Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android MEDIUM 6.5
CVE-2021-25416

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel…

Mitigation only
Fix from $1,600 2021-06-11
Android MEDIUM 5.5
CVE-2021-25413

Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbi…

No fix yet
Fix from $1,600 2021-06-11
Android MEDIUM 5.5
CVE-2021-25415

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writ…

Mitigation only
Fix from $1,600 2021-06-11
Tensorflow MEDIUM 5.5
CVE-2021-29611

TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseReshape` results in a denial of service based …

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Chrome MEDIUM 6.5
CVE-2021-21208

Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain s…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21221

Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer …

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Android MEDIUM 5.5
CVE-2021-0400

In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency se…

Patch available
Fix from $1,600 2021-04-13
Android HIGH 8.8
CVE-2021-25356

An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary a…

No fix yet
Fix from $1,950 2021-04-09
Exposure Notifications Verification Server HIGH 8.8
CVE-2021-22538

A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker wh…

Fix: 0.23.1+
Fix from $1,950 2021-03-31
Android MEDIUM 5.5
CVE-2021-0377

In DeltaPerformer::Write of delta_performer.cc, there is a possible use of untrusted input due to improper input validation. This could lead to a loc…

Mitigation only
Fix from $1,600 2021-03-10
Android MEDIUM 5.5
CVE-2021-25334

Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent d…

Mitigation only
Fix from $1,600 2021-03-04
Android MEDIUM 5.2
CVE-2021-25338

Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to wr…

Mitigation only
Fix from $1,600 2021-03-04
Android MEDIUM 5.2
CVE-2021-25339

Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corr…

Mitigation only
Fix from $1,600 2021-03-04
Chrome MEDIUM 6.5
CVE-2021-21126EPSS 9%

Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Chrome MEDIUM 6.5
CVE-2021-21123EPSS 10%

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions vi…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Android MEDIUM 6.7
CVE-2021-0345

In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,600 2021-02-04
Android HIGH 7.5
CVE-2020-0236

In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation. This could lead to remote informa…

Mitigation only
Fix from $1,950 2021-01-26
Android HIGH 7.5
CVE-2021-0313

In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remo…

Patch available
Fix from $1,950 2021-01-11
Android MEDIUM 5.0
CVE-2021-0322

In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to loc…

Patch available
Fix from $1,600 2021-01-11
Android CRITICAL 9.8
CVE-2020-0471

In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper …

Patch available
Fix from $2,300 2021-01-11
Chrome MEDIUM 6.5
CVE-2020-16040EPSS 100%

Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 87.0.4280.88+
Fix from $1,600 2021-01-08
Chrome HIGH 8.8
CVE-2020-16015

Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 87.0.4280.66+
Fix from $1,950 2021-01-08
Android MEDIUM 6.5
CVE-2020-27029

In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2020-12-15
Android MEDIUM 5.5
CVE-2020-0493

In CPDF_SampledFunc::v_Call of cpdf_sampledfunc.cpp, there is a possible out of bounds read due to improper input validation. This could lead to loca…

Mitigation only
Fix from $1,600 2020-12-15
Android HIGH 7.5
CVE-2020-0442

In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote de…

Patch available
Fix from $1,950 2020-11-10
Chrome HIGH 8.8
CVE-2020-15978

Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the render…

Fix: 86.0.4240.75+
Fix from $1,950 2020-11-03
Chrome HIGH 7.8
CVE-2020-15983

Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy v…

Fix: 86.0.4240.75+
Fix from $1,950 2020-11-03
Chrome MEDIUM 6.5
CVE-2020-15977

Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive info…

Fix: 86.0.4240.75+
Fix from $1,600 2020-11-03
Android HIGH 7.5
CVE-2020-26597

An issue was discovered on LG mobile devices with Android OS 9.0 and 10 software. The Wi-Fi subsystem has incorrect input validation, leading to a cr…

Mitigation only
Fix from $1,950 2020-10-06
Tensorflow MEDIUM 6.5
CVE-2020-15210

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25