Vulnerability index

Browse CVEs

373 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
App Engine Python Sdk HIGH 7.2
CVE-2011-4213

The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent use of the os module, which allows local users to …

Fix: 1.5.4+
Fix from $1,950 2011-10-30
App Engine Python Sdk HIGH 7.2
CVE-2011-4211

The FakeFile implementation in the sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly control the opening of file…

Fix: after 1.5.3
Fix from $1,950 2011-10-30
Chrome HIGH 7.5
CVE-2011-2862

Google V8, as used in Google Chrome before 14.0.835.163, does not properly restrict access to built-in objects, which has unspecified impact and remo…

Fix: 14.0.835.163+
Fix from $1,950 2011-09-19
Chrome MEDIUM 5.8
CVE-2008-7294

Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attack…

Fix: after 3.0.195.38
Fix from $1,600 2011-08-09
Chrome Os HIGH 7.2
CVE-2011-2169

Google Chrome OS before R12 0.12.433.38 Beta allows local users to gain privileges by creating a /var/lib/chromeos-aliases.conf file and placing comm…

Fix: after 0.12.433.35
Fix from $1,950 2011-05-24
Android HIGH 7.2
CVE-2011-1149

Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox …

Fix: after 2.2.2
Fix from $1,950 2011-04-21
Chrome HIGH 7.5
CVE-2011-0778

Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Pol…

Fix: after 9.0.597.83
Fix from $1,950 2011-02-04
Chrome HIGH 9.3
CVE-2010-2296

The implementation of unspecified DOM methods in Google Chrome before 5.0.375.70 allows remote attackers to bypass the Same Origin Policy via unknown…

Fix: 5.0.375.70+
Fix from $1,950 2010-06-15
Chrome HIGH 10.0
CVE-2010-1663EPSS 54%

The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy…

Fix: after 4.1.249.1063
Fix from $1,950 2010-05-03
Chrome HIGH 10.0
CVE-2010-1505

Google Chrome before 4.1.249.1059 does not prevent pages from loading with the New Tab page's privileges, which has unknown impact and attack vectors.

Fix: after 4.1.249.1058
Fix from $1,950 2010-04-23
Chrome MEDIUM 6.8
CVE-2010-0661

WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypa…

Fix: after 4.0.249.0
Fix from $1,600 2010-02-18
Chrome HIGH 10.0
CVE-2009-2935EPSS 5%

Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain…

Fix: after 2.0.172.37
Fix from $1,950 2009-08-27
Chrome MEDIUM 5.0
CVE-2009-0411

Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, whi…

Fix: after 1.0.154.43
Fix from $1,600 2009-02-03