Vulnerability index

Browse CVEs

161 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Android MEDIUM 6.7
CVE-2024-25987

In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privil…

Mitigation only
Fix from $1,600 2024-03-11
Android MEDIUM 6.4
CVE-2024-25990

In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a race condition. This could lead …

Mitigation only
Fix from $1,600 2024-03-11
Android HIGH 7.8
CVE-2024-0046

In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This c…

Patch available
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2024-0049

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with n…

Patch available
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2023-40106

In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could le…

Patch available
Fix from $1,950 2024-02-15
Pixel Watch Firmware HIGH 7.8
CVE-2023-48418

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default…

No fix yet
Fix from $1,950 2024-01-02
Nest Audio Firmware CRITICAL 9.8
CVE-2023-48419

An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 

Fix: 2.58+
Fix from $2,300 2024-01-02
Android MEDIUM 6.7
CVE-2023-48406

there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. This could lead to local escalat…

Mitigation only
Fix from $1,600 2023-12-08
Android HIGH 7.8
CVE-2023-21374

In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,950 2023-10-30
Android HIGH 7.8
CVE-2023-21396

In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privileg…

Fix: 14.0+
Fix from $1,950 2023-10-30
Android HIGH 7.8
CVE-2023-21397

In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of privilege wi…

Fix: 14.0+
Fix from $1,950 2023-10-30
Android MEDIUM 5.5
CVE-2023-21376

In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no…

Fix: 14.0+
Fix from $1,600 2023-10-30
Android HIGH 7.8
CVE-2023-21343

In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege w…

Fix: 14.0+
Fix from $1,950 2023-10-30
Android HIGH 7.8
CVE-2023-35674 KEV

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local e…

Patch available
Fix from $1,950 2023-09-11
Android HIGH 7.8
CVE-2023-35676

In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe Pending…

Mitigation only
Fix from $1,950 2023-09-11
Android MEDIUM 5.5
CVE-2023-35671

In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry…

Patch available
Fix from $1,600 2023-09-11
Android HIGH 7.8
CVE-2023-35667

In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic erro…

Patch available
Fix from $1,950 2023-09-11
Chrome CRITICAL 9.6
CVE-2019-13690

Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalat…

Fix: 75.0.3770.80+
Fix from $2,300 2023-08-25
Android HIGH 7.8
CVE-2023-21272

In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privil…

Patch available
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-21269

In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. Thi…

Patch available
Fix from $1,950 2023-08-14
Android MEDIUM 6.7
CVE-2023-20680

In adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execu…

Mitigation only
Fix from $1,600 2023-04-06
Android HIGH 7.8
CVE-2023-20655

In mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local code execution with no additional exe…

Mitigation only
Fix from $1,950 2023-04-06
Android HIGH 7.8
CVE-2023-21068

In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to local escalati…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-20995

In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This could lead t…

Mitigation only
Fix from $1,950 2023-03-24
Android MEDIUM 6.7
CVE-2022-32633

In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution pr…

Mitigation only
Fix from $1,600 2022-12-05
Drive HIGH 7.3
CVE-2022-3421

An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-…

Fix: 64.0+
Fix from $1,950 2022-10-17
Android MEDIUM 5.3
CVE-2022-36861

Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI priv…

Mitigation only
Fix from $1,600 2022-09-09
Android HIGH 7.5
CVE-2021-0891

An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Product: AndroidVersions: Androi…

Mitigation only
Fix from $1,950 2022-08-24
Android CRITICAL 9.8
CVE-2022-20361

In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. Th…

Patch available
Fix from $2,300 2022-08-10
Android HIGH 7.8
CVE-2022-20356

In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improp…

Patch available
Fix from $1,950 2022-08-10