Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2020-0107

In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local …

Patch available
Fix from $1,600 2020-07-17
Android HIGH 7.8
CVE-2020-0202

In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirements for capturing system traces due to a missing pe…

Patch available
Fix from $1,950 2020-06-11
Android MEDIUM 5.5
CVE-2020-0177

In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privilege to change network connectio…

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 5.5
CVE-2020-0178

In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This could lead to local informatio…

Patch available
Fix from $1,600 2020-06-11
Android HIGH 7.8
CVE-2020-0137

In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This …

Patch available
Fix from $1,950 2020-06-11
Android HIGH 7.8
CVE-2020-0105

In onKeyguardVisibilityChanged of key_store_service.cpp, there is a missing permission check. This could lead to local escalation of privilege, allow…

Patch available
Fix from $1,950 2020-05-14
Android HIGH 7.8
CVE-2020-0109

In simulatePackageSuspendBroadcast of NotificationManagerService.java, there is a missing permission check. This could lead to local escalation of pr…

Patch available
Fix from $1,950 2020-05-14
Android MEDIUM 5.5
CVE-2020-0106

In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a missing SDK version check. This could lead to local …

Mitigation only
Fix from $1,600 2020-05-14
Android HIGH 7.5
CVE-2020-12745

An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protection mechanism and access clipbo…

Mitigation only
Fix from $1,950 2020-05-11
Android HIGH 7.5
CVE-2018-21047

An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Factory Reset Protection (FRP) bypass via the voice assistant beca…

Mitigation only
Fix from $1,950 2020-04-08
Android CRITICAL 9.8
CVE-2018-21042

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK wi…

Mitigation only
Fix from $2,300 2020-04-08
Android HIGH 7.5
CVE-2017-18666

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Applications can send arbitrary premium SMS …

Mitigation only
Fix from $1,950 2020-04-07
Android HIGH 7.5
CVE-2017-18677

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Because of an unprotected Intent, an attacker can reset the config…

Mitigation only
Fix from $1,950 2020-04-07
Android CRITICAL 9.8
CVE-2016-11036

An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-…

Mitigation only
Fix from $2,300 2020-04-07
Android HIGH 7.5
CVE-2019-20614

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Allshare allows attackers to access sensitive information…

Mitigation only
Fix from $1,950 2020-03-24
Android MEDIUM 6.5
CVE-2019-20609

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can use Smartwatch to view Secure Folder notification content. The …

Mitigation only
Fix from $1,600 2020-03-24
Android HIGH 7.5
CVE-2019-20599

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Voice Assistant mishandles the notification audibility of…

Mitigation only
Fix from $1,950 2020-03-24
Android MEDIUM 5.3
CVE-2019-20555

An issue was discovered on Samsung mobile devices with N(7.x) software. The Gallery app allows attackers to view all pictures of a locked device. The…

Mitigation only
Fix from $1,600 2020-03-24
Android HIGH 7.8
CVE-2020-0084

In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local escalation of privilege by cre…

Mitigation only
Fix from $1,950 2020-03-10
Android HIGH 7.8
CVE-2020-0085

In setBluetoothTethering of PanService.java, there is a possible permission bypass due to a missing permission check. This could lead to local escala…

Mitigation only
Fix from $1,950 2020-03-10
Android HIGH 7.8
CVE-2020-0054

In WifiNetworkSuggestionsManager of WifiNetworkSuggestionsManager.java, there is a possible permission revocation due to a missing permission check. …

Patch available
Fix from $1,950 2020-03-10
Android MEDIUM 5.5
CVE-2020-0035

In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This could lead to local informati…

Mitigation only
Fix from $1,600 2020-03-10
Android MEDIUM 5.5
CVE-2020-0023

In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission ch…

Patch available
Fix from $1,600 2020-02-13
Chrome MEDIUM 6.5
CVE-2020-6393

Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTM…

Fix: 80.0.3987.87+
Fix from $1,600 2020-02-11
Chrome MEDIUM 6.5
CVE-2019-13748

Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive in…

Fix: 79.0.3945.79+
Fix from $1,600 2019-12-10
Android MEDIUM 5.5
CVE-2019-2229

In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. This could lead to local informa…

Patch available
Fix from $1,600 2019-12-06
Android HIGH 7.8
CVE-2019-2218

In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check. This could…

Mitigation only
Fix from $1,950 2019-12-06
Chrome MEDIUM 6.5
CVE-2019-5865

Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer proc…

Fix: 76.0.3809.87+
Fix from $1,600 2019-11-25
Chrome HIGH 7.4
CVE-2019-13673

Insufficient data validation in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a craf…

Fix: 77.0.3865.75+
Fix from $1,950 2019-11-25
Android MEDIUM 5.5
CVE-2019-2110

In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure screen due to a missing permission check. This co…

Patch available
Fix from $1,600 2019-10-11