Vulnerability index

Browse CVEs

386 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2015-6626 libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently byp… Android 5.1.1+ Fix from $1,6002015-12-08 MEDIUM 5.0 CVE-2015-6622 The Native Frameworks Library in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and conseque… Android 5.1.1+ Fix from $1,6002015-12-08 MEDIUM 5.0 CVE-2015-8074 mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection… Android after 5.1 Fix from $1,6002015-11-03 MEDIUM 5.0 CVE-2015-6611 mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive information, and consequently bypass… Android 5.1.1+ Fix from $1,6002015-11-03 MEDIUM 5.0 CVE-2015-6759 The shouldTreatAsUniqueOrigin function in platform/weborigin/SecurityOrigin.cpp in Blink, as used in Google Chrome before 46.0.2490.71, does not ensu… Chrome after 45.0.2454.101 Fix from $1,6002015-10-15 MEDIUM 5.0 CVE-2015-1247 The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does … Chrome after 42.0.2311.60 Fix from $1,6002015-04-19 HIGH 7.5 CVE-2013-7373 Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection … Android after 4.3.1 Fix from $1,9502014-04-29 MEDIUM 5.0 CVE-2013-6656 The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, processe… Chrome after 33.0.1750.116 Fix from $1,6002014-02-24 MEDIUM 5.0 CVE-2013-6629EPSS 10% The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, … Chrome 1.3.1 / 9.03+ Fix from $1,6002013-11-19 MEDIUM 5.8 CVE-2013-2879 Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer process can be considered a trusted process for s… Chrome after 28.0.1500.70 Fix from $1,6002013-07-10 MEDIUM 5.0 CVE-2013-2848 The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors. Chrome after 27.0.1453.91 Fix from $1,6002013-05-22 MEDIUM 5.0 CVE-2013-0909 The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HTTP Referer information via unspecified vectors. Chrome after 25.0.1364.126 Fix from $1,6002013-03-05 HIGH 7.1 CVE-2011-1350 The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an applicati… Android after 2.3.5 Fix from $1,9502013-02-05 MEDIUM 5.0 CVE-2012-2891 The IPC implementation in Google Chrome before 22.0.1229.79 allows attackers to obtain potentially sensitive information about memory addresses via u… Chrome after 22.0.1229.78 Fix from $1,6002012-09-26 MEDIUM 5.0 CVE-2012-2854 Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to obtain poten… Chrome after 21.0.1180.56 Fix from $1,6002012-08-06 MEDIUM 5.0 CVE-2012-2815 Google Chrome before 20.0.1132.43 allows remote attackers to obtain potentially sensitive information from a fragment identifier by leveraging access… Chrome after 20.0.1132.42 Fix from $1,6002012-06-27 MEDIUM 5.0 CVE-2011-1190 The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors,… Chrome 5.0 / 5.0.6+ Fix from $1,6002011-03-11 MEDIUM 5.0 CVE-2011-1187 Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak… Chrome 2.9 / 10.0.648.127+ Fix from $1,6002011-03-11 MEDIUM 5.0 CVE-2011-0776 The sandbox implementation in Google Chrome before 9.0.597.84 on Mac OS X might allow remote attackers to obtain potentially sensitive information ab… Chrome 9.0.597.84+ Fix from $1,6002011-02-04 MEDIUM 5.0 CVE-2010-3417 Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentiall… Chrome 6.0.472.59+ Fix from $1,6002010-09-16 MEDIUM 5.0 CVE-2010-3118 The autosuggest feature in the Omnibox implementation in Google Chrome before 5.0.375.127 does not anticipate entry of passwords, which might allow r… Chrome 5.0.375.127+ Fix from $1,6002010-08-24 HIGH 10.0 CVE-2010-1230 Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Securit… Chrome 4.1.249.1036+ Fix from $1,9502010-04-01 MEDIUM 5.0 CVE-2010-0663 The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations… Chrome after 4.0.249.0 Fix from $1,6002010-02-18 MEDIUM 5.0 CVE-2010-0660 Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirect… Chrome after 4.0.249.0 Fix from $1,6002010-02-18 HIGH 7.8 CVE-2009-1412 Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows re… Chrome after 1.0.154.53 Fix from $1,9502009-04-24 MEDIUM 6.8 CVE-2007-6536 The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy conside… Toolbar No fix yet Fix from $1,6002007-12-27