Vulnerability index

Browse CVEs

66 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Android CRITICAL 9.1
CVE-2018-21081

An issue was discovered on Samsung mobile devices with N(7.x) software. In Dual Messenger, the second app can use the runtime permissions of the firs…

Mitigation only
Fix from $2,300 2020-04-08
Android HIGH 7.8
CVE-2019-2089

In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could lead to a local escalation of …

Mitigation only
Fix from $1,950 2020-03-15
Android MEDIUM 5.5
CVE-2019-9464

In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is an incorrect warning indicati…

Patch available
Fix from $1,600 2019-12-06
Chrome MEDIUM 6.5
CVE-2019-13665

Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file download protection via a cr…

Fix: 77.0.3865.75+
Fix from $1,600 2019-11-25
Chrome MEDIUM 6.5
CVE-2019-13677

Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a cra…

Fix: 77.0.3865.75+
Fix from $1,600 2019-11-25
Chrome CRITICAL 9.1
CVE-2016-5202

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 …

Fix: 54.0.2840.98 / 54.0.2840.99+
Fix from $2,300 2019-10-25
Android HIGH 7.8
CVE-2019-9378

In the Activity Manager service, there is a possible permission bypass due to incorrect permission check. This could lead to local escalation of priv…

Mitigation only
Fix from $1,950 2019-09-27
Android HIGH 7.8
CVE-2019-2023

In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could al…

Mitigation only
Fix from $1,950 2019-06-19
Android MEDIUM 5.5
CVE-2019-2001

The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional execution privileges needed. U…

Mitigation only
Fix from $1,600 2019-02-28
Android HIGH 7.8
CVE-2018-11964

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Exposing the hashed content in /etc/passwd…

Patch available
Fix from $1,950 2018-12-20
Chrome MEDIUM 6.5
CVE-2018-18349

Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinc…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
Chrome MEDIUM 6.5
CVE-2018-18352

Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to by…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
Android HIGH 7.5
CVE-2018-15835

Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.

Fix: after 9.0
Fix from $1,950 2018-11-30
Android HIGH 7.8
CVE-2018-11914

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11907

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11908

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11909

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11910

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11913

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of dev nodes may le…

Patch available
Fix from $1,950 2018-11-27
Chrome HIGH 8.8
CVE-2018-6057

Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process t…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6040

Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially bypass content security pol…

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Android CRITICAL 9.8
CVE-2018-14981

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The LG ID is LVE-SMP-180005.

Mitigation only
Fix from $2,300 2018-08-17
Android CRITICAL 9.8
CVE-2018-14982

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is LVE-SMP-180004.

Mitigation only
Fix from $2,300 2018-08-17
Android CRITICAL 9.8
CVE-2018-15482

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.

Mitigation only
Fix from $2,300 2018-08-17
Android HIGH 7.8
CVE-2017-13236

In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege wi…

No fix yet
Fix from $1,950 2018-02-12
Android HIGH 7.8
CVE-2017-0830

An elevation of privilege vulnerability in the Android framework (device policy client). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-0831

An elevation of privilege vulnerability in the Android framework (window manager). Product: Android. Versions: 8.0. Android ID: A-37442941.

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.5
CVE-2017-0845

A denial of service vulnerability in the Android framework (syncstorageengine). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 8.8
CVE-2017-0784

A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android …

Patch available
Fix from $1,950 2017-09-08
Android HIGH 7.8
CVE-2017-0752

A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.…

Patch available
Fix from $1,950 2017-09-08