Vulnerability index

Browse CVEs

373 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Chrome HIGH 8.8
CVE-2016-1631

The PPB_Flash_MessageLoop_Impl::InternalRun function in content/renderer/pepper/ppb_flash_message_loop_impl.cc in the Pepper plugin in Google Chrome …

Fix: after 48.0.2564.116
Fix from $1,950 2016-03-06
Chrome HIGH 8.8
CVE-2016-1630

The ContainerNode::parserRemoveChild function in WebKit/Source/core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 49.0.2623.75, mis…

Fix: after 48.0.2564.116
Fix from $1,950 2016-03-06
Chrome CRITICAL 9.8
CVE-2016-1629

Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified …

Fix: after 48.0.2564.109
Fix from $2,300 2016-02-21
Chrome HIGH 8.8
CVE-2016-1622

The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extensio…

Fix: after 48.0.2564.103
Fix from $1,950 2016-02-14
Android MEDIUM 6.1
CVE-2016-0813

packages/SystemUI/src/com/android/systemui/recents/AlternateRecentsComponent.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.x before…

Mitigation only
Fix from $1,600 2016-02-07
Android MEDIUM 6.1
CVE-2016-0812

The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindowManager.java in Setup Wizard in Android 5.1.x be…

Mitigation only
Fix from $1,600 2016-02-07
Android HIGH 7.8
CVE-2016-0810

media/libmedia/SoundPool.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 mishandles locking requir…

Mitigation only
Fix from $1,950 2016-02-07
Android HIGH 8.8
CVE-2016-0809

Use-after-free vulnerability in the wifi_cleanup function in bcmdhd/wifi_hal/wifi_hal.cpp in Wi-Fi in Android 6.x before 2016-02-01 allows attackers …

Mitigation only
Fix from $1,950 2016-02-07
Android HIGH 8.4
CVE-2016-0807

The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows attackers to gain privileges via a crafted applicatio…

Mitigation only
Fix from $1,950 2016-02-07
Android HIGH 8.4
CVE-2016-0806

The Qualcomm Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain priv…

Mitigation only
Fix from $1,950 2016-02-07
Android HIGH 8.4
CVE-2016-0805

The performance event manager for Qualcomm ARM processors in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows atta…

Mitigation only
Fix from $1,950 2016-02-07
Android HIGH 7.8
CVE-2015-6647

The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafte…

No fix yet
Fix from $1,950 2016-01-06
Android MEDIUM 5.0
CVE-2015-6645

SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to cause a denial of service (continuous rebooting) via a craft…

Mitigation only
Fix from $1,600 2016-01-06
Android MEDIUM 6.6
CVE-2015-6643

Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset …

Mitigation only
Fix from $1,600 2016-01-06
Android CRITICAL 9.8
CVE-2015-6642

The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unsp…

Mitigation only
Fix from $2,300 2016-01-06
Android HIGH 7.8
CVE-2015-6640

The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is ac…

Mitigation only
Fix from $1,950 2016-01-06
Android HIGH 7.8
CVE-2015-6639EPSS 7%

The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafte…

No fix yet
Fix from $1,950 2016-01-06
Android HIGH 7.8
CVE-2015-6638

The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted ap…

Mitigation only
Fix from $1,950 2016-01-06
Android HIGH 7.8
CVE-2015-6637

The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, a…

Mitigation only
Fix from $1,950 2016-01-06
Android HIGH 9.3
CVE-2015-6623

Wi-Fi in Android 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or Signa…

Mitigation only
Fix from $1,950 2015-12-08
Android HIGH 9.3
CVE-2015-6621

SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated …

Mitigation only
Fix from $1,950 2015-12-08
Android HIGH 9.3
CVE-2015-6620

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrate…

Fix: 5.1.1+
Fix from $1,950 2015-12-08
Android HIGH 9.3
CVE-2015-6619

The kernel in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, aka internal bug 2…

Fix: 5.1.1+
Fix from $1,950 2015-12-08
Chrome HIGH 7.5
CVE-2015-6772

The DOM implementation in Blink, as used in Google Chrome before 47.0.2526.73, does not prevent javascript: URL navigation while a document is being …

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Chrome HIGH 7.5
CVE-2015-6770

The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a diffe…

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Chrome HIGH 7.5
CVE-2015-6769

The provisional-load commit implementation in WebKit/Source/bindings/core/v8/WindowProxy.cpp in Google Chrome before 47.0.2526.73 allows remote attac…

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Chrome HIGH 7.5
CVE-2015-6768

The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a diffe…

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Android MEDIUM 5.8
CVE-2015-6614

Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended network-interface restrictions, pe…

Mitigation only
Fix from $1,600 2015-11-03
Android HIGH 9.3
CVE-2015-6612

libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted application, aka internal bug 235…

Fix: 5.1.1+
Fix from $1,950 2015-11-03
Chrome HIGH 7.5
CVE-2015-6755

The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 46.0.2490.71, proceeds with a …

Fix: after 45.0.2454.101
Fix from $1,950 2015-10-15