Vulnerability index

Browse CVEs

373 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Android HIGH 9.3
CVE-2015-7717

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 9.3
CVE-2015-6606

The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted…

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 9.3
CVE-2015-6596

mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bugs 20731946 and 20719651, a …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 9.3
CVE-2015-3879

Media Player Framework in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bug 23223325.

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 9.3
CVE-2015-3865

The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Sign…

Fix: after 5.1
Fix from $1,950 2015-10-06
Android MEDIUM 6.4
CVE-2015-3847

Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafted application, aka internal bug 22343270.

Fix: after 5.1
Fix from $1,600 2015-10-06
Android HIGH 9.3
CVE-2015-3858

The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an au…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3849

The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return value…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android MEDIUM 6.8
CVE-2015-3845

The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identif…

Fix: after 5.1
Fix from $1,600 2015-10-01
Android MEDIUM 6.8
CVE-2015-3844

The getProcessRecordLocked method in services/core/java/com/android/server/am/ActivityManagerService.java in ActivityManager in Android before 5.1.1 …

Fix: after 5.1
Fix from $1,600 2015-10-01
Android HIGH 9.3
CVE-2015-3843

The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or (2) emulate unspecified Telephony STK SIM command…

Fix: after 5.1
Fix from $1,950 2015-10-01
Chrome HIGH 7.5
CVE-2015-1293

The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecifi…

Fix: after 44.0.2403
Fix from $1,950 2015-09-03
Chrome MEDIUM 5.0
CVE-2015-1292

The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.…

Fix: after 44.0.2403
Fix from $1,600 2015-09-03
Chrome MEDIUM 6.4
CVE-2015-1291

The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check wh…

Fix: after 44.0.2403
Fix from $1,600 2015-09-03
Chrome HIGH 7.5
CVE-2015-3335

The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc in Google Chrome before 42.0.2311.9…

Fix: after 42.0.2311.60
Fix from $1,950 2015-04-19
Chrome MEDIUM 5.0
CVE-2015-1226

The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properl…

Fix: after 40.0.2214.115
Fix from $1,600 2015-03-09
Chrome MEDIUM 5.0
CVE-2014-9689

content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate …

Fix: after 40.0.2214.115
Fix from $1,600 2015-03-09
Chrome MEDIUM 5.0
CVE-2011-5319

content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accel…

Fix: after 40.0.2214.115
Fix from $1,600 2015-03-09
Android HIGH 7.2
CVE-2014-8609

The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not prope…

Fix: after 4.4.4
Fix from $1,950 2014-12-15
Android HIGH 7.2
CVE-2014-7911EPSS 25%

luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deseri…

Fix: after 4.4.4
Fix from $1,950 2014-12-15
Chrome HIGH 7.5
CVE-2014-3189

The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate imag…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Chrome HIGH 7.5
CVE-2014-3196

base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Chrome MEDIUM 5.0
CVE-2014-3197

The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, d…

Fix: after 38.0.2125.7
Fix from $1,600 2014-10-08
Android Browser MEDIUM 5.8
CVE-2014-6041EPSS 18%

The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 charac…

No fix yet
Fix from $1,600 2014-09-02
Chrome MEDIUM 6.4
CVE-2014-3170

extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote at…

Fix: after 37.0.2062.93
Fix from $1,600 2014-08-27
Chrome MEDIUM 6.4
CVE-2014-3172

The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL befo…

Fix: after 37.0.2062.93
Fix from $1,600 2014-08-27
Chrome HIGH 7.5
CVE-2014-3161

The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android…

Fix: after 36.0.1985.106
Fix from $1,950 2014-07-20
Chrome MEDIUM 5.8
CVE-2013-6666

The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not veri…

Fix: after 33.0.1750.144
Fix from $1,600 2014-03-05
Android Api MEDIUM 6.8
CVE-2012-6636EPSS 41%

The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary me…

Fix: after 16.0
Fix from $1,600 2014-03-03
Chrome MEDIUM 6.4
CVE-2013-6657

core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certai…

Fix: after 33.0.1750.116
Fix from $1,600 2014-02-24