Vulnerability index

Browse CVEs

150 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.8 CVE-2024-0025 In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local esc… Android Patch available Fix from $1,9502024-05-07 HIGH 8.8 CVE-2024-1675EPSS 11% Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a… Chrome 122.0.6261.57+ Fix from $1,9502024-02-21 HIGH 7.8 CVE-2024-0036 In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the b… Android Patch available Fix from $1,9502024-02-16 MEDIUM 6.5 CVE-2024-0032 In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could le… Android Patch available Fix from $1,6002024-02-16 MEDIUM 6.5 CVE-2023-2940 Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious ext… Chrome 114.0.5735.90+ Fix from $1,6002023-05-30 HIGH 7.8 CVE-2023-20927 In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local e… Android Mitigation only Fix from $1,9502023-02-15 HIGH 7.8 CVE-2022-39854 Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory. Android Mitigation only Fix from $1,9502022-10-07 HIGH 7.1 CVE-2022-33731 Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components. Android Mitigation only Fix from $1,9502022-08-05 HIGH 7.5 CVE-2022-31055 kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was bro… Kctf 1.6.0+ Fix from $1,9502022-06-13 MEDIUM 5.3 CVE-2022-30715 Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window. Android Mitigation only Fix from $1,6002022-06-07 MEDIUM 5.5 CVE-2022-28780 Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in We… Android Mitigation only Fix from $1,6002022-05-03 HIGH 7.8 CVE-2022-27836 Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local a… Android Mitigation only Fix from $1,9502022-04-11 MEDIUM 5.5 CVE-2022-27822 Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission. Android Mitigation only Fix from $1,6002022-04-11 MEDIUM 6.8 CVE-2022-26091 Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a fu… Android Mitigation only Fix from $1,6002022-04-11 MEDIUM 6.5 CVE-2021-22565 An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to genera… Exposure Notification Verification Server 1.1.2+ Fix from $1,6002021-12-09 HIGH 7.8 CVE-2021-25412 An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity wi… Android Mitigation only Fix from $1,9502021-06-11 HIGH 7.5 CVE-2019-5036 An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specia… Nest Cam Iq Indoor Firmware No fix yet Fix from $1,9502019-08-20 HIGH 7.8 CVE-2013-6272 The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended ac… Android after 4.4.2 Fix from $1,9502018-05-02 CRITICAL 9.8 CVE-2015-9064 In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send IMEI or IMEISV to the network on a network request be… Android Mitigation only Fix from $2,3002017-08-18 CRITICAL 9.8 CVE-2016-10382 In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not sufficient. Android Mitigation only Fix from $2,3002017-08-18 CRITICAL 9.8 CVE-2015-9040 In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in a GERAN API. Android No fix yet Fix from $2,3002017-08-18 CRITICAL 9.8 CVE-2015-9047 In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after bootup. Android No fix yet Fix from $2,3002017-08-18 MEDIUM 5.5 CVE-2015-3840 The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS a… Android after 5.1.1 Fix from $1,6002017-06-27 MEDIUM 5.5 CVE-2016-10335 In all Android releases from CAF using the Linux kernel, libtomcrypt was updated. Android No fix yet Fix from $1,6002017-06-13 HIGH 7.8 CVE-2014-9961 In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write pr… Android Mitigation only Fix from $1,9502017-06-13 HIGH 7.8 CVE-2015-9029 In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory. Android Mitigation only Fix from $1,9502017-06-13 MEDIUM 5.5 CVE-2015-9021 In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled. Android Mitigation only Fix from $1,6002017-06-13 MEDIUM 5.5 CVE-2015-9024 In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications. Android Mitigation only Fix from $1,6002017-06-13 MEDIUM 5.5 CVE-2016-10333 In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS. Android No fix yet Fix from $1,6002017-06-13 MEDIUM 5.5 CVE-2016-10334 In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten. Android No fix yet Fix from $1,6002017-06-13