Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Tensorflow HIGH 7.5
CVE-2022-35972

TensorFlow is an open source platform for machine learning. If `QuantizedBiasAdd` is given `min_input`, `max_input`, `min_bias`, `max_bias` tensors o…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35973

TensorFlow is an open source platform for machine learning. If `QuantizedMatMul` is given nonscalar input for: `min_a`, `max_a`, `min_b`, or `max_b` …

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35974

TensorFlow is an open source platform for machine learning. If `QuantizeDownAndShrinkRange` is given nonscalar inputs for `input_min` or `input_max`,…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35964

TensorFlow is an open source platform for machine learning. The implementation of `BlockLSTMGradV2` does not fully validate its inputs. This results …

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Android HIGH 7.8
CVE-2022-20392

In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to imp…

Patch available
Fix from $1,950 2022-09-13
Android HIGH 7.5
CVE-2022-36853

Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.

Mitigation only
Fix from $1,950 2022-09-09
Android MEDIUM 5.5
CVE-2022-36854

Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.

Mitigation only
Fix from $1,600 2022-09-09
Chrome MEDIUM 6.5
CVE-2022-2618

Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrict…

Fix: 104.0.5112.79+
Fix from $1,600 2022-08-12
Android MEDIUM 6.7
CVE-2022-20314

In KeyChain, there is a possible spoof keychain chooser activity request due to improper input validation. This could lead to local escalation of pri…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.0
CVE-2022-20266

In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to impro…

Mitigation only
Fix from $1,600 2022-08-12
Android HIGH 7.8
CVE-2022-20356

In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improp…

Patch available
Fix from $1,950 2022-08-10
Android MEDIUM 5.5
CVE-2022-20355

In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service…

Patch available
Fix from $1,600 2022-08-10
Android MEDIUM 5.5
CVE-2022-20350

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app…

Patch available
Fix from $1,600 2022-08-10
Android MEDIUM 5.5
CVE-2022-20353

In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to…

Patch available
Fix from $1,600 2022-08-10
Android CRITICAL 9.8
CVE-2022-33719

Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

Mitigation only
Fix from $2,300 2022-08-05
Android MEDIUM 5.5
CVE-2022-33715

Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of …

Mitigation only
Fix from $1,600 2022-08-05
Chrome MEDIUM 6.5
CVE-2022-1500

Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass content security policy via a c…

Fix: 101.0.4951.41+
Fix from $1,600 2022-07-26
Android HIGH 7.8
CVE-2022-33703

Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $1,950 2022-07-12
Android HIGH 7.8
CVE-2022-33704

Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $1,950 2022-07-12
Android HIGH 7.8
CVE-2022-30754

Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privile…

Mitigation only
Fix from $1,950 2022-07-12
Android HIGH 7.8
CVE-2022-30756

Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege …

Mitigation only
Fix from $1,950 2022-07-12
Android MEDIUM 5.5
CVE-2022-20205

In isFileUri of FileUtil.java, there is a possible way to bypass the check for a file:// scheme due to improper input validation. This could lead to …

Mitigation only
Fix from $1,600 2022-06-15
Android HIGH 7.8
CVE-2022-20186

In kbase_mem_alias of mali_kbase_mem_linux.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local…

No fix yet
Fix from $1,950 2022-06-15
Android HIGH 7.8
CVE-2022-20156

In unflatten of GraphicBuffer.cpp, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.8
CVE-2022-20134

In readArguments of CallSubjectDialog.java, there is a possible way to trick the user to call the wrong phone number due to improper input validation…

Mitigation only
Fix from $1,950 2022-06-15
Android MEDIUM 5.5
CVE-2022-20129

In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper inp…

Mitigation only
Fix from $1,600 2022-06-15
Android CRITICAL 9.1
CVE-2022-30711

Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $2,300 2022-06-07
Android CRITICAL 9.1
CVE-2022-30712

Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

No fix yet
Fix from $2,300 2022-06-07
Android CRITICAL 9.1
CVE-2022-30713

Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $2,300 2022-06-07
Android HIGH 7.8
CVE-2022-30726

Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to la…

Mitigation only
Fix from $1,950 2022-06-07