Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chrome MEDIUM 6.5
CVE-2017-5110

Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windo…

Fix: 60.0.3112.78+
Fix from $1,600 2017-10-27
Chrome HIGH 8.8
CVE-2017-5092

Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to potential…

Fix: 60.0.3112.78+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5097

Insufficient validation of untrusted input in Skia in Google Chrome prior to 60.0.3112.78 for Linux allowed a remote attacker to perform an out of bo…

Fix: after 60.0.3112.76
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5099

Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially g…

Fix: after 60.0.3112.76
Fix from $1,950 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5076

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed …

Fix: 59.0.3071.86 / 59.0.3071.92+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5086

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spo…

Fix: 59.0.3071.86+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5089

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.104 for Mac allowed a remote attacker to perform domain spoofing via a…

Fix: 59.0.3071.104+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5090

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.115 for Mac allowed a remote attacker to perform domain spoofing via a…

Fix: 59.0.3071.115+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5093

Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a …

Fix: 60.0.3112.78+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5067

An insufficient watchdog timer in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof th…

Fix: 58.0.3029.81+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5072

Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with …

Fix: 59.0.3071.92+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.3
CVE-2017-5071

Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android allo…

Fix: 59.0.3071.86 / 59.0.3071.92+
Fix from $1,600 2017-10-27
Android CRITICAL 9.8
CVE-2016-10391

In all Qualcomm products with Android releases from CAF using the Linux kernel, the length in an HCI command is not properly checked for validity.

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2016-5872

In all Qualcomm products with Android releases from CAF using the Linux kernel, arguments to several QTEE syscalls are not properly validated.

Mitigation only
Fix from $2,300 2017-08-18
Android HIGH 7.8
CVE-2017-8260

In all Qualcomm products with Android releases from CAF using the Linux kernel, due to a type downcast, a value may improperly pass validation and ca…

Patch available
Fix from $1,950 2017-08-18
Android CRITICAL 9.8
CVE-2015-9055

In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a memory management routine.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9060

In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not properly validated in a QTEE system call.

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9061

In all Qualcomm products with Android releases from CAF using the Linux kernel, playReady DRM failed to check a length potentially leading to unautho…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9068

In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a mink syscall is not properly validated.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9069

In all Qualcomm products with Android releases from CAF using the Linux kernel, the Secure File System can become corrupted.

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2016-10347

In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a hypervisor function is not properly validated.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2016-10384

In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a WLAN driver ioctl.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2016-10387

In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a handover scenario.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9039

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in eMBMS where an assertion can be reached by …

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9044

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due t…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9046

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due t…

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9048

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of lost RTP packets.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9049

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of certain responses from th…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9051

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due t…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9052

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached while…

Mitigation only
Fix from $2,300 2017-08-18