Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chrome MEDIUM 6.5
CVE-2019-5801

Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted…

Fix: 73.0.3683.75+
Fix from $1,600 2019-05-23
Chrome MEDIUM 6.5
CVE-2019-5803

Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content securit…

Fix: 73.0.3683.75+
Fix from $1,600 2019-05-23
Chrome MEDIUM 6.5
CVE-2019-5793

Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installatio…

Fix: 73.0.3683.75+
Fix from $1,600 2019-05-23
Android HIGH 7.5
CVE-2019-2051

In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when p…

Mitigation only
Fix from $1,950 2019-05-08
Android HIGH 7.8
CVE-2018-6243

NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of video metadata count may lead t…

Mitigation only
Fix from $1,950 2019-05-07
Snappy HIGH 8.1
CVE-2018-7577

Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts …

Fix: 1.7.1+
Fix from $1,950 2019-04-24
Android HIGH 8.8
CVE-2019-2028

In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code execution with no additional executi…

Patch available
Fix from $1,950 2019-04-19
Android HIGH 8.8
CVE-2019-1988

In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in s…

Mitigation only
Fix from $1,950 2019-02-28
Chrome HIGH 8.8
CVE-2019-5783

Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Inj…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 7.8
CVE-2019-5780

Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute J…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 8.8
CVE-2019-5769

Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker t…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Android HIGH 7.8
CVE-2018-6267

NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software does not validate or incorrectly validates input that can affec…

No fix yet
Fix from $1,950 2019-02-13
Android HIGH 7.8
CVE-2018-6241

NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lea…

Mitigation only
Fix from $1,950 2019-01-31
Chrome MEDIUM 6.5
CVE-2018-6160

JavaScript alert handling in Prompts in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) …

Fix: 68.0.3440.75+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6169

Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of…

Fix: 68.0.3440.75+
Fix from $1,600 2019-01-09
Chrome HIGH 8.8
CVE-2018-6139

Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to …

Fix: 67.0.3396.62+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-6140

Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a use…

Fix: 67.0.3396.62+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-6111

An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local attacker to execute arbitrary…

Fix: 66.0.3359.117+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6113

Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform dom…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6114

Incorrect enforcement of CSP for <object> tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass content security …

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 5.4
CVE-2018-6110

Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a loc…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6096

A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome HIGH 8.8
CVE-2018-20065

Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to initiate potentially unsafe navigations without …

Fix: 71.0.3578.80+
Fix from $1,950 2019-01-09
Chrome HIGH 7.8
CVE-2018-6084

Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrar…

Fix: 66.0.3359.117+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-20070

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents o…

Fix: 71.0.3578.80+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16080

A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the conten…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16088

A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files w…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome CRITICAL 9.6
CVE-2018-16068

Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM…

Fix: 69.0.3497.81+
Fix from $2,300 2019-01-09
Chrome CRITICAL 9.6
CVE-2017-15402

Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same proces…

Fix: 62.0.3202.74+
Fix from $2,300 2019-01-09
Gvisor MEDIUM 5.5
CVE-2018-20168

Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a den…

Fix: 2018-08-22+
Fix from $1,600 2018-12-17