Vulnerability index

Browse CVEs

373 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 9.3 CVE-2015-7717 mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal … Android after 5.1 Fix from $1,9502015-10-06 HIGH 9.3 CVE-2015-6606 The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted… Android after 5.1 Fix from $1,9502015-10-06 HIGH 9.3 CVE-2015-6596 mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bugs 20731946 and 20719651, a … Android after 5.1 Fix from $1,9502015-10-06 HIGH 9.3 CVE-2015-3879 Media Player Framework in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bug 23223325. Android after 5.1 Fix from $1,9502015-10-06 HIGH 9.3 CVE-2015-3865 The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Sign… Android after 5.1 Fix from $1,9502015-10-06 MEDIUM 6.4 CVE-2015-3847 Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafted application, aka internal bug 22343270. Android after 5.1 Fix from $1,6002015-10-06 HIGH 9.3 CVE-2015-3858 The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an au… Android after 5.1 Fix from $1,9502015-10-01 HIGH 9.3 CVE-2015-3849 The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return value… Android after 5.1 Fix from $1,9502015-10-01 MEDIUM 6.8 CVE-2015-3845 The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identif… Android after 5.1 Fix from $1,6002015-10-01 MEDIUM 6.8 CVE-2015-3844 The getProcessRecordLocked method in services/core/java/com/android/server/am/ActivityManagerService.java in ActivityManager in Android before 5.1.1 … Android after 5.1 Fix from $1,6002015-10-01 HIGH 9.3 CVE-2015-3843 The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or (2) emulate unspecified Telephony STK SIM command… Android after 5.1 Fix from $1,9502015-10-01 HIGH 7.5 CVE-2015-1293 The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecifi… Chrome after 44.0.2403 Fix from $1,9502015-09-03 MEDIUM 5.0 CVE-2015-1292 The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.… Chrome after 44.0.2403 Fix from $1,6002015-09-03 MEDIUM 6.4 CVE-2015-1291 The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check wh… Chrome after 44.0.2403 Fix from $1,6002015-09-03 HIGH 7.5 CVE-2015-3335 The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc in Google Chrome before 42.0.2311.9… Chrome after 42.0.2311.60 Fix from $1,9502015-04-19 MEDIUM 5.0 CVE-2015-1226 The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properl… Chrome after 40.0.2214.115 Fix from $1,6002015-03-09 MEDIUM 5.0 CVE-2014-9689 content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate … Chrome after 40.0.2214.115 Fix from $1,6002015-03-09 MEDIUM 5.0 CVE-2011-5319 content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accel… Chrome after 40.0.2214.115 Fix from $1,6002015-03-09 HIGH 7.2 CVE-2014-8609 The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not prope… Android after 4.4.4 Fix from $1,9502014-12-15 HIGH 7.2 CVE-2014-7911EPSS 25% luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deseri… Android after 4.4.4 Fix from $1,9502014-12-15 HIGH 7.5 CVE-2014-3189 The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate imag… Chrome after 38.0.2125.7 Fix from $1,9502014-10-08 HIGH 7.5 CVE-2014-3196 base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory… Chrome after 38.0.2125.7 Fix from $1,9502014-10-08 MEDIUM 5.0 CVE-2014-3197 The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, d… Chrome after 38.0.2125.7 Fix from $1,6002014-10-08 MEDIUM 5.8 CVE-2014-6041EPSS 18% The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 charac… Android Browser No fix yet Fix from $1,6002014-09-02 MEDIUM 6.4 CVE-2014-3170 extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote at… Chrome after 37.0.2062.93 Fix from $1,6002014-08-27 MEDIUM 6.4 CVE-2014-3172 The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL befo… Chrome after 37.0.2062.93 Fix from $1,6002014-08-27 HIGH 7.5 CVE-2014-3161 The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android… Chrome after 36.0.1985.106 Fix from $1,9502014-07-20 MEDIUM 5.8 CVE-2013-6666 The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not veri… Chrome after 33.0.1750.144 Fix from $1,6002014-03-05 MEDIUM 6.8 CVE-2012-6636EPSS 41% The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary me… Android Api after 16.0 Fix from $1,6002014-03-03 MEDIUM 6.4 CVE-2013-6657 core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certai… Chrome after 33.0.1750.116 Fix from $1,6002014-02-24