Vulnerability index

Browse CVEs

43 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Android MEDIUM 6.8
CVE-2020-10847

An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial recognition can be spoofed. The Samsung ID is SV…

Mitigation only
Fix from $1,600 2020-03-24
Android MEDIUM 5.5
CVE-2020-10846

An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devi…

Mitigation only
Fix from $1,600 2020-03-24
Android HIGH 8.8
CVE-2019-2018

In resetPasswordInternal of DevicePolicyManagerService.java, there is a possible bypass of password reset protection due to an unusual root cause. Re…

No fix yet
Fix from $1,950 2019-06-19
Android MEDIUM 6.8
CVE-2017-10709

The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressin…

Mitigation only
Fix from $1,600 2017-06-30
Android HIGH 7.8
CVE-2014-9952

In the Secure File System in all Android releases from CAF using the Linux kernel, a capture-replay vulnerability could potentially exist.

Patch available
Fix from $1,950 2017-06-06
Chrome MEDIUM 5.3
CVE-2016-5133

Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a prox…

Fix: after 51.0.2704.106
Fix from $1,600 2016-07-23
Chrome HIGH 7.5
CVE-2013-6643

The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on…

Fix: 32.0.1700.76 / 32.0.1700.77+
Fix from $1,950 2014-01-16
Chrome MEDIUM 6.8
CVE-2013-6634

The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an i…

Fix: after 31.0.1650.62
Fix from $1,600 2013-12-07
Chrome HIGH 7.5
CVE-2013-0910

Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser process and renderer processes during authorization o…

Fix: after 25.0.1364.126
Fix from $1,950 2013-03-05
Chrome MEDIUM 5.0
CVE-2010-4488

Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows remote attackers to cause a denial of service (appl…

Fix: after 8.0.552.214
Fix from $1,600 2010-12-07
Chrome MEDIUM 6.8
CVE-2009-2071

Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows…

Fix: after 1.0.154.52
Fix from $1,600 2009-06-15
Chrome MEDIUM 5.8
CVE-2009-2060

src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided…

Fix: after 1.0.154.52
Fix from $1,600 2009-06-15
Google Apps HIGH 7.5
CVE-2008-3891

The SAML Single Sign-On (SSO) Service for Google Apps allows remote service providers to impersonate users at arbitrary service providers via vectors…

Mitigation only
Fix from $1,950 2008-09-03