Vulnerability index

Browse CVEs

373 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Chrome MEDIUM 5.0
CVE-2013-6660

The drag-and-drop implementation in Google Chrome before 33.0.1750.117 does not properly restrict the information in WebDropData data structures, whi…

Fix: after 33.0.1750.116
Fix from $1,600 2014-02-24
Android HIGH 8.8
CVE-2013-6271EPSS 8%

Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the up…

No fix yet
Fix from $1,950 2013-12-14
Chrome MEDIUM 5.8
CVE-2013-6802

Google Chrome before 31.0.1650.57 allows remote attackers to bypass intended sandbox restrictions by leveraging access to a renderer process, as demo…

Fix: after 31.0.1650.57
Fix from $1,600 2013-11-18
Android MEDIUM 6.9
CVE-2013-4777

A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that…

No fix yet
Fix from $1,600 2013-09-25
Chrome MEDIUM 5.8
CVE-2013-2881

Google Chrome before 28.0.1500.95 does not properly handle frames, which allows remote attackers to bypass the Same Origin Policy via a crafted web s…

Fix: after 28.0.1500.94
Fix from $1,600 2013-07-31
Glass MEDIUM 6.9
CVE-2013-4872

Google Glass before XE6 does not properly restrict the processing of QR codes, which allows physically proximate attackers to modify the configuratio…

Mitigation only
Fix from $1,600 2013-07-18
Android HIGH 7.2
CVE-2013-3666

The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attackers to execute arbitrary commands by entering USB…

Mitigation only
Fix from $1,950 2013-05-29
Chrome Os MEDIUM 5.0
CVE-2013-2834

Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attacker…

Fix: after 26.0.1410.56
Fix from $1,600 2013-04-16
Chrome Os MEDIUM 5.0
CVE-2013-2835

Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attacker…

Fix: after 26.0.1410.56
Fix from $1,600 2013-04-16
Chrome HIGH 7.5
CVE-2013-0922

Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, wh…

Fix: after 26.0.1410.42
Fix from $1,950 2013-03-28
Chrome HIGH 7.5
CVE-2013-0924

The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the permissions API is consistent with file permissions,…

Fix: after 26.0.1410.42
Fix from $1,950 2013-03-28
Chrome HIGH 7.5
CVE-2013-0925

Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this …

Fix: after 26.0.1410.42
Fix from $1,950 2013-03-28
Chrome MEDIUM 6.8
CVE-2013-0918

Google Chrome before 26.0.1410.43 does not prevent navigation to developer tools in response to a drag-and-drop operation, which allows user-assisted…

Fix: after 26.0.1410.42
Fix from $1,600 2013-03-28
Chrome MEDIUM 6.8
CVE-2013-0921

The Isolated Sites feature in Google Chrome before 26.0.1410.43 does not properly enforce the use of separate processes, which makes it easier for re…

Fix: after 26.0.1410.42
Fix from $1,600 2013-03-28
Chrome HIGH 7.5
CVE-2013-0838

Google Chrome before 24.0.1312.52 on Linux uses weak permissions for shared memory segments, which has unspecified impact and attack vectors.

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Chrome MEDIUM 6.4
CVE-2013-0829

Google Chrome before 24.0.1312.52 does not properly maintain database metadata, which allows remote attackers to bypass intended file-access restrict…

Fix: after 24.0.1312.51
Fix from $1,600 2013-01-15
Chrome MEDIUM 5.0
CVE-2012-5146

Google Chrome before 24.0.1312.52 allows remote attackers to bypass the Same Origin Policy via a malformed URL.

Fix: after 24.0.1312.51
Fix from $1,600 2013-01-15
Chrome MEDIUM 5.0
CVE-2012-5155

Google Chrome before 24.0.1312.52 on Mac OS X does not use an appropriate sandboxing approach for worker processes, which makes it easier for remote …

Fix: after 24.0.1312.51
Fix from $1,600 2013-01-15
Chrome HIGH 7.5
CVE-2012-5117

Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecifie…

Fix: after 23.0.1271.62
Fix from $1,950 2012-11-07
Chrome HIGH 9.3
CVE-2012-4907

Google Chrome before 18.0.1025308 on Android does not properly restrict access from JavaScript code to Android APIs, which allows remote attackers to…

Fix: after 18.0.1025306
Fix from $1,950 2012-09-13
Chrome HIGH 7.5
CVE-2012-4908

Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors in…

Fix: after 18.0.1025306
Fix from $1,950 2012-09-13
Chrome MEDIUM 5.0
CVE-2012-4903

Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive infor…

Fix: after 18.0.1025306
Fix from $1,600 2012-09-13
Chrome MEDIUM 5.0
CVE-2012-4906

Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive infor…

Fix: after 18.0.1025306
Fix from $1,600 2012-09-13
Tunnelblick MEDIUM 6.9
CVE-2012-3486

Tunnelblick 3.3beta20 and earlier allows local users to gain privileges via an OpenVPN configuration file that specifies execution of a script upon o…

Fix: after 3.3beta20
Fix from $1,600 2012-08-26
Tunnelblick HIGH 7.2
CVE-2012-3484

Tunnelblick 3.3beta20 and earlier relies on a test for specific ownership and permissions to determine whether a program can be safely executed, whic…

Fix: after 3.3beta20
Fix from $1,950 2012-08-26
Chrome HIGH 7.2
CVE-2011-3098

Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Player plug-in, which might allow local users to gai…

Fix: after 19.0.1084.45
Fix from $1,950 2012-05-16
Chrome HIGH 7.5
CVE-2011-3084

Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on an internal page, which might allow attackers to…

Fix: after 19.0.1084.45
Fix from $1,950 2012-05-16
Chrome MEDIUM 5.0
CVE-2011-4691

Google Chrome 15.0.874.121 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attemp…

Fix: after 15.0.874.121
Fix from $1,600 2011-12-07
Chrome MEDIUM 5.0
CVE-2010-5073

The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyl…

No fix yet
Fix from $1,600 2011-12-07
App Engine Python Sdk HIGH 7.2
CVE-2011-4212

The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass…

Fix: after 1.5.3
Fix from $1,950 2011-10-30