Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Android HIGH 7.8
CVE-2025-48535

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywh…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32312

In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2018-9474

In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to…

Patch available
Fix from $1,950 2024-11-20
Androidx.car.app HIGH 7.5
CVE-2024-10382

There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction…

Fix: after 1.4.0
Fix from $1,950 2024-11-20
Android HIGH 7.8
CVE-2024-43080

In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local esc…

Patch available
Fix from $1,950 2024-11-13
Reverb HIGH 7.8
CVE-2024-8375

There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to represent an arbitrary object in C+…

Fix: 2024-08-05+
Fix from $1,950 2024-09-19
Android HIGH 7.8
CVE-2024-31317

In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe des…

Patch available
Fix from $1,950 2024-07-09
Android MEDIUM 5.5
CVE-2024-0047

In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to …

Patch available
Fix from $1,600 2024-03-11
Android MEDIUM 5.5
CVE-2023-40121

In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local informatio…

Patch available
Fix from $1,600 2023-10-27
Android HIGH 7.8
CVE-2023-35669

In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deseriali…

Patch available
Fix from $1,950 2023-09-11
Android MEDIUM 6.7
CVE-2023-21209

In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of …

Mitigation only
Fix from $1,600 2023-06-28
Android MEDIUM 5.5
CVE-2023-21205

In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local inform…

Mitigation only
Fix from $1,600 2023-06-28
Android HIGH 7.8
CVE-2023-21124

In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege…

Patch available
Fix from $1,950 2023-06-15
Android HIGH 7.8
CVE-2023-20944

In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local esca…

Patch available
Fix from $1,950 2023-02-28
Android HIGH 7.8
CVE-2022-32601

In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additio…

Mitigation only
Fix from $1,950 2022-11-08
Android HIGH 7.8
CVE-2022-26471

In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no a…

Mitigation only
Fix from $1,950 2022-10-07
Android HIGH 7.8
CVE-2022-26472

In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no additio…

Mitigation only
Fix from $1,950 2022-10-07
Android MEDIUM 5.0
CVE-2022-20195

In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial o…

Mitigation only
Fix from $1,600 2022-06-15
Android HIGH 7.8
CVE-2021-0970

In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalat…

Patch available
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0685

In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This c…

Patch available
Fix from $1,950 2021-10-06
Tensorflow HIGH 8.8
CVE-2021-37678

TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary …

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12
Android MEDIUM 5.5
CVE-2020-0132

In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local …

Patch available
Fix from $1,600 2020-06-11
Android HIGH 7.8
CVE-2020-0082

In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead …

Mitigation only
Fix from $1,950 2020-04-17
Android CRITICAL 9.8
CVE-2019-9365

In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional…

Mitigation only
Fix from $2,300 2019-09-27
Android MEDIUM 5.5
CVE-2019-9373

In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of servic…

Mitigation only
Fix from $1,600 2019-09-27
Chrome HIGH 8.8
CVE-2018-6162

Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via …

Fix: 68.0.3440.75+
Fix from $1,950 2019-01-09
Android HIGH 7.8
CVE-2017-13286

In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a l…

Mitigation only
Fix from $1,950 2018-04-04
Android HIGH 7.8
CVE-2017-0806

An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0…

Patch available
Fix from $1,950 2017-10-04
Chrome HIGH 7.5
CVE-2010-4574

The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not…

Fix: 8.0.552.224 / 8.0.552.343+
Fix from $1,950 2010-12-22
Chrome HIGH 9.3
CVE-2010-3258

The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attac…

Fix: 6.0.472.53+
Fix from $1,950 2010-09-07