Vulnerability index

Browse CVEs

83 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Chrome MEDIUM 6.5
CVE-2021-21182

Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer proc…

Fix: 89.0.4389.72+
Fix from $1,600 2021-03-09
Android HIGH 7.8
CVE-2021-0317

In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalat…

Patch available
Fix from $1,950 2021-01-11
Android HIGH 7.3
CVE-2021-0319

In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without approp…

Patch available
Fix from $1,950 2021-01-11
Android HIGH 7.8
CVE-2020-0479

In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malic…

Patch available
Fix from $1,950 2020-12-15
Android CRITICAL 9.8
CVE-2020-25055

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unp…

Mitigation only
Fix from $2,300 2020-08-31
Oauth Client Library For Java CRITICAL 9.1
CVE-2020-7692

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by…

Fix: 1.31.0+
Fix from $2,300 2020-07-09
Android HIGH 7.8
CVE-2020-0115

In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for a…

Patch available
Fix from $1,950 2020-06-10
Android HIGH 7.5
CVE-2020-13834

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folder does not properly restrict …

Mitigation only
Fix from $1,950 2020-06-04
Android HIGH 7.8
CVE-2020-0097

In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This could lead t…

Patch available
Fix from $1,950 2020-05-14
Android HIGH 7.5
CVE-2018-21039

An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka Quic…

Mitigation only
Fix from $1,950 2020-04-08
Android HIGH 8.4
CVE-2018-21082

An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-screen bypass via the "Use scr…

Mitigation only
Fix from $1,950 2020-04-08
Android MEDIUM 5.5
CVE-2020-0087

In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lead to local information disclo…

Mitigation only
Fix from $1,600 2020-03-10
Android HIGH 7.8
CVE-2020-0036

In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions bypass. This could lead to loc…

Mitigation only
Fix from $1,950 2020-03-10
Android HIGH 8.1
CVE-2014-7914

btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote att…

Fix: 5.1+
Fix from $1,950 2020-02-21
Chrome HIGH 8.8
CVE-2020-6380

Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer proc…

Fix: 79.0.3945.130+
Fix from $1,950 2020-02-11
Chrome MEDIUM 6.5
CVE-2019-5879

Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious …

Fix: 77.0.3865.75+
Fix from $1,600 2019-11-25
Android MEDIUM 5.5
CVE-2019-9272

In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to…

Mitigation only
Fix from $1,600 2019-09-27
Android HIGH 7.8
CVE-2019-2175

In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could…

Patch available
Fix from $1,950 2019-09-05
Android HIGH 7.8
CVE-2018-9488

In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of pri…

Patch available
Fix from $1,950 2018-11-06
Android HIGH 7.8
CVE-2018-9492

In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privi…

Patch available
Fix from $1,950 2018-10-02
Chrome MEDIUM 6.5
CVE-2017-5060

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed …

Fix: 58.0.3029.81 / 58.0.3029.83+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.8
CVE-2013-0889

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement bef…

Fix: 25.0.1364.97 / 25.0.1364.99+
Fix from $1,600 2013-02-23
Chrome HIGH 7.5
CVE-2011-1123

Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack ve…

Fix: 9.0.597.107+
Fix from $1,950 2011-03-01