Vulnerability index

Browse CVEs

1,761 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Android HIGH 7.8
CVE-2020-28343

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software. The NPU driver allows attac…

Mitigation only
Fix from $1,950 2020-11-08
Chrome CRITICAL 9.6
CVE-2020-16010 KEVEPSS 6%

Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to p…

Fix: 86.0.4240.185+
Fix from $2,300 2020-11-03
Chrome CRITICAL 9.6
CVE-2020-16011

Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to p…

Fix: 86.0.4240.183+
Fix from $2,300 2020-11-03
Chrome HIGH 8.8
CVE-2020-16002

Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF f…

Fix: 86.0.4240.111+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-16003

Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 86.0.4240.111+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-16004

Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 86.0.4240.183+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-16005

Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via…

Fix: 86.0.4240.183+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-16006

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 86.0.4240.183+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-16008

Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a craft…

Fix: 86.0.4240.183+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-16009 KEVEPSS 49%

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 86.0.241 / 86.0.622.63+
Fix from $1,950 2020-11-03
Chrome CRITICAL 9.6
CVE-2020-15999 KEVEPSS 44%

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 2.10.4 / 86.0.4240.111+
Fix from $2,300 2020-11-03
Chrome HIGH 8.8
CVE-2020-15995

Out of bounds write in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 86.0.4240.99+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-16000

Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a …

Fix: 86.0.4240.111+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-16001

Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 86.0.4240.111+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-15972

Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 86.0.4240.75+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-15975

Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 86.0.4240.75+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-15976

Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 86.0.4240.75+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-15979

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 86.0.4240.75+
Fix from $1,950 2020-11-03
Chrome HIGH 8.8
CVE-2020-15969

Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 11.1 / 14.0.2+
Fix from $1,950 2020-11-03
Android HIGH 7.8
CVE-2020-0420

In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escala…

Patch available
Fix from $1,950 2020-10-14
Android HIGH 7.8
CVE-2020-0421

In appendFormatV of String8.cpp, there is a possible out of bounds write due to incorrect error handling. This could lead to local escalation of priv…

Patch available
Fix from $1,950 2020-10-14
Android CRITICAL 9.1
CVE-2020-0283

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-163008257

Mitigation only
Fix from $2,300 2020-10-14
Android CRITICAL 9.1
CVE-2020-0367

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-162980455

Mitigation only
Fix from $2,300 2020-10-14
Android HIGH 7.8
CVE-2020-0408

In remove of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2020-10-14
Android MEDIUM 6.5
CVE-2020-0411

In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote information disc…

Patch available
Fix from $1,600 2020-10-14
Tensorflow CRITICAL 9.8
CVE-2020-15208

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `D…

Fix: 1.15.4 / 2.0.3+
Fix from $2,300 2020-09-25
Tensorflow HIGH 8.6
CVE-2020-15212

In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by insert…

Fix: 2.2.1 / 2.3.1+
Fix from $1,950 2020-09-25
Tensorflow HIGH 8.1
CVE-2020-15214

In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger a write out bounds / segmentation fault if the segment ids a…

Fix: 2.2.1 / 2.3.1+
Fix from $1,950 2020-09-25
Tensorflow MEDIUM 6.5
CVE-2020-15210

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Tensorflow CRITICAL 9.8
CVE-2020-15205

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This a…

Fix: 1.15.4 / 2.0.3+
Fix from $2,300 2020-09-25