Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2022-27833 Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow. Android Mitigation only Fix from $1,9502022-04-11 HIGH 7.8 CVE-2022-27835 Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write. Android Mitigation only Fix from $1,9502022-04-11 HIGH 7.2 CVE-2022-27573 Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allow… Android Mitigation only Fix from $1,9502022-04-11 HIGH 7.2 CVE-2022-27574 Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allow… Android Mitigation only Fix from $1,9502022-04-11 HIGH 7.8 CVE-2021-39763 In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to local escalation of privilege … Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39764 In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead to local escalation of privil… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39771 In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validation. This could lead to local… Android Mitigation only Fix from $1,9502022-03-30 MEDIUM 5.5 CVE-2021-39778 In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This coul… Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39740 In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lead to local information disclo… Android Mitigation only Fix from $1,6002022-03-30 HIGH 7.8 CVE-2021-39701 In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or pe… Android Patch available Fix from $1,9502022-03-16 CRITICAL 9.8 CVE-2022-25818 Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution. Android Mitigation only Fix from $2,3002022-03-10 MEDIUM 6.5 CVE-2022-24925 Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of servi… Android Mitigation only Fix from $1,6002022-02-11 CRITICAL 9.8 CVE-2022-23425 Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base… Android Mitigation only Fix from $2,3002022-02-11 HIGH 7.1 CVE-2022-23427 PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files witho… Android Mitigation only Fix from $1,9502022-02-11 MEDIUM 6.7 CVE-2022-23432 An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution. Android Mitigation only Fix from $1,6002022-02-11 HIGH 7.8 CVE-2021-39676 In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This cou… Android Mitigation only Fix from $1,9502022-02-11 MEDIUM 5.5 CVE-2022-20036 In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no a… Android Mitigation only Fix from $1,6002022-02-09 MEDIUM 5.5 CVE-2022-20037 In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no a… Android Mitigation only Fix from $1,6002022-02-09 MEDIUM 5.5 CVE-2022-20017 In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no a… Android Mitigation only Fix from $1,6002022-02-09 HIGH 7.1 CVE-2022-22264 Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files withou… Android Mitigation only Fix from $1,9502022-01-10 MEDIUM 5.5 CVE-2022-20019 In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with… Android Mitigation only Fix from $1,6002022-01-04 MEDIUM 5.5 CVE-2022-20020 In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no ad… Android Mitigation only Fix from $1,6002022-01-04 HIGH 8.8 CVE-2021-38015 Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extensio… Chrome 96.0.4664.45+ Fix from $1,9502021-12-23 MEDIUM 6.5 CVE-2021-4059 Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML … Chrome 96.0.4664.93+ Fix from $1,6002021-12-23 HIGH 7.3 CVE-2021-1021 In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbitrary user due to improper in… Android Mitigation only Fix from $1,9502021-12-15 HIGH 7.3 CVE-2021-1020 In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper inpu… Android Mitigation only Fix from $1,9502021-12-15 HIGH 8.0 CVE-2021-0933 In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to interfere with a consent dialog d… Android Mitigation only Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-0921 In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation.… Android Mitigation only Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-0928 In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. … Android Mitigation only Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-25517 An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution. Android Mitigation only Fix from $1,9502021-12-08