Vulnerability index

Browse CVEs

134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Android MEDIUM 5.5
CVE-2020-0294

In bindWallpaperComponentLocked of WallpaperManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lea…

Mitigation only
Fix from $1,600 2020-09-18
Android HIGH 7.8
CVE-2020-0374

In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution pr…

Mitigation only
Fix from $1,950 2020-09-17
Android HIGH 7.8
CVE-2020-0275

In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypa…

Mitigation only
Fix from $1,950 2020-09-17
Android HIGH 7.8
CVE-2020-0388

In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to an empty mutable PendingInten…

Patch available
Fix from $1,950 2020-09-17
Android MEDIUM 5.5
CVE-2020-0390

In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution pri…

Patch available
Fix from $1,600 2020-09-17
Android MEDIUM 6.7
CVE-2020-0122

In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions…

Patch available
Fix from $1,600 2020-07-17
Android MEDIUM 5.5
CVE-2020-15578

An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime permissions. The Samsung ID …

Mitigation only
Fix from $1,600 2020-07-07
Guest Oslogin HIGH 7.8
CVE-2020-8903

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/co…

Fix: after 20200507.00
Fix from $1,950 2020-06-22
Guest Oslogin HIGH 7.8
CVE-2020-8907

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/co…

Fix: after 20200507.00
Fix from $1,950 2020-06-22
Guest Oslogin HIGH 7.8
CVE-2020-8933

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/co…

Fix: after 20200507.00
Fix from $1,950 2020-06-22
Android HIGH 7.8
CVE-2020-0215

In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypass. This could lead to local e…

Mitigation only
Fix from $1,950 2020-06-11
Android HIGH 7.8
CVE-2020-0208

In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additi…

Patch available
Fix from $1,950 2020-06-11
Android HIGH 7.8
CVE-2020-0209

In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additi…

Patch available
Fix from $1,950 2020-06-11
Android HIGH 7.3
CVE-2020-0133

In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to lo…

Patch available
Fix from $1,950 2020-06-11
Chrome MEDIUM 6.5
CVE-2020-6497

Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a c…

Fix: 83.0.4103.88+
Fix from $1,600 2020-06-03
Chrome MEDIUM 6.5
CVE-2020-6498

Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a c…

Fix: 83.0.4103.88+
Fix from $1,600 2020-06-03
Chrome MEDIUM 6.5
CVE-2020-6501

Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a craft…

Fix: 80.0.3987.87+
Fix from $1,600 2020-06-03
Chrome MEDIUM 6.5
CVE-2020-6502

Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.

Fix: 80.0.3987.87+
Fix from $1,600 2020-06-03
Chrome MEDIUM 6.5
CVE-2020-6495

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malic…

Fix: 83.0.4103.97+
Fix from $1,600 2020-06-03
Chrome MEDIUM 6.5
CVE-2020-6487

Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6480

Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation restrictions via U…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6482

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6483

Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a …

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6484

Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6471

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic…

Fix: 83.0.4103.61+
Fix from $2,300 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6476

Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious e…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6469

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic…

Fix: 83.0.4103.61+
Fix from $2,300 2020-05-21
Android HIGH 7.8
CVE-2020-0024

In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions bypass. This could lead to local…

Patch available
Fix from $1,950 2020-05-14
Chrome MEDIUM 6.5
CVE-2020-6456

Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via …

Fix: 81.0.4044.92+
Fix from $1,600 2020-04-13
Chrome HIGH 8.8
CVE-2020-6439

Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted H…

Fix: 81.0.4044.92+
Fix from $1,950 2020-04-13