Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 6.5
CVE-2019-9380

In the settings UI, there is a possible spoofing vulnerability due to a missing permission check. This could lead to a user mistakenly changing permi…

Mitigation only
Fix from $1,600 2019-09-27
Android MEDIUM 5.3
CVE-2019-9323

In the Wallpaper Manager service, there is a possible information disclosure due to a missing permission check. Any application can access wallpaper …

Mitigation only
Fix from $1,600 2019-09-27
Android HIGH 7.8
CVE-2019-9295

In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check. This could lead to a to local…

Mitigation only
Fix from $1,950 2019-09-27
Android HIGH 7.8
CVE-2019-9263

In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of pr…

Mitigation only
Fix from $1,950 2019-09-27
Android MEDIUM 5.5
CVE-2019-2137

In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission check. This could lead to local d…

Mitigation only
Fix from $1,600 2019-08-20
Android MEDIUM 5.5
CVE-2019-2117

In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permission check. This could lead t…

Mitigation only
Fix from $1,600 2019-07-08
Android HIGH 8.8
CVE-2019-2005

In onPermissionGrantResult of GrantPermissionsActivity.java, there is a possible incorrectly granted permission due to a missing permission check. Th…

Mitigation only
Fix from $1,950 2019-06-19
Android HIGH 7.8
CVE-2019-2091

In GetPermittedAccessibilityServicesForUser of DevicePolicyManagerService.java, there is a possible permissions bypass due to a missing permission ch…

Mitigation only
Fix from $1,950 2019-06-07
Android HIGH 7.8
CVE-2019-2092

In isSeparateProfileChallengeAllowed of DevicePolicyManagerService.java, there is a possible permissions bypass due to a missing permission check. Th…

Mitigation only
Fix from $1,950 2019-06-07
Android HIGH 7.8
CVE-2019-2098

In areNotificationsEnabledForPackage of NotificationManagerService.java, there is a possible permissions bypass due to a missing permissions check. T…

Mitigation only
Fix from $1,950 2019-06-07
Android HIGH 7.8
CVE-2019-2090

In isPackageDeviceAdminOnAnyUser of PackageManagerService.java, there is a possible permissions bypass due to a missing permissions check. This could…

Mitigation only
Fix from $1,950 2019-06-07
Android HIGH 7.8
CVE-2019-2026

In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission check. This could lead to local…

Patch available
Fix from $1,950 2019-04-19
Chrome HIGH 8.8
CVE-2019-5774

Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacke…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 7.4
CVE-2018-16081

Allowing the chrome.debugger API to run on file:// URLs in DevTools in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user t…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Android MEDIUM 5.5
CVE-2018-9548

In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. This could lead to local inform…

Patch available
Fix from $1,600 2018-12-06
Android MEDIUM 5.5
CVE-2018-9457

In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a permissions bypass. This cou…

Patch available
Fix from $1,600 2018-11-14
Android HIGH 7.8
CVE-2017-13247

In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileg…

Mitigation only
Fix from $1,950 2018-02-12
Android HIGH 7.8
CVE-2017-13209

In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which coul…

No fix yet
Fix from $1,950 2018-01-12
Android HIGH 7.8
CVE-2017-11042

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, ImsService and the IQtiImsExt AIDL AP…

Mitigation only
Fix from $1,950 2017-12-05
Android HIGH 7.8
CVE-2017-0554

An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its p…

Mitigation only
Fix from $1,950 2017-04-07