Vulnerability index

Browse CVEs

1,761 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Android CRITICAL 9.8
CVE-2017-13178

In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails.…

Patch available
Fix from $2,300 2018-01-12
Android CRITICAL 9.8
CVE-2017-13179

In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-of-bounds write due to a use after free. Both ps_…

Patch available
Fix from $2,300 2018-01-12
Android HIGH 7.8
CVE-2017-13180

In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use after free if a bad header causes the decoder to ge…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.8
CVE-2017-13166

An elevation of privilege vulnerability in the kernel v4l2 video driver. Product: Android. Versions: Android kernel. Android ID A-34624167.

Patch available
Fix from $1,950 2017-12-06
Android HIGH 7.5
CVE-2017-0852

A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0. Android ID: A-62815506.

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-0834

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Andr…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-11012

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when processing a specially crafted Q…

Patch available
Fix from $1,950 2017-11-16
Chrome HIGH 8.8
CVE-2017-5113

Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to …

Fix: 61.0.3163.79 / 61.0.3163.81+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5095

Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack co…

Fix: after 60.0.3112.78
Fix from $1,950 2017-10-27
Android HIGH 7.8
CVE-2017-11046

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when an audio driver ioctl handler is…

Mitigation only
Fix from $1,950 2017-10-10
Protobuf HIGH 8.8
CVE-2015-5237EPSS 5%

protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.

Fix: after 3.1.0
Fix from $1,950 2017-09-25
Android HIGH 7.8
CVE-2017-8260

In all Qualcomm products with Android releases from CAF using the Linux kernel, due to a type downcast, a value may improperly pass validation and ca…

Patch available
Fix from $1,950 2017-08-18
Android HIGH 7.8
CVE-2017-8272

In all Qualcomm products with Android releases from CAF using the Linux kernel, in a driver function, a value from userspace is not properly validate…

Patch available
Fix from $1,950 2017-08-18
Android HIGH 7.8
CVE-2017-8271

Out of bound memory write can happen in the MDSS Rotator driver in all Qualcomm products with Android releases from CAF using the Linux kernel by an …

Patch available
Fix from $1,950 2017-08-11
Android HIGH 7.8
CVE-2017-0750

A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions: Android kernel. Android ID: A-36817013.

Fix: after 7.1.2
Fix from $1,950 2017-08-09
Android HIGH 7.8
CVE-2017-0684

A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421…

Mitigation only
Fix from $1,950 2017-07-06
Android HIGH 7.8
CVE-2017-0701

A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36385715.

Mitigation only
Fix from $1,950 2017-07-06
Android MEDIUM 5.5
CVE-2017-0695

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID…

Mitigation only
Fix from $1,600 2017-07-06
Android HIGH 7.8
CVE-2017-0638

A remote code execution vulnerability in System UI component could enable an attacker using a specially crafted file to execute arbitrary code within…

Mitigation only
Fix from $1,950 2017-06-14
Android HIGH 7.8
CVE-2017-0663

A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context…

Mitigation only
Fix from $1,950 2017-06-14
Android HIGH 7.8
CVE-2017-8233

In a camera driver function in all Android releases from CAF using the Linux kernel, a bounds check is missing when writing into an array potentially…

Patch available
Fix from $1,950 2017-06-13
Chrome HIGH 8.8
CVE-2017-5029

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux …

Fix: after 57.0.2987.100
Fix from $1,950 2017-04-24
Chrome HIGH 8.8
CVE-2017-5032

PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allowed a remote attacker to pote…

Fix: after 57.0.2987.75
Fix from $1,950 2017-04-24
Chrome MEDIUM 6.3
CVE-2017-5044

Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android al…

Fix: after 57.0.2987.100
Fix from $1,600 2017-04-24
Android HIGH 7.8
CVE-2017-0416

An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a p…

Mitigation only
Fix from $1,950 2017-02-08
Android HIGH 7.8
CVE-2017-0417

An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a p…

Mitigation only
Fix from $1,950 2017-02-08
Android HIGH 7.8
CVE-2017-0418

An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a p…

Mitigation only
Fix from $1,950 2017-02-08
Chrome HIGH 8.8
CVE-2016-5198 KEVEPSS 35%

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisati…

Fix: 54.0.2840.85 / 54.0.2840.87+
Fix from $1,950 2017-01-19
Chrome HIGH 8.8
CVE-2016-5209

Bad casting in bitmap manipulation in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a…

Fix: after 54.0.2840.99
Fix from $1,950 2017-01-19
Chrome HIGH 8.8
CVE-2016-5210

Heap buffer overflow during TIFF image parsing in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Andr…

Fix: after 54.0.2840.99
Fix from $1,950 2017-01-19