Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 6.7 CVE-2024-0044 In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to loc… Android Patch available Fix from $1,6002024-03-11 HIGH 7.8 CVE-2022-42544 In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to improper input validation. T… Android Patch available Fix from $1,9502022-12-16 HIGH 8.0 CVE-2021-0594 In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation. This could lead to remote … Android Mitigation only Fix from $1,9502021-07-14 HIGH 7.3 CVE-2021-0553 In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local esc… Android Mitigation only Fix from $1,9502021-06-22 MEDIUM 6.5 CVE-2021-0551 In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. Th… Android Mitigation only Fix from $1,6002021-06-22 HIGH 7.8 CVE-2021-0567 In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of… Android Mitigation only Fix from $1,9502021-06-22 MEDIUM 6.5 CVE-2021-30540 Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafte… Chrome 91.0.4472.77+ Fix from $1,6002021-06-07 HIGH 8.8 CVE-2021-30506 Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a we… Chrome 90.0.4430.212+ Fix from $1,9502021-06-04 MEDIUM 6.5 CVE-2021-21137EPSS 6% Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information… Chrome 88.0.705.50 / 88.0.4324.96+ Fix from $1,6002021-02-09 MEDIUM 6.5 CVE-2021-21141EPSS 5% Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy v… Chrome 88.0.705.74 / 88.0.4324.96+ Fix from $1,6002021-02-09 CRITICAL 9.8 CVE-2018-21051 An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trus… Android Mitigation only Fix from $2,3002020-04-08 CRITICAL 9.8 CVE-2017-18652 An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic librari… Android Mitigation only Fix from $2,3002020-04-07 HIGH 7.8 CVE-2014-7952 The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveragi… Android No fix yet Fix from $1,9502018-01-12 CRITICAL 9.8 CVE-2016-1155 HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or … Android Mitigation only Fix from $2,3002017-04-13 HIGH 8.8 CVE-2016-6754 A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote a… Android after 6.0.1 Fix from $1,9502016-11-25 MEDIUM 6.8 CVE-2011-2855 Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a den… Chrome 5.1 / 5.1.4+ Fix from $1,6002011-09-19 MEDIUM 6.8 CVE-2011-2805 Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vecto… Chrome 5.0 / 5.1.1+ Fix from $1,6002011-08-03