Vulnerability index

Browse CVEs

386 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Android MEDIUM 5.0
CVE-2015-6626

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently byp…

Fix: 5.1.1+
Fix from $1,600 2015-12-08
Android MEDIUM 5.0
CVE-2015-6622

The Native Frameworks Library in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and conseque…

Fix: 5.1.1+
Fix from $1,600 2015-12-08
Android MEDIUM 5.0
CVE-2015-8074

mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection…

Fix: after 5.1
Fix from $1,600 2015-11-03
Android MEDIUM 5.0
CVE-2015-6611

mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive information, and consequently bypass…

Fix: 5.1.1+
Fix from $1,600 2015-11-03
Chrome MEDIUM 5.0
CVE-2015-6759

The shouldTreatAsUniqueOrigin function in platform/weborigin/SecurityOrigin.cpp in Blink, as used in Google Chrome before 46.0.2490.71, does not ensu…

Fix: after 45.0.2454.101
Fix from $1,600 2015-10-15
Chrome MEDIUM 5.0
CVE-2015-1247

The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does …

Fix: after 42.0.2311.60
Fix from $1,600 2015-04-19
Android HIGH 7.5
CVE-2013-7373

Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection …

Fix: after 4.3.1
Fix from $1,950 2014-04-29
Chrome MEDIUM 5.0
CVE-2013-6656

The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, processe…

Fix: after 33.0.1750.116
Fix from $1,600 2014-02-24
Chrome MEDIUM 5.0
CVE-2013-6629EPSS 10%

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, …

Fix: 1.3.1 / 9.03+
Fix from $1,600 2013-11-19
Chrome MEDIUM 5.8
CVE-2013-2879

Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer process can be considered a trusted process for s…

Fix: after 28.0.1500.70
Fix from $1,600 2013-07-10
Chrome MEDIUM 5.0
CVE-2013-2848

The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.

Fix: after 27.0.1453.91
Fix from $1,600 2013-05-22
Chrome MEDIUM 5.0
CVE-2013-0909

The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HTTP Referer information via unspecified vectors.

Fix: after 25.0.1364.126
Fix from $1,600 2013-03-05
Android HIGH 7.1
CVE-2011-1350

The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an applicati…

Fix: after 2.3.5
Fix from $1,950 2013-02-05
Chrome MEDIUM 5.0
CVE-2012-2891

The IPC implementation in Google Chrome before 22.0.1229.79 allows attackers to obtain potentially sensitive information about memory addresses via u…

Fix: after 22.0.1229.78
Fix from $1,600 2012-09-26
Chrome MEDIUM 5.0
CVE-2012-2854

Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to obtain poten…

Fix: after 21.0.1180.56
Fix from $1,600 2012-08-06
Chrome MEDIUM 5.0
CVE-2012-2815

Google Chrome before 20.0.1132.43 allows remote attackers to obtain potentially sensitive information from a fragment identifier by leveraging access…

Fix: after 20.0.1132.42
Fix from $1,600 2012-06-27
Chrome MEDIUM 5.0
CVE-2011-1190

The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors,…

Fix: 5.0 / 5.0.6+
Fix from $1,600 2011-03-11
Chrome MEDIUM 5.0
CVE-2011-1187

Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak…

Fix: 2.9 / 10.0.648.127+
Fix from $1,600 2011-03-11
Chrome MEDIUM 5.0
CVE-2011-0776

The sandbox implementation in Google Chrome before 9.0.597.84 on Mac OS X might allow remote attackers to obtain potentially sensitive information ab…

Fix: 9.0.597.84+
Fix from $1,600 2011-02-04
Chrome MEDIUM 5.0
CVE-2010-3417

Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentiall…

Fix: 6.0.472.59+
Fix from $1,600 2010-09-16
Chrome MEDIUM 5.0
CVE-2010-3118

The autosuggest feature in the Omnibox implementation in Google Chrome before 5.0.375.127 does not anticipate entry of passwords, which might allow r…

Fix: 5.0.375.127+
Fix from $1,600 2010-08-24
Chrome HIGH 10.0
CVE-2010-1230

Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Securit…

Fix: 4.1.249.1036+
Fix from $1,950 2010-04-01
Chrome MEDIUM 5.0
CVE-2010-0663

The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations…

Fix: after 4.0.249.0
Fix from $1,600 2010-02-18
Chrome MEDIUM 5.0
CVE-2010-0660

Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirect…

Fix: after 4.0.249.0
Fix from $1,600 2010-02-18
Chrome HIGH 7.8
CVE-2009-1412

Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows re…

Fix: after 1.0.154.53
Fix from $1,950 2009-04-24
Toolbar MEDIUM 6.8
CVE-2007-6536

The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy conside…

No fix yet
Fix from $1,600 2007-12-27