Vulnerability index

Browse CVEs

386 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Android MEDIUM 5.5
CVE-2016-5346

An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing…

Fix: 7.0+
Fix from $1,600 2020-01-08
Chrome MEDIUM 6.5
CVE-2019-13737

Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive info…

Fix: 79.0.3945.79+
Fix from $1,600 2019-12-10
Chrome MEDIUM 6.5
CVE-2019-13744

Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted H…

Fix: 79.0.3945.79+
Fix from $1,600 2019-12-10
Chrome HIGH 7.4
CVE-2019-5880

Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTM…

Fix: 77.0.3865.75+
Fix from $1,950 2019-11-25
Android MEDIUM 5.5
CVE-2019-2183

In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching optimization. This could lead …

Patch available
Fix from $1,600 2019-10-11
Android HIGH 7.5
CVE-2019-9424

In the Screen Lock, there is a possible information disclosure due to an unusual root cause. In certain circumstances, the setting to hide the unlock…

Mitigation only
Fix from $1,950 2019-09-27
Android MEDIUM 5.5
CVE-2019-2103

In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. Thi…

Patch available
Fix from $1,600 2019-09-05
Chrome MEDIUM 6.5
CVE-2018-6150

Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted…

Fix: 66.0.3359.117+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-6159

Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive inf…

Fix: 68.0.3440.75+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-6168

Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from pr…

Fix: 68.0.3440.75+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-6134

Information leak in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page.

Fix: 67.0.3396.62+
Fix from $1,600 2019-06-27
Chrome MEDIUM 5.5
CVE-2018-20073

Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem.

Fix: 72.0.3626.81+
Fix from $1,600 2019-06-27
Android MEDIUM 5.5
CVE-2018-12006

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potenti…

Patch available
Fix from $1,600 2019-02-11
Chrome MEDIUM 6.5
CVE-2018-6179

Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who…

Fix: 68.0.3440.75+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6164

Insufficient origin checks for CSS content in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a …

Fix: 68.0.3440.75+
Fix from $1,600 2019-01-09
Chrome MEDIUM 5.5
CVE-2018-6147

Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive i…

Fix: 67.0.3396.62+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6117

Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially sensitive information from pro…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6137

CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Fix: 67.0.3396.62+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6109

readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome pri…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6093

Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16078

Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive i…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Rendertron HIGH 7.5
CVE-2017-18355

Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "…

Patch available
Fix from $1,950 2018-12-17
Android MEDIUM 5.5
CVE-2018-9554

In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media files due to a permissions bypass. This could lead…

Mitigation only
Fix from $1,600 2018-12-06
Android MEDIUM 5.5
CVE-2018-9543

In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a factory reset. This could lead to local informati…

Patch available
Fix from $1,600 2018-11-14
Android HIGH 7.5
CVE-2018-9526

In device configuration data, there is an improperly configured setting. This could lead to remote disclosure of device location. User interaction is…

Patch available
Fix from $1,950 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6066

Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-orig…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6075

Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin da…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6077

Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacke…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6079

Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to …

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-17468

Incorrect handling of timer information during navigation in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obtain cross o…

Fix: 70.0.3538.67+
Fix from $1,600 2018-11-14