or `…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35982

TensorFlow is an open source platform for machine learning. If `SparseBincount` is given inputs for `indices`, `values`, and `dense_shape` that do no…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35986

TensorFlow is an open source platform for machine learning. If `RaggedBincount` is given an empty input tensor `splits`, it results in a segfault tha…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35966

TensorFlow is an open source platform for machine learning. If `QuantizedAvgPool` is given `min_input` or `max_input` tensors of a nonzero rank, it r…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35967

TensorFlow is an open source platform for machine learning. If `QuantizedAdd` is given `min_input` or `max_input` tensors of a nonzero rank, it resul…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35970

TensorFlow is an open source platform for machine learning. If `QuantizedInstanceNorm` is given `x_min` or `x_max` tensors of a nonzero rank, it resu…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16