Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android HIGH 7.8
CVE-2021-25510

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.

Mitigation only
Fix from $1,950 2021-12-08
Android HIGH 7.8
CVE-2021-25511

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal…

Mitigation only
Fix from $1,950 2021-12-08
Android HIGH 7.8
CVE-2021-25512

An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $1,950 2021-12-08
Chrome MEDIUM 6.1
CVE-2021-38000 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily brow…

Fix: 95.0.4638.69+
Fix from $1,600 2021-11-23
Android MEDIUM 6.7
CVE-2021-25503

Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.

Mitigation only
Fix from $1,600 2021-11-05
Chrome MEDIUM 5.5
CVE-2021-37996

Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictio…

Fix: 95.0.4638.54+
Fix from $1,600 2021-11-02
Android MEDIUM 5.5
CVE-2021-0651

In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to incorrect input validation. Thi…

Mitigation only
Fix from $1,600 2021-10-22
Android HIGH 8.0
CVE-2021-25485

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote so…

Mitigation only
Fix from $1,950 2021-10-06
Android HIGH 7.5
CVE-2021-25471

A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network c…

Mitigation only
Fix from $1,950 2021-10-06
Android MEDIUM 5.5
CVE-2021-25453

Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 6.5
CVE-2021-25450

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socke…

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25452

An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent …

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-0416

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no ad…

Mitigation only
Fix from $1,600 2021-08-18
Android MEDIUM 5.5
CVE-2021-0417

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no ad…

Mitigation only
Fix from $1,600 2021-08-18
Android MEDIUM 5.5
CVE-2021-0418

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no ad…

Mitigation only
Fix from $1,600 2021-08-18
Android MEDIUM 5.5
CVE-2021-0419

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no ad…

Mitigation only
Fix from $1,600 2021-08-18
Tensorflow MEDIUM 5.5
CVE-2021-37677

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the shape inference code for `tf.raw_ops.Dequantize` has …

Fix: 2.3.4 / 2.4.3+
Fix from $1,600 2021-08-12
Tensorflow MEDIUM 5.5
CVE-2021-37692

TensorFlow is an end-to-end open source platform for machine learning. In affected versions under certain conditions, Go code can trigger a segfault …

Fix: 2.6.0+
Fix from $1,600 2021-08-12
Tensorflow HIGH 7.8
CVE-2021-37663

TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation in `tf.raw_ops.QuantizeV2`, …

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12
Tensorflow HIGH 7.8
CVE-2021-37665

TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation in MKL implementation of req…

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12
Tensorflow MEDIUM 5.5
CVE-2021-37673

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a `CHECK`…

Fix: 2.3.4 / 2.4.3+
Fix from $1,600 2021-08-12
Tensorflow MEDIUM 5.5
CVE-2021-37674

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a segment…

Fix: 2.3.4 / 2.4.3+
Fix from $1,600 2021-08-12
Android MEDIUM 5.5
CVE-2021-25444

An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.

Mitigation only
Fix from $1,600 2021-08-05
Android HIGH 7.8
CVE-2021-0600

In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input validation. This c…

Mitigation only
Fix from $1,950 2021-07-14
Android HIGH 7.8
CVE-2021-25428

Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permi…

Mitigation only
Fix from $1,950 2021-07-08
Android HIGH 7.8
CVE-2021-0511

In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalatio…

Patch available
Fix from $1,950 2021-06-21
Android HIGH 7.8
CVE-2021-0481

In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could le…

Patch available
Fix from $1,950 2021-06-11
Android HIGH 7.8
CVE-2021-0485

In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to a permissions bypass. This co…

Patch available
Fix from $1,950 2021-06-11
Android HIGH 7.8
CVE-2021-25414

Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary fi…

No fix yet
Fix from $1,950 2021-06-11
Android HIGH 7.1
CVE-2021-25410

Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an esc…

No fix yet
Fix from $1,950 2021-06-11