Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.3 CVE-2016-11032 An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all Sound functionality by broadcasting an unprotecte… Android Mitigation only Fix from $1,6002020-04-07 HIGH 7.8 CVE-2016-11052 An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so in Qjpeg in Qt 5.5 allows memory corruption via a … Android Mitigation only Fix from $1,9502020-04-07 HIGH 7.5 CVE-2016-11046 An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. Because of a misused whitelist, attackers can reac… Android Mitigation only Fix from $1,9502020-04-07 CRITICAL 9.8 CVE-2020-10837 An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and a… Android Mitigation only Fix from $2,3002020-03-24 MEDIUM 5.4 CVE-2020-6425 Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious… Chrome 80.0.3987.149+ Fix from $1,6002020-03-23 HIGH 7.3 CVE-2019-2216 In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privileg… Android Mitigation only Fix from $1,9502020-03-15 MEDIUM 6.7 CVE-2020-0050 In nfa_hciu_send_msg of nfa_hci_utils.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalati… Android Patch available Fix from $1,6002020-03-10 HIGH 7.8 CVE-2020-0041 KEV In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of p… Android Mitigation only Fix from $1,9502020-03-10 HIGH 8.8 CVE-2020-6416 Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a… Chrome 80.0.3987.87+ Fix from $1,9502020-02-11 MEDIUM 5.4 CVE-2020-6411 Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via… Chrome 80.0.3987.87+ Fix from $1,6002020-02-11 MEDIUM 5.4 CVE-2020-6412 Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via… Chrome 80.0.3987.87+ Fix from $1,6002020-02-11 HIGH 8.8 CVE-2020-6402 Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a mal… Chrome 80.0.3987.87+ Fix from $1,9502020-02-11 MEDIUM 6.5 CVE-2020-6399 Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted … Chrome 80.0.3987.87+ Fix from $1,6002020-02-11 MEDIUM 6.5 CVE-2020-6401 Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via… Chrome 80.0.3987.87+ Fix from $1,6002020-02-11 HIGH 8.8 CVE-2014-7224 A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityT… Android 4.4+ Fix from $1,9502020-02-07 HIGH 7.5 CVE-2020-5215 In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation fault in eager mode as the f… Tensorflow 1.15.2 / 2.0.1+ Fix from $1,9502020-01-28 MEDIUM 5.5 CVE-2015-1525 audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted … Android 5.1+ Fix from $1,6002020-01-24 MEDIUM 6.5 CVE-2019-13750 Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a cra… Chrome 79.0.3945.79+ Fix from $1,6002019-12-10 HIGH 7.5 CVE-2019-2232 In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service wh… Android Patch available Fix from $1,9502019-12-06 HIGH 8.8 CVE-2019-5856 Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process … Chrome 76.0.3809.87+ Fix from $1,9502019-11-25 HIGH 8.8 CVE-2019-5858 Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code… Chrome 76.0.3809.87+ Fix from $1,9502019-11-25 MEDIUM 6.5 CVE-2019-5862 Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to… Chrome 76.0.3809.87+ Fix from $1,6002019-11-25 MEDIUM 6.5 CVE-2019-5852 Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain potentially sensitive informati… Chrome 76.0.3809.87+ Fix from $1,6002019-11-25 MEDIUM 5.5 CVE-2019-13707 Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a … Chrome 78.0.3904.70+ Fix from $1,6002019-11-25 HIGH 8.8 CVE-2019-13692 Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafte… Chrome 77.0.3865.75+ Fix from $1,9502019-11-25 MEDIUM 6.7 CVE-2019-9467 In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to a local elevation of privileg… Android Mitigation only Fix from $1,6002019-11-13 HIGH 7.8 CVE-2019-2192 In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privil… Android Mitigation only Fix from $1,9502019-11-13 HIGH 7.8 CVE-2019-2195 In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to loc… Android Mitigation only Fix from $1,9502019-11-13 MEDIUM 6.5 CVE-2011-2808 A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed. Blink Mitigation only Fix from $1,6002019-11-06 HIGH 7.5 CVE-2019-9432 In Bluetooth, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure in the Blueto… Android Mitigation only Fix from $1,9502019-09-27