Vulnerability index

Browse CVEs

373 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2013-6660 The drag-and-drop implementation in Google Chrome before 33.0.1750.117 does not properly restrict the information in WebDropData data structures, whi… Chrome after 33.0.1750.116 Fix from $1,6002014-02-24 HIGH 8.8 CVE-2013-6271EPSS 8% Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the up… Android No fix yet Fix from $1,9502013-12-14 MEDIUM 5.8 CVE-2013-6802 Google Chrome before 31.0.1650.57 allows remote attackers to bypass intended sandbox restrictions by leveraging access to a renderer process, as demo… Chrome after 31.0.1650.57 Fix from $1,6002013-11-18 MEDIUM 6.9 CVE-2013-4777 A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that… Android No fix yet Fix from $1,6002013-09-25 MEDIUM 5.8 CVE-2013-2881 Google Chrome before 28.0.1500.95 does not properly handle frames, which allows remote attackers to bypass the Same Origin Policy via a crafted web s… Chrome after 28.0.1500.94 Fix from $1,6002013-07-31 MEDIUM 6.9 CVE-2013-4872 Google Glass before XE6 does not properly restrict the processing of QR codes, which allows physically proximate attackers to modify the configuratio… Glass Mitigation only Fix from $1,6002013-07-18 HIGH 7.2 CVE-2013-3666 The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attackers to execute arbitrary commands by entering USB… Android Mitigation only Fix from $1,9502013-05-29 MEDIUM 5.0 CVE-2013-2834 Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attacker… Chrome Os after 26.0.1410.56 Fix from $1,6002013-04-16 MEDIUM 5.0 CVE-2013-2835 Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attacker… Chrome Os after 26.0.1410.56 Fix from $1,6002013-04-16 HIGH 7.5 CVE-2013-0922 Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, wh… Chrome after 26.0.1410.42 Fix from $1,9502013-03-28 HIGH 7.5 CVE-2013-0924 The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the permissions API is consistent with file permissions,… Chrome after 26.0.1410.42 Fix from $1,9502013-03-28 HIGH 7.5 CVE-2013-0925 Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this … Chrome after 26.0.1410.42 Fix from $1,9502013-03-28 MEDIUM 6.8 CVE-2013-0918 Google Chrome before 26.0.1410.43 does not prevent navigation to developer tools in response to a drag-and-drop operation, which allows user-assisted… Chrome after 26.0.1410.42 Fix from $1,6002013-03-28 MEDIUM 6.8 CVE-2013-0921 The Isolated Sites feature in Google Chrome before 26.0.1410.43 does not properly enforce the use of separate processes, which makes it easier for re… Chrome after 26.0.1410.42 Fix from $1,6002013-03-28 HIGH 7.5 CVE-2013-0838 Google Chrome before 24.0.1312.52 on Linux uses weak permissions for shared memory segments, which has unspecified impact and attack vectors. Chrome after 24.0.1312.51 Fix from $1,9502013-01-15 MEDIUM 6.4 CVE-2013-0829 Google Chrome before 24.0.1312.52 does not properly maintain database metadata, which allows remote attackers to bypass intended file-access restrict… Chrome after 24.0.1312.51 Fix from $1,6002013-01-15 MEDIUM 5.0 CVE-2012-5146 Google Chrome before 24.0.1312.52 allows remote attackers to bypass the Same Origin Policy via a malformed URL. Chrome after 24.0.1312.51 Fix from $1,6002013-01-15 MEDIUM 5.0 CVE-2012-5155 Google Chrome before 24.0.1312.52 on Mac OS X does not use an appropriate sandboxing approach for worker processes, which makes it easier for remote … Chrome after 24.0.1312.51 Fix from $1,6002013-01-15 HIGH 7.5 CVE-2012-5117 Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecifie… Chrome after 23.0.1271.62 Fix from $1,9502012-11-07 HIGH 9.3 CVE-2012-4907 Google Chrome before 18.0.1025308 on Android does not properly restrict access from JavaScript code to Android APIs, which allows remote attackers to… Chrome after 18.0.1025306 Fix from $1,9502012-09-13 HIGH 7.5 CVE-2012-4908 Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors in… Chrome after 18.0.1025306 Fix from $1,9502012-09-13 MEDIUM 5.0 CVE-2012-4903 Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive infor… Chrome after 18.0.1025306 Fix from $1,6002012-09-13 MEDIUM 5.0 CVE-2012-4906 Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive infor… Chrome after 18.0.1025306 Fix from $1,6002012-09-13 MEDIUM 6.9 CVE-2012-3486 Tunnelblick 3.3beta20 and earlier allows local users to gain privileges via an OpenVPN configuration file that specifies execution of a script upon o… Tunnelblick after 3.3beta20 Fix from $1,6002012-08-26 HIGH 7.2 CVE-2012-3484 Tunnelblick 3.3beta20 and earlier relies on a test for specific ownership and permissions to determine whether a program can be safely executed, whic… Tunnelblick after 3.3beta20 Fix from $1,9502012-08-26 HIGH 7.2 CVE-2011-3098 Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Player plug-in, which might allow local users to gai… Chrome after 19.0.1084.45 Fix from $1,9502012-05-16 HIGH 7.5 CVE-2011-3084 Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on an internal page, which might allow attackers to… Chrome after 19.0.1084.45 Fix from $1,9502012-05-16 MEDIUM 5.0 CVE-2011-4691 Google Chrome 15.0.874.121 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attemp… Chrome after 15.0.874.121 Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2010-5073 The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyl… Chrome No fix yet Fix from $1,6002011-12-07 HIGH 7.2 CVE-2011-4212 The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass… App Engine Python Sdk after 1.5.3 Fix from $1,9502011-10-30