Vulnerability index

Browse CVEs

1,761 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Android HIGH 7.8
CVE-2018-9584

In nfc_ncif_set_config_status of nfc_ncif.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possibl…

Mitigation only
Fix from $1,950 2019-02-11
Android HIGH 7.8
CVE-2018-9585

In nfc_ncif_proc_get_routing of nfc_ncif.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible…

Patch available
Fix from $1,950 2019-02-11
Android HIGH 7.8
CVE-2018-12010

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Absence of length sanity check may lead to…

Patch available
Fix from $1,950 2019-02-11
Chrome HIGH 8.8
CVE-2018-6144

Off-by-one error in PDFium in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted PD…

Fix: 67.0.3396.62+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-6153

A precision error in Skia in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform an out…

Fix: 68.0.3440.75+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-6162

Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via …

Fix: 68.0.3440.75+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-6170

A bad cast in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

Fix: 68.0.3440.75+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-6120

An integer overflow that could lead to an attacker-controlled heap out-of-bounds write in PDFium in Google Chrome prior to 66.0.3359.170 allowed a re…

Fix: 67.0.3396.62+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-6126EPSS 8%

A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTM…

Fix: 67.0.3396.62+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6123

A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 67.0.3396.62+
Fix from $1,600 2019-01-09
Chrome HIGH 8.8
CVE-2018-16085

A use after free in ResourceCoordinator in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2017-15428EPSS 18%

Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3…

Fix: 62.0.3202.94+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-16071

A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted vide…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16066

A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16067

A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome HIGH 8.8
CVE-2017-15401

A memory corruption bug in WebAssembly could lead to out of bounds read and write through V8 in WebAssembly in Google Chrome prior to 62.0.3202.62 al…

Fix: 62.0.3202.62+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-18340

Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption v…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18341

An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploi…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18342

Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds write in V8 in Google Chrome…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18343

Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploi…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18356

An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-17480 KEVEPSS 36%

Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 all…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-17481

Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remote attacker to potentially exploit heap corruption…

Fix: 71.0.3578.98+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18335

Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18336

Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18337

Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentiall…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18338

Incorrect, thread-unsafe use of SkImage in Canvas in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corrup…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18339

Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a …

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Android CRITICAL 9.8
CVE-2018-9578

In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write due to a missing bounds check. This could lead t…

Mitigation only
Fix from $2,300 2018-12-07
Android HIGH 8.8
CVE-2018-9569

In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound write due to incorrect bounds check. This could lead …

Mitigation only
Fix from $1,950 2018-12-07