Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2017-14878 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a length variable which is used to co… Android Patch available Fix from $1,9502018-03-15 HIGH 7.8 CVE-2017-6281 NVIDIA libnvomx contains a possible out of bounds write due to a improper input validation which could lead to local escalation of privilege. This is… Android Mitigation only Fix from $1,9502018-03-12 HIGH 7.8 CVE-2017-15817 In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, t… Android Mitigation only Fix from $1,9502018-02-23 CRITICAL 9.8 CVE-2017-13229 A remote code execution vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68160703. Android Mitigation only Fix from $2,3002018-02-12 MEDIUM 6.5 CVE-2017-15386 Incorrect implementation in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via… Chrome 62.0.3202.62+ Fix from $1,6002018-02-07 MEDIUM 6.5 CVE-2017-15389 An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (U… Chrome 62.0.3202.62+ Fix from $1,6002018-02-07 MEDIUM 6.5 CVE-2017-15390 Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing via IDN homogr… Chrome 62.0.3202.62+ Fix from $1,6002018-02-07 MEDIUM 6.5 CVE-2017-15394 Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permissi… Chrome 62.0.3202.62+ Fix from $1,6002018-02-07 MEDIUM 5.7 CVE-2017-17860 In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user'… Android No fix yet Fix from $1,6002018-01-18 HIGH 7.5 CVE-2017-13198 A vulnerability in the Android media framework (ex) related to composition of frames lacking a color map. Product: Android. Versions: 7.0, 7.1.1, 7.1… Android Patch available Fix from $1,9502018-01-12 HIGH 7.5 CVE-2017-13214 In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process w… Android Mitigation only Fix from $1,9502018-01-12 HIGH 8.8 CVE-2017-13176 In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privileg… Android Patch available Fix from $1,9502018-01-12 HIGH 7.5 CVE-2017-13186 A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8… Android Patch available Fix from $1,9502018-01-12 HIGH 7.8 CVE-2017-15845 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an invalid input of firmware size (ne… Android Patch available Fix from $1,9502018-01-10 HIGH 8.8 CVE-2017-0872 A remote code execution vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-6529… Android Patch available Fix from $1,9502017-12-06 HIGH 8.8 CVE-2017-0876 A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-64964675. Android Mitigation only Fix from $1,9502017-12-06 HIGH 8.8 CVE-2017-0877 A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937. Android Mitigation only Fix from $1,9502017-12-06 HIGH 8.8 CVE-2017-0878 A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 8.0. Android ID A-65186291. Android Mitigation only Fix from $1,9502017-12-06 MEDIUM 6.5 CVE-2017-0873 A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android … Android Mitigation only Fix from $1,6002017-12-06 MEDIUM 6.5 CVE-2017-0874 A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID… Android Mitigation only Fix from $1,6002017-12-06 MEDIUM 6.5 CVE-2017-13148 A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android … Android Mitigation only Fix from $1,6002017-12-06 CRITICAL 9.8 CVE-2017-14908 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the SafeSwitch test application does … Android Mitigation only Fix from $2,3002017-12-05 CRITICAL 9.8 CVE-2017-14909 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a count value that is read from a fil… Android No fix yet Fix from $2,3002017-12-05 CRITICAL 9.8 CVE-2017-14914 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, handles in the global client structur… Android No fix yet Fix from $2,3002017-12-05 HIGH 7.5 CVE-2017-0858 Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64836894. Android Patch available Fix from $1,9502017-11-16 HIGH 7.8 CVE-2017-11027 In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing UBI image, size is not… Android Patch available Fix from $1,9502017-11-16 HIGH 8.8 CVE-2017-5121EPSS 5% Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute … Chrome 61.0.3163.100+ Fix from $1,9502017-10-27 MEDIUM 6.5 CVE-2017-5104 Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the o… Chrome after 60.0.3112.78 Fix from $1,6002017-10-27 MEDIUM 6.5 CVE-2017-5105 Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to p… Chrome after 60.0.3112.78 Fix from $1,6002017-10-27 MEDIUM 6.5 CVE-2017-5106 Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to p… Chrome after 60.0.3112.78 Fix from $1,6002017-10-27