Vulnerability index

Browse CVEs

83 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2021-21182 Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer proc… Chrome 89.0.4389.72+ Fix from $1,6002021-03-09 HIGH 7.8 CVE-2021-0317 In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalat… Android Patch available Fix from $1,9502021-01-11 HIGH 7.3 CVE-2021-0319 In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without approp… Android Patch available Fix from $1,9502021-01-11 HIGH 7.8 CVE-2020-0479 In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malic… Android Patch available Fix from $1,9502020-12-15 CRITICAL 9.8 CVE-2020-25055 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unp… Android Mitigation only Fix from $2,3002020-08-31 CRITICAL 9.1 CVE-2020-7692 PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by… Oauth Client Library For Java 1.31.0+ Fix from $2,3002020-07-09 HIGH 7.8 CVE-2020-0115 In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for a… Android Patch available Fix from $1,9502020-06-10 HIGH 7.5 CVE-2020-13834 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folder does not properly restrict … Android Mitigation only Fix from $1,9502020-06-04 HIGH 7.8 CVE-2020-0097 In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This could lead t… Android Patch available Fix from $1,9502020-05-14 HIGH 7.5 CVE-2018-21039 An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka Quic… Android Mitigation only Fix from $1,9502020-04-08 HIGH 8.4 CVE-2018-21082 An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-screen bypass via the "Use scr… Android Mitigation only Fix from $1,9502020-04-08 MEDIUM 5.5 CVE-2020-0087 In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lead to local information disclo… Android Mitigation only Fix from $1,6002020-03-10 HIGH 7.8 CVE-2020-0036 In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions bypass. This could lead to loc… Android Mitigation only Fix from $1,9502020-03-10 HIGH 8.1 CVE-2014-7914 btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote att… Android 5.1+ Fix from $1,9502020-02-21 HIGH 8.8 CVE-2020-6380 Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer proc… Chrome 79.0.3945.130+ Fix from $1,9502020-02-11 MEDIUM 6.5 CVE-2019-5879 Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious … Chrome 77.0.3865.75+ Fix from $1,6002019-11-25 MEDIUM 5.5 CVE-2019-9272 In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to… Android Mitigation only Fix from $1,6002019-09-27 HIGH 7.8 CVE-2019-2175 In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could… Android Patch available Fix from $1,9502019-09-05 HIGH 7.8 CVE-2018-9488 In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of pri… Android Patch available Fix from $1,9502018-11-06 HIGH 7.8 CVE-2018-9492 In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privi… Android Patch available Fix from $1,9502018-10-02 MEDIUM 6.5 CVE-2017-5060 Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed … Chrome 58.0.3029.81 / 58.0.3029.83+ Fix from $1,6002017-10-27 MEDIUM 6.8 CVE-2013-0889 Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement bef… Chrome 25.0.1364.97 / 25.0.1364.99+ Fix from $1,6002013-02-23 HIGH 7.5 CVE-2011-1123 Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack ve… Chrome 9.0.597.107+ Fix from $1,9502011-03-01