Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Tensorflow HIGH 7.5
CVE-2020-15203

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as_string, a malicious attacker…

Fix: 1.15.4 / 2.0.3+
Fix from $1,950 2020-09-25
Tensorflow HIGH 7.5
CVE-2020-15206

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of …

Fix: 1.15.4 / 2.0.3+
Fix from $1,950 2020-09-25
Tensorflow MEDIUM 5.9
CVE-2020-15199

In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` does not validate that the input arguments form a valid ragged tensor. In particula…

Patch available
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.9
CVE-2020-15200

In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input arguments form a valid ragged tenso…

Patch available
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 6.3
CVE-2020-15197

In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tenso…

Patch available
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.3
CVE-2020-15190

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a tensor and a boolean and outp…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.3
CVE-2020-15191

In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected validations will cause variabl…

Patch available
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.3
CVE-2020-15194

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the sh…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Chrome MEDIUM 6.5
CVE-2020-6567

Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to by…

Fix: 85.0.4183.83+
Fix from $1,600 2020-09-21
Chrome HIGH 8.8
CVE-2020-15964

Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a …

Fix: 85.0.4183.121+
Fix from $1,950 2020-09-21
Android MEDIUM 6.5
CVE-2020-0362

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0363

In libmedia, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional…

Mitigation only
Fix from $1,600 2020-09-17
Android CRITICAL 9.8
CVE-2020-0333

In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no additional execution privileges…

Mitigation only
Fix from $2,300 2020-09-17
Android MEDIUM 6.5
CVE-2020-0351

In libstagefright, there is possible CPU exhaustion due to improper input validation. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0353

In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additi…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0320

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0287

In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additi…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0301

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2020-09-17
Android HIGH 7.8
CVE-2020-0130

In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system pr…

Mitigation only
Fix from $1,950 2020-09-17
Android HIGH 7.5
CVE-2020-25059

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A service crash may occur because of incorrect input …

Mitigation only
Fix from $1,950 2020-08-31
Android HIGH 7.5
CVE-2020-25063

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. An application crash can occur because of incorrect a…

Mitigation only
Fix from $1,950 2020-08-31
Chrome HIGH 8.8
CVE-2020-6507EPSS 19%

Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 83.0.4103.106+
Fix from $1,950 2020-07-22
Android MEDIUM 5.5
CVE-2020-15584

An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can trigger an out-of-bounds access and device reset via a 4K wall…

Mitigation only
Fix from $1,600 2020-07-07
Android MEDIUM 6.5
CVE-2020-0207

In next_marker of jdmarker.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosu…

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 5.5
CVE-2020-0206

In the settings app, there is a possible app crash due to improper input validation. This could lead to local denial of service of the Settings app w…

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 6.5
CVE-2020-0192

In ih264d_decode_slice_thread of ih264d_thread_parse_decode.c, there is a possible out of bounds read due to improper input validation. This could le…

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 6.5
CVE-2020-0196

In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper input validation. This could …

Patch available
Fix from $1,600 2020-06-11
Android HIGH 7.8
CVE-2020-0179

In doSendObjectInfo of MtpServer.cpp, there is a possible path traversal attack due to insufficient input validation. This could lead to local escala…

Patch available
Fix from $1,950 2020-06-11
Android HIGH 7.5
CVE-2020-0176

In avdt_msg_prs_rej of avdt_msg.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information di…

Patch available
Fix from $1,950 2020-06-11
Android MEDIUM 6.5
CVE-2020-0171

In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no…

Patch available
Fix from $1,600 2020-06-11