Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android HIGH 7.8
CVE-2022-27833

Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2022-27835

Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.2
CVE-2022-27573

Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allow…

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.2
CVE-2022-27574

Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allow…

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2021-39763

In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39764

In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead to local escalation of privil…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39771

In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validation. This could lead to local…

Mitigation only
Fix from $1,950 2022-03-30
Android MEDIUM 5.5
CVE-2021-39778

In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This coul…

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39740

In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lead to local information disclo…

Mitigation only
Fix from $1,600 2022-03-30
Android HIGH 7.8
CVE-2021-39701

In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or pe…

Patch available
Fix from $1,950 2022-03-16
Android CRITICAL 9.8
CVE-2022-25818

Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.

Mitigation only
Fix from $2,300 2022-03-10
Android MEDIUM 6.5
CVE-2022-24925

Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of servi…

Mitigation only
Fix from $1,600 2022-02-11
Android CRITICAL 9.8
CVE-2022-23425

Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base…

Mitigation only
Fix from $2,300 2022-02-11
Android HIGH 7.1
CVE-2022-23427

PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files witho…

Mitigation only
Fix from $1,950 2022-02-11
Android MEDIUM 6.7
CVE-2022-23432

An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

Mitigation only
Fix from $1,600 2022-02-11
Android HIGH 7.8
CVE-2021-39676

In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This cou…

Mitigation only
Fix from $1,950 2022-02-11
Android MEDIUM 5.5
CVE-2022-20036

In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no a…

Mitigation only
Fix from $1,600 2022-02-09
Android MEDIUM 5.5
CVE-2022-20037

In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no a…

Mitigation only
Fix from $1,600 2022-02-09
Android MEDIUM 5.5
CVE-2022-20017

In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no a…

Mitigation only
Fix from $1,600 2022-02-09
Android HIGH 7.1
CVE-2022-22264

Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files withou…

Mitigation only
Fix from $1,950 2022-01-10
Android MEDIUM 5.5
CVE-2022-20019

In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with…

Mitigation only
Fix from $1,600 2022-01-04
Android MEDIUM 5.5
CVE-2022-20020

In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no ad…

Mitigation only
Fix from $1,600 2022-01-04
Chrome HIGH 8.8
CVE-2021-38015

Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extensio…

Fix: 96.0.4664.45+
Fix from $1,950 2021-12-23
Chrome MEDIUM 6.5
CVE-2021-4059

Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML …

Fix: 96.0.4664.93+
Fix from $1,600 2021-12-23
Android HIGH 7.3
CVE-2021-1021

In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbitrary user due to improper in…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.3
CVE-2021-1020

In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper inpu…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 8.0
CVE-2021-0933

In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to interfere with a consent dialog d…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0921

In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation.…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0928

In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. …

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-25517

An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.

Mitigation only
Fix from $1,950 2021-12-08