Vulnerability index

Browse CVEs

386 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Android MEDIUM 5.5
CVE-2016-6679

CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to obt…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6678

The Motorola USBNet driver in Android before 2016-10-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6677

The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3924

services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 …

Patch available
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3918

email/provider/AttachmentProvider.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7…

Patch available
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3902

drivers/platform/msm/ipa/ipa_qmi_service.c in the Qualcomm IPA driver in Android before 2016-10-05 on Nexus 5X and 6P devices allows attackers to obt…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3860

sound/soc/msm/qdsp6v2/audio_calibration.c in the Qualcomm sound driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices al…

Fix: after 7.0
Fix from $1,600 2016-10-10
Chrome MEDIUM 6.5
CVE-2016-5172

The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive informat…

Fix: after 53.0.2785.101
Fix from $1,600 2016-09-25
Android MEDIUM 5.5
CVE-2016-3897

The WifiEnterpriseConfig class in net/wifi/WifiEnterpriseConfig.java in Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, an…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3896

AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows attackers to obtain sensitive EmailAc…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3895

Integer overflow in the Region::unflatten function in libs/ui/Region.cpp in mediaserver in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 al…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3894

The Qualcomm DMA component in Android before 2016-09-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application…

Fix: after 7.0
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3893

The wcdcal_hwdep_ioctl_shared function in sound/soc/codecs/wcdcal-hwdep.c in the Qualcomm sound codec in Android before 2016-09-05 on Nexus 6P device…

Fix: after 7.0
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3892

The Qualcomm SPMI driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafte…

Fix: after 7.0
Fix from $1,600 2016-09-11
Chrome MEDIUM 5.3
CVE-2016-7153EPSS 14%

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for …

Mitigation only
Fix from $1,600 2016-09-06
Android MEDIUM 5.5
CVE-2014-9899

drivers/usb/host/ehci-msm2.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices omits certain minimum calculations before cop…

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9898

arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly …

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9897

sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate certain user-spac…

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9896

drivers/char/adsprpc.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate parameters …

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9894

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not ensure that certain name strings en…

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9893

drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not properly determine the size …

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2016-3852

The MediaTek Wi-Fi driver in Android before 2016-08-05 on Android One devices allows attackers to obtain sensitive information via a crafted applicat…

Fix: after 6.0.1
Fix from $1,600 2016-08-05
Android MEDIUM 5.5
CVE-2016-3837

service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attac…

Patch available
Fix from $1,600 2016-08-05
Android MEDIUM 5.5
CVE-2016-3836

The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive informat…

Patch available
Fix from $1,600 2016-08-05
Android MEDIUM 5.5
CVE-2016-3835

The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, an…

Patch available
Fix from $1,600 2016-08-05
Android MEDIUM 5.5
CVE-2016-3834

The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended acc…

Patch available
Fix from $1,600 2016-08-05
Chrome HIGH 8.8
CVE-2016-5134

net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure that URL information is restri…

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23
Android MEDIUM 5.5
CVE-2016-3816

The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted applic…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2016-3815

The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, …

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2016-3814

The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, …

Fix: after 6.0.1
Fix from $1,600 2016-07-11