Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2021-25416 Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel… Android Mitigation only Fix from $1,6002021-06-11 MEDIUM 5.5 CVE-2021-25413 Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbi… Android No fix yet Fix from $1,6002021-06-11 MEDIUM 5.5 CVE-2021-25415 Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writ… Android Mitigation only Fix from $1,6002021-06-11 MEDIUM 5.5 CVE-2021-29611 TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseReshape` results in a denial of service based … Tensorflow 2.1.4 / 2.2.3+ Fix from $1,6002021-05-14 MEDIUM 6.5 CVE-2021-21208 Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain s… Chrome 90.0.4430.72+ Fix from $1,6002021-04-26 MEDIUM 6.5 CVE-2021-21221 Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer … Chrome 90.0.4430.72+ Fix from $1,6002021-04-26 MEDIUM 5.5 CVE-2021-0400 In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency se… Android Patch available Fix from $1,6002021-04-13 HIGH 8.8 CVE-2021-25356 An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary a… Android No fix yet Fix from $1,9502021-04-09 HIGH 8.8 CVE-2021-22538 A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker wh… Exposure Notifications Verification Server 0.23.1+ Fix from $1,9502021-03-31 MEDIUM 5.5 CVE-2021-0377 In DeltaPerformer::Write of delta_performer.cc, there is a possible use of untrusted input due to improper input validation. This could lead to a loc… Android Mitigation only Fix from $1,6002021-03-10 MEDIUM 5.5 CVE-2021-25334 Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent d… Android Mitigation only Fix from $1,6002021-03-04 MEDIUM 5.2 CVE-2021-25338 Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to wr… Android Mitigation only Fix from $1,6002021-03-04 MEDIUM 5.2 CVE-2021-25339 Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corr… Android Mitigation only Fix from $1,6002021-03-04 MEDIUM 6.5 CVE-2021-21126EPSS 9% Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted… Chrome 88.0.705.50 / 88.0.4324.96+ Fix from $1,6002021-02-09 MEDIUM 6.5 CVE-2021-21123EPSS 10% Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions vi… Chrome 88.0.705.50 / 88.0.4324.96+ Fix from $1,6002021-02-09 MEDIUM 6.7 CVE-2021-0345 In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with … Android Mitigation only Fix from $1,6002021-02-04 HIGH 7.5 CVE-2020-0236 In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation. This could lead to remote informa… Android Mitigation only Fix from $1,9502021-01-26 HIGH 7.5 CVE-2021-0313 In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remo… Android Patch available Fix from $1,9502021-01-11 MEDIUM 5.0 CVE-2021-0322 In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to loc… Android Patch available Fix from $1,6002021-01-11 CRITICAL 9.8 CVE-2020-0471 In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper … Android Patch available Fix from $2,3002021-01-11 MEDIUM 6.5 CVE-2020-16040EPSS 100% Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a craf… Chrome 87.0.4280.88+ Fix from $1,6002021-01-08 HIGH 8.8 CVE-2020-16015 Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a cr… Chrome 87.0.4280.66+ Fix from $1,9502021-01-08 MEDIUM 6.5 CVE-2020-27029 In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote denial of service with no addi… Android Mitigation only Fix from $1,6002020-12-15 MEDIUM 5.5 CVE-2020-0493 In CPDF_SampledFunc::v_Call of cpdf_sampledfunc.cpp, there is a possible out of bounds read due to improper input validation. This could lead to loca… Android Mitigation only Fix from $1,6002020-12-15 HIGH 7.5 CVE-2020-0442 In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote de… Android Patch available Fix from $1,9502020-11-10 HIGH 8.8 CVE-2020-15978 Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the render… Chrome 86.0.4240.75+ Fix from $1,9502020-11-03 HIGH 7.8 CVE-2020-15983 Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy v… Chrome 86.0.4240.75+ Fix from $1,9502020-11-03 MEDIUM 6.5 CVE-2020-15977 Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive info… Chrome 86.0.4240.75+ Fix from $1,6002020-11-03 HIGH 7.5 CVE-2020-26597 An issue was discovered on LG mobile devices with Android OS 9.0 and 10 software. The Wi-Fi subsystem has incorrect input validation, leading to a cr… Android Mitigation only Fix from $1,9502020-10-06 MEDIUM 6.5 CVE-2020-15210 In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an… Tensorflow 1.15.4 / 2.0.3+ Fix from $1,6002020-09-25