Vulnerability index

Browse CVEs

150 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Android HIGH 7.8
CVE-2024-0025

In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local esc…

Patch available
Fix from $1,950 2024-05-07
Chrome HIGH 8.8
CVE-2024-1675EPSS 11%

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a…

Fix: 122.0.6261.57+
Fix from $1,950 2024-02-21
Android HIGH 7.8
CVE-2024-0036

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the b…

Patch available
Fix from $1,950 2024-02-16
Android MEDIUM 6.5
CVE-2024-0032

In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could le…

Patch available
Fix from $1,600 2024-02-16
Chrome MEDIUM 6.5
CVE-2023-2940

Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious ext…

Fix: 114.0.5735.90+
Fix from $1,600 2023-05-30
Android HIGH 7.8
CVE-2023-20927

In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local e…

Mitigation only
Fix from $1,950 2023-02-15
Android HIGH 7.8
CVE-2022-39854

Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.

Mitigation only
Fix from $1,950 2022-10-07
Android HIGH 7.1
CVE-2022-33731

Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

Mitigation only
Fix from $1,950 2022-08-05
Kctf HIGH 7.5
CVE-2022-31055

kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was bro…

Fix: 1.6.0+
Fix from $1,950 2022-06-13
Android MEDIUM 5.3
CVE-2022-30715

Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.

Mitigation only
Fix from $1,600 2022-06-07
Android MEDIUM 5.5
CVE-2022-28780

Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in We…

Mitigation only
Fix from $1,600 2022-05-03
Android HIGH 7.8
CVE-2022-27836

Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local a…

Mitigation only
Fix from $1,950 2022-04-11
Android MEDIUM 5.5
CVE-2022-27822

Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.

Mitigation only
Fix from $1,600 2022-04-11
Android MEDIUM 6.8
CVE-2022-26091

Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a fu…

Mitigation only
Fix from $1,600 2022-04-11
Exposure Notification Verification Server MEDIUM 6.5
CVE-2021-22565

An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to genera…

Fix: 1.1.2+
Fix from $1,600 2021-12-09
Android HIGH 7.8
CVE-2021-25412

An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity wi…

Mitigation only
Fix from $1,950 2021-06-11
Nest Cam Iq Indoor Firmware HIGH 7.5
CVE-2019-5036

An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specia…

No fix yet
Fix from $1,950 2019-08-20
Android HIGH 7.8
CVE-2013-6272

The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended ac…

Fix: after 4.4.2
Fix from $1,950 2018-05-02
Android CRITICAL 9.8
CVE-2015-9064

In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send IMEI or IMEISV to the network on a network request be…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2016-10382

In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not sufficient.

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9040

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in a GERAN API.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9047

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after bootup.

No fix yet
Fix from $2,300 2017-08-18
Android MEDIUM 5.5
CVE-2015-3840

The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS a…

Fix: after 5.1.1
Fix from $1,600 2017-06-27
Android MEDIUM 5.5
CVE-2016-10335

In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.

No fix yet
Fix from $1,600 2017-06-13
Android HIGH 7.8
CVE-2014-9961

In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write pr…

Mitigation only
Fix from $1,950 2017-06-13
Android HIGH 7.8
CVE-2015-9029

In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory.

Mitigation only
Fix from $1,950 2017-06-13
Android MEDIUM 5.5
CVE-2015-9021

In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.

Mitigation only
Fix from $1,600 2017-06-13
Android MEDIUM 5.5
CVE-2015-9024

In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.

Mitigation only
Fix from $1,600 2017-06-13
Android MEDIUM 5.5
CVE-2016-10333

In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.

No fix yet
Fix from $1,600 2017-06-13
Android MEDIUM 5.5
CVE-2016-10334

In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.

No fix yet
Fix from $1,600 2017-06-13