Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android HIGH 7.5
CVE-2017-14878

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a length variable which is used to co…

Patch available
Fix from $1,950 2018-03-15
Android HIGH 7.8
CVE-2017-6281

NVIDIA libnvomx contains a possible out of bounds write due to a improper input validation which could lead to local escalation of privilege. This is…

Mitigation only
Fix from $1,950 2018-03-12
Android HIGH 7.8
CVE-2017-15817

In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, t…

Mitigation only
Fix from $1,950 2018-02-23
Android CRITICAL 9.8
CVE-2017-13229

A remote code execution vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68160703.

Mitigation only
Fix from $2,300 2018-02-12
Chrome MEDIUM 6.5
CVE-2017-15386

Incorrect implementation in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Chrome MEDIUM 6.5
CVE-2017-15389

An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (U…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Chrome MEDIUM 6.5
CVE-2017-15390

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing via IDN homogr…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Chrome MEDIUM 6.5
CVE-2017-15394

Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permissi…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Android MEDIUM 5.7
CVE-2017-17860

In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user'…

No fix yet
Fix from $1,600 2018-01-18
Android HIGH 7.5
CVE-2017-13198

A vulnerability in the Android media framework (ex) related to composition of frames lacking a color map. Product: Android. Versions: 7.0, 7.1.1, 7.1…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.5
CVE-2017-13214

In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process w…

Mitigation only
Fix from $1,950 2018-01-12
Android HIGH 8.8
CVE-2017-13176

In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privileg…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.5
CVE-2017-13186

A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.8
CVE-2017-15845

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an invalid input of firmware size (ne…

Patch available
Fix from $1,950 2018-01-10
Android HIGH 8.8
CVE-2017-0872

A remote code execution vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-6529…

Patch available
Fix from $1,950 2017-12-06
Android HIGH 8.8
CVE-2017-0876

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-64964675.

Mitigation only
Fix from $1,950 2017-12-06
Android HIGH 8.8
CVE-2017-0877

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937.

Mitigation only
Fix from $1,950 2017-12-06
Android HIGH 8.8
CVE-2017-0878

A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 8.0. Android ID A-65186291.

Mitigation only
Fix from $1,950 2017-12-06
Android MEDIUM 6.5
CVE-2017-0873

A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android …

Mitigation only
Fix from $1,600 2017-12-06
Android MEDIUM 6.5
CVE-2017-0874

A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID…

Mitigation only
Fix from $1,600 2017-12-06
Android MEDIUM 6.5
CVE-2017-13148

A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android …

Mitigation only
Fix from $1,600 2017-12-06
Android CRITICAL 9.8
CVE-2017-14908

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the SafeSwitch test application does …

Mitigation only
Fix from $2,300 2017-12-05
Android CRITICAL 9.8
CVE-2017-14909

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a count value that is read from a fil…

No fix yet
Fix from $2,300 2017-12-05
Android CRITICAL 9.8
CVE-2017-14914

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, handles in the global client structur…

No fix yet
Fix from $2,300 2017-12-05
Android HIGH 7.5
CVE-2017-0858

Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64836894.

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-11027

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing UBI image, size is not…

Patch available
Fix from $1,950 2017-11-16
Chrome HIGH 8.8
CVE-2017-5121EPSS 5%

Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute …

Fix: 61.0.3163.100+
Fix from $1,950 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5104

Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the o…

Fix: after 60.0.3112.78
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5105

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to p…

Fix: after 60.0.3112.78
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5106

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to p…

Fix: after 60.0.3112.78
Fix from $1,600 2017-10-27