Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chrome HIGH 8.8
CVE-2016-5197

The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who …

Fix: after 54.0.2840.68
Fix from $1,950 2017-01-19
Chrome MEDIUM 6.5
CVE-2016-5218

The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation wit…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.5
CVE-2016-5222

Incorrect handling of invalid URLs in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote a…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Android HIGH 7.5
CVE-2017-0389

A denial of service vulnerability in core networking could enable a remote attacker to use specially crafted network packet to cause a device hang or…

Mitigation only
Fix from $1,950 2017-01-12
Chrome MEDIUM 6.5
CVE-2016-5187

Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacke…

Fix: after 53.0.2785.143
Fix from $1,600 2016-12-18
Android MEDIUM 5.5
CVE-2016-6712

A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before…

Patch available
Fix from $1,600 2016-12-13
Android MEDIUM 5.5
CVE-2016-6711

A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before…

Patch available
Fix from $1,600 2016-12-13
Android CRITICAL 9.8
CVE-2016-6696

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-6693

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-6694

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android HIGH 7.8
CVE-2016-6674

system_server in Android before 2016-10-05 on Nexus devices allows attackers to gain privileges via a crafted application, aka internal bug 30445380.

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3937

The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 300309…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3936

The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 300190…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android MEDIUM 5.5
CVE-2016-3920

id3/ID3.cpp in libstagefright in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allo…

Patch available
Fix from $1,600 2016-10-10
Chrome MEDIUM 6.5
CVE-2016-5174

browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a full…

Fix: after 53.0.2785.101
Fix from $1,600 2016-09-25
Chrome HIGH 7.5
CVE-2016-5141

Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors involving a provisional URL for an…

Fix: after 52.0.2743.82
Fix from $1,950 2016-08-07
Android HIGH 7.8
CVE-2014-9889

drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9886

arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly …

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9884

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain pointers, wh…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9872

The diag driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not ensure unique identifiers in a DCI client table, …

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9866

drivers/media/platform/msm/camera_v2/sensor/csid/msm_csid.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices d…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9864

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate ioctl calls, which a…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.5
CVE-2016-3831

The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cau…

Patch available
Fix from $1,950 2016-08-05
Android MEDIUM 5.5
CVE-2016-3830

codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-…

Patch available
Fix from $1,600 2016-08-05
Android HIGH 7.8
CVE-2016-3826

services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does …

Patch available
Fix from $1,950 2016-08-05
Chrome MEDIUM 6.5
CVE-2016-5135

WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not consider referrer-policy infor…

Fix: after 51.0.2704.106
Fix from $1,600 2016-07-23
Chrome MEDIUM 6.5
CVE-2016-1707

ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid URL is replaced with the about…

Fix: after 51.0.2704.106
Fix from $1,600 2016-07-23
Chrome CRITICAL 9.6
CVE-2016-1706

The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should h…

Fix: after 51.0.2704.106
Fix from $2,300 2016-07-23
Android HIGH 7.5
CVE-2016-3766

MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 do…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.5
CVE-2016-3760

Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local users to gain privileges by establishing a pairin…

Mitigation only
Fix from $1,950 2016-07-11