Vulnerability index

Browse CVEs

1,761 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
CRITICAL 9.8 CVE-2017-13178 In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails.… Android Patch available Fix from $2,3002018-01-12 CRITICAL 9.8 CVE-2017-13179 In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-of-bounds write due to a use after free. Both ps_… Android Patch available Fix from $2,3002018-01-12 HIGH 7.8 CVE-2017-13180 In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use after free if a bad header causes the decoder to ge… Android Patch available Fix from $1,9502018-01-12 HIGH 7.8 CVE-2017-13166 An elevation of privilege vulnerability in the kernel v4l2 video driver. Product: Android. Versions: Android kernel. Android ID A-34624167. Android Patch available Fix from $1,9502017-12-06 HIGH 7.5 CVE-2017-0852 A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0. Android ID: A-62815506. Android Patch available Fix from $1,9502017-11-16 HIGH 7.8 CVE-2017-0834 A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Andr… Android Patch available Fix from $1,9502017-11-16 HIGH 7.8 CVE-2017-11012 In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when processing a specially crafted Q… Android Patch available Fix from $1,9502017-11-16 HIGH 8.8 CVE-2017-5113 Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to … Chrome 61.0.3163.79 / 61.0.3163.81+ Fix from $1,9502017-10-27 HIGH 8.8 CVE-2017-5095 Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack co… Chrome after 60.0.3112.78 Fix from $1,9502017-10-27 HIGH 7.8 CVE-2017-11046 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when an audio driver ioctl handler is… Android Mitigation only Fix from $1,9502017-10-10 HIGH 8.8 CVE-2015-5237EPSS 5% protobuf allows remote authenticated attackers to cause a heap-based buffer overflow. Protobuf after 3.1.0 Fix from $1,9502017-09-25 HIGH 7.8 CVE-2017-8260 In all Qualcomm products with Android releases from CAF using the Linux kernel, due to a type downcast, a value may improperly pass validation and ca… Android Patch available Fix from $1,9502017-08-18 HIGH 7.8 CVE-2017-8272 In all Qualcomm products with Android releases from CAF using the Linux kernel, in a driver function, a value from userspace is not properly validate… Android Patch available Fix from $1,9502017-08-18 HIGH 7.8 CVE-2017-8271 Out of bound memory write can happen in the MDSS Rotator driver in all Qualcomm products with Android releases from CAF using the Linux kernel by an … Android Patch available Fix from $1,9502017-08-11 HIGH 7.8 CVE-2017-0750 A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions: Android kernel. Android ID: A-36817013. Android after 7.1.2 Fix from $1,9502017-08-09 HIGH 7.8 CVE-2017-0684 A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421… Android Mitigation only Fix from $1,9502017-07-06 HIGH 7.8 CVE-2017-0701 A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36385715. Android Mitigation only Fix from $1,9502017-07-06 MEDIUM 5.5 CVE-2017-0695 A denial of service vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID… Android Mitigation only Fix from $1,6002017-07-06 HIGH 7.8 CVE-2017-0638 A remote code execution vulnerability in System UI component could enable an attacker using a specially crafted file to execute arbitrary code within… Android Mitigation only Fix from $1,9502017-06-14 HIGH 7.8 CVE-2017-0663 A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context… Android Mitigation only Fix from $1,9502017-06-14 HIGH 7.8 CVE-2017-8233 In a camera driver function in all Android releases from CAF using the Linux kernel, a bounds check is missing when writing into an array potentially… Android Patch available Fix from $1,9502017-06-13 HIGH 8.8 CVE-2017-5029 The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux … Chrome after 57.0.2987.100 Fix from $1,9502017-04-24 HIGH 8.8 CVE-2017-5032 PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allowed a remote attacker to pote… Chrome after 57.0.2987.75 Fix from $1,9502017-04-24 MEDIUM 6.3 CVE-2017-5044 Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android al… Chrome after 57.0.2987.100 Fix from $1,6002017-04-24 HIGH 7.8 CVE-2017-0416 An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a p… Android Mitigation only Fix from $1,9502017-02-08 HIGH 7.8 CVE-2017-0417 An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a p… Android Mitigation only Fix from $1,9502017-02-08 HIGH 7.8 CVE-2017-0418 An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a p… Android Mitigation only Fix from $1,9502017-02-08 HIGH 8.8 CVE-2016-5198 KEVEPSS 35% V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisati… Chrome 54.0.2840.85 / 54.0.2840.87+ Fix from $1,9502017-01-19 HIGH 8.8 CVE-2016-5209 Bad casting in bitmap manipulation in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a… Chrome after 54.0.2840.99 Fix from $1,9502017-01-19 HIGH 8.8 CVE-2016-5210 Heap buffer overflow during TIFF image parsing in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Andr… Chrome after 54.0.2840.99 Fix from $1,9502017-01-19