Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2019-5801 Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted… Chrome 73.0.3683.75+ Fix from $1,6002019-05-23 MEDIUM 6.5 CVE-2019-5803 Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content securit… Chrome 73.0.3683.75+ Fix from $1,6002019-05-23 MEDIUM 6.5 CVE-2019-5793 Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installatio… Chrome 73.0.3683.75+ Fix from $1,6002019-05-23 HIGH 7.5 CVE-2019-2051 In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when p… Android Mitigation only Fix from $1,9502019-05-08 HIGH 7.8 CVE-2018-6243 NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of video metadata count may lead t… Android Mitigation only Fix from $1,9502019-05-07 HIGH 8.1 CVE-2018-7577 Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts … Snappy 1.7.1+ Fix from $1,9502019-04-24 HIGH 8.8 CVE-2019-2028 In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code execution with no additional executi… Android Patch available Fix from $1,9502019-04-19 HIGH 8.8 CVE-2019-1988 In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in s… Android Mitigation only Fix from $1,9502019-02-28 HIGH 8.8 CVE-2019-5783 Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Inj… Chrome 72.0.3626.81+ Fix from $1,9502019-02-19 HIGH 7.8 CVE-2019-5780 Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute J… Chrome 72.0.3626.81+ Fix from $1,9502019-02-19 HIGH 8.8 CVE-2019-5769 Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker t… Chrome 72.0.3626.81+ Fix from $1,9502019-02-19 HIGH 7.8 CVE-2018-6267 NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software does not validate or incorrectly validates input that can affec… Android No fix yet Fix from $1,9502019-02-13 HIGH 7.8 CVE-2018-6241 NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lea… Android Mitigation only Fix from $1,9502019-01-31 MEDIUM 6.5 CVE-2018-6160 JavaScript alert handling in Prompts in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) … Chrome 68.0.3440.75+ Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-6169 Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of… Chrome 68.0.3440.75+ Fix from $1,6002019-01-09 HIGH 8.8 CVE-2018-6139 Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to … Chrome 67.0.3396.62+ Fix from $1,9502019-01-09 HIGH 8.8 CVE-2018-6140 Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a use… Chrome 67.0.3396.62+ Fix from $1,9502019-01-09 HIGH 8.8 CVE-2018-6111 An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local attacker to execute arbitrary… Chrome 66.0.3359.117+ Fix from $1,9502019-01-09 MEDIUM 6.5 CVE-2018-6113 Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform dom… Chrome 66.0.3359.117+ Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-6114 Incorrect enforcement of CSP for <object> tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass content security … Chrome 66.0.3359.117+ Fix from $1,6002019-01-09 MEDIUM 5.4 CVE-2018-6110 Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a loc… Chrome 66.0.3359.117+ Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-6096 A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker… Chrome 66.0.3359.117+ Fix from $1,6002019-01-09 HIGH 8.8 CVE-2018-20065 Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to initiate potentially unsafe navigations without … Chrome 71.0.3578.80+ Fix from $1,9502019-01-09 HIGH 7.8 CVE-2018-6084 Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrar… Chrome 66.0.3359.117+ Fix from $1,9502019-01-09 MEDIUM 6.5 CVE-2018-20070 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents o… Chrome 71.0.3578.80+ Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-16080 A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the conten… Chrome 69.0.3497.81+ Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-16088 A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files w… Chrome 69.0.3497.81+ Fix from $1,6002019-01-09 CRITICAL 9.6 CVE-2018-16068 Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM… Chrome 69.0.3497.81+ Fix from $2,3002019-01-09 CRITICAL 9.6 CVE-2017-15402 Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same proces… Chrome 62.0.3202.74+ Fix from $2,3002019-01-09 MEDIUM 5.5 CVE-2018-20168 Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a den… Gvisor 2018-08-22+ Fix from $1,6002018-12-17