Vulnerability index

Browse CVEs

83 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Android HIGH 7.8
CVE-2023-20975

In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due to a permis…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-20971

In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic…

Mitigation only
Fix from $1,950 2023-03-24
Chrome MEDIUM 6.5
CVE-2023-0133

Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main ori…

Fix: 109.0.5414.74+
Fix from $1,600 2023-01-10
Chrome MEDIUM 6.8
CVE-2022-3048

Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscre…

Fix: 105.0.5195.52+
Fix from $1,600 2022-09-26
Chrome MEDIUM 6.3
CVE-2022-1499

Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via …

Fix: 101.0.4951.41+
Fix from $1,600 2022-07-26
Chrome CRITICAL 9.6
CVE-2022-1309

Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox…

Fix: 100.0.4896.88+
Fix from $2,300 2022-07-25
Chrome MEDIUM 6.1
CVE-2022-1132

Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation r…

Fix: 100.0.4896.60+
Fix from $1,600 2022-07-23
Android HIGH 7.8
CVE-2021-39799

In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local esca…

Patch available
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2021-39802

In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local esca…

Patch available
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2021-0694

In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due …

Mitigation only
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2022-27836

Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local a…

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2021-39789

In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no a…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39790

In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of …

Mitigation only
Fix from $1,950 2022-03-30
Chrome MEDIUM 6.5
CVE-2022-0309

Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a cra…

Fix: 97.0.4692.99+
Fix from $1,600 2022-02-12
Chrome MEDIUM 6.5
CVE-2022-0117

Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Fix: 97.0.4692.71+
Fix from $1,600 2022-02-12
Android HIGH 7.8
CVE-2021-39630

In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. T…

Mitigation only
Fix from $1,950 2022-01-14
Chrome HIGH 8.8
CVE-2021-38016

Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via…

Fix: 96.0.4664.45+
Fix from $1,950 2021-12-23
Chrome HIGH 8.8
CVE-2021-38017

Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions …

Fix: 96.0.4664.45+
Fix from $1,950 2021-12-23
Android HIGH 7.8
CVE-2021-0649

In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CO…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0645

In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, all…

Patch available
Fix from $1,950 2021-08-17
Chrome CRITICAL 9.6
CVE-2021-30571

Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious e…

Fix: 92.0.4515.107+
Fix from $2,300 2021-08-03
Android HIGH 7.8
CVE-2021-0571

In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possi…

Mitigation only
Fix from $1,950 2021-06-22
Android HIGH 7.8
CVE-2021-0472

In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could l…

Patch available
Fix from $1,950 2021-06-11
Android HIGH 7.1
CVE-2021-25410

Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an esc…

No fix yet
Fix from $1,950 2021-06-11
Chrome MEDIUM 6.5
CVE-2021-30533 KEVEPSS 17%

Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions vi…

Fix: 91.0.4472.77+
Fix from $1,600 2021-06-07
Chrome MEDIUM 6.5
CVE-2021-30534

Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions v…

Fix: 91.0.4472.77+
Fix from $1,600 2021-06-07
Chrome MEDIUM 5.4
CVE-2021-30539

Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content securit…

Fix: 91.0.4472.77+
Fix from $1,600 2021-06-07
Android HIGH 8.8
CVE-2021-25356

An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary a…

No fix yet
Fix from $1,950 2021-04-09
Android MEDIUM 5.5
CVE-2021-0382

In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permission check. This could lead to l…

Patch available
Fix from $1,600 2021-03-10
Android HIGH 7.8
CVE-2021-0376

In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access external files due to a permissions bypass. This…

Mitigation only
Fix from $1,950 2021-03-10