Vulnerability index

Browse CVEs

150 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Chrome MEDIUM 6.5
CVE-2016-5176

Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.

Fix: after 53.0.2785.101
Fix from $1,600 2016-09-29
Chrome HIGH 7.1
CVE-2016-5173

The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers t…

Fix: after 53.0.2785.101
Fix from $1,950 2016-09-25
Android MEDIUM 5.5
CVE-2016-3899

OMXCodec.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 bef…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3898

Telephony in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows attackers to cause a denial of s…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3884

server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 la…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3883

internal/telephony/SMSDispatcher.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3880

Multiple buffer overflows in rtsp/ASessionDescription.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x bef…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3879

arm-wt-22k/lib_src/eas_mdls.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows re…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3878

decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-09-01 mishandles the case of decoding zero MBs, which allows remote attackers to cause…

Patch available
Fix from $1,600 2016-09-11
Android HIGH 7.8
CVE-2016-3863

Multiple stack-based buffer overflows in the AVCC reassembly implementation in Utils.cpp in libstagefright in MediaMuxer in Android 4.x before 4.4.4,…

Patch available
Fix from $1,950 2016-09-11
Android HIGH 7.5
CVE-2015-3854

packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission r…

Patch available
Fix from $1,950 2016-08-07
Chrome CRITICAL 9.8
CVE-2016-5144

The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase…

Fix: after 52.0.2743.82
Fix from $2,300 2016-08-07
Android HIGH 7.8
CVE-2014-9865

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly restrict user-space …

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android MEDIUM 5.5
CVE-2016-3839

Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of servic…

Patch available
Fix from $1,600 2016-08-05
Android MEDIUM 5.5
CVE-2016-3838

Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that …

Patch available
Fix from $1,600 2016-08-05
Android HIGH 7.5
CVE-2014-9901

The Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices makes incorrect snprintf calls, which allows remote attackers to cau…

Fix: after 6.0.1
Fix from $1,950 2016-08-05
Chrome MEDIUM 6.5
CVE-2016-5130

content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, …

Fix: after 51.0.2704.106
Fix from $1,600 2016-07-23
Android MEDIUM 5.5
CVE-2016-3818

libc in Android 4.x before 4.4.4 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28…

Mitigation only
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2014-9798

platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tag…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Chrome HIGH 8.8
CVE-2016-1697

The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not pre…

Fix: after 51.0.2704.63
Fix from $1,950 2016-06-05
Chrome HIGH 8.8
CVE-2016-1696

The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the…

Fix: after 51.0.2704.63
Fix from $1,950 2016-06-05
Chrome MEDIUM 5.3
CVE-2016-1694

browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier fo…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Chrome MEDIUM 6.1
CVE-2016-1682

The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used i…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Chrome HIGH 8.8
CVE-2016-1672

The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 m…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Chrome HIGH 8.8
CVE-2016-1668

The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.10…

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Chrome HIGH 7.5
CVE-2016-1656

The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unsp…

Fix: after 49.0.2623.112
Fix from $1,950 2016-04-18
Chrome MEDIUM 6.3
CVE-2016-1638

extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web …

Fix: after 48.0.2564.116
Fix from $1,600 2016-03-06
Chrome HIGH 7.5
CVE-2015-1304

object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, whi…

Fix: after 45.0.2454.93
Fix from $1,950 2015-10-12
Android HIGH 7.2
CVE-2015-3860

packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters i…

Fix: after 5.1
Fix from $1,950 2015-10-01
Chrome MEDIUM 5.0
CVE-2014-7905

Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, whic…

Fix: after 39.0.2171.45
Fix from $1,600 2014-11-19