Vulnerability index

Browse CVEs

150 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Android HIGH 7.8
CVE-2015-9006

In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vulnerability could potentially e…

Patch available
Fix from $1,950 2017-06-06
Android HIGH 7.8
CVE-2016-10237

If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android releases …

Patch available
Fix from $1,950 2017-05-16
Android HIGH 8.8
CVE-2016-2433

The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to execute arbitrary code in th…

Fix: after 6.0.1
Fix from $1,950 2017-04-21
Android CRITICAL 9.8
CVE-2016-8418

A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of th…

Fix: after 6.0.1
Fix from $2,300 2017-02-08
Chrome HIGH 8.8
CVE-2016-5206

The PDF plugin in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly followed redirects, which …

Fix: after 54.0.2840.99
Fix from $1,950 2017-01-19
Chrome MEDIUM 6.5
CVE-2016-5217

The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly permitted access to pr…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Android HIGH 7.0
CVE-2016-6783

An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the contex…

Fix: after 7.1.0
Fix from $1,950 2017-01-12
Android HIGH 7.0
CVE-2016-6784

An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the contex…

Mitigation only
Fix from $1,950 2017-01-12
Android HIGH 7.8
CVE-2016-6768

A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code …

Mitigation only
Fix from $1,950 2017-01-12
Android MEDIUM 5.5
CVE-2016-6763

A denial of service vulnerability in Telephony could enable a local malicious application to use a specially crafted file to cause a device hang or r…

Mitigation only
Fix from $1,600 2017-01-12
Android MEDIUM 5.3
CVE-2016-6771

An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functions beyond its access level. T…

Mitigation only
Fix from $1,600 2017-01-12
Chrome MEDIUM 6.5
CVE-2016-5189

Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted navigation to blob URLs with non-canonical origin…

Fix: after 53.0.2785.143
Fix from $1,600 2016-12-18
Chrome MEDIUM 6.5
CVE-2016-5192

Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrackLoader, which allowed a remote attacker to bypas…

Fix: after 53.0.2785.143
Fix from $1,600 2016-12-18
Android MEDIUM 5.9
CVE-2016-5341

The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial of service (GPS signal-acquisition delay) via an …

Fix: after 7.1.0
Fix from $1,600 2016-12-06
Android MEDIUM 5.5
CVE-2016-6747

A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a dev…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android CRITICAL 9.8
CVE-2016-6725

A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary …

Fix: after 7.0
Fix from $2,300 2016-11-25
Android MEDIUM 5.5
CVE-2016-6724

A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-1…

Fix: 4.4.4 / 5.0.2+
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6719

An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 20…

Fix: 4.4.4 / 5.0.2+
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6716

An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could allow a local malicious application to create sho…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6715

An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11…

Fix: 4.4.4 / 5.0.2+
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6714

A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a …

Fix: after 6.0.1
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6713

A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a …

Fix: after 6.0.1
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6708

An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android HIGH 7.8
CVE-2016-6703

A remote code execution vulnerability in an Android runtime library in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befo…

Fix: after 6.0.1
Fix from $1,950 2016-11-25
Android HIGH 7.8
CVE-2016-6702

A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker usi…

Mitigation only
Fix from $1,950 2016-11-25
Android HIGH 7.8
CVE-2016-6701

A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause me…

Fix: after 7.0
Fix from $1,950 2016-11-25
Android MEDIUM 5.5
CVE-2016-6690

The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Nexus Player devices allows attackers to cau…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3925

server/wifi/anqp/ANQPFactory.java in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attackers to cause a denial of service (blocked W…

Patch available
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3923

The Accessibility services in Android 7.0 before 2016-10-01 mishandle motion events, which allows attackers to conduct touchjacking attacks and conse…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 6.5
CVE-2016-3882

Off-by-one error in server/wifi/anqp/VenueNameElement.java in Wi-Fi in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows remote attacker…

Patch available
Fix from $1,600 2016-10-10