Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Android MEDIUM 5.5
CVE-2021-25415

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writ…

Mitigation only
Fix from $1,600 2021-06-11
Android MEDIUM 5.5
CVE-2021-25393

Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system ui…

No fix yet
Fix from $1,600 2021-06-11
Chrome MEDIUM 6.1
CVE-2019-13714

Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS…

Fix: 78.0.3904.70+
Fix from $1,600 2019-11-25
Chrome HIGH 8.8
CVE-2016-9651EPSS 11%

A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute ar…

Fix: 55.0.2883.75+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2016-5149

The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to …

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Chrome Os HIGH 10.0
CVE-2014-3188EPSS 6%

Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remot…

Fix: after 38.0.2125.77
Fix from $1,950 2014-10-08
Chrome HIGH 10.0
CVE-2014-3176EPSS 10%

Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attac…

Fix: after 37.0.2062.93
Fix from $1,950 2014-08-27
Chrome HIGH 10.0
CVE-2014-3177

Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attac…

Fix: after 37.0.2062.93
Fix from $1,950 2014-08-27
Chrome HIGH 7.5
CVE-2014-1716

Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.1…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Android HIGH 7.5
CVE-2014-1939

java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchB…

Fix: after 4.3.1
Fix from $1,950 2014-03-03
Chrome HIGH 7.5
CVE-2013-0912

WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion."

Mitigation only
Fix from $1,950 2013-03-11
Chrome HIGH 10.0
CVE-2012-5142

Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote attackers to execute arbitrary code or cause a den…

Fix: after 23.0.1271.96
Fix from $1,950 2012-12-12
Sketchup HIGH 9.3
CVE-2011-2478

Google SketchUp before 8 does not properly handle edge geometry in SketchUp (aka .SKP) files, which allows remote attackers to execute arbitrary code…

Fix: after 7.1
Fix from $1,950 2012-04-17
Picasa HIGH 9.3
CVE-2011-2747

Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary …

Fix: after 3.6_build_105.65
Fix from $1,950 2011-07-28
Chrome HIGH 9.3
CVE-2010-2297

rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (applicat…

Fix: 5.0.375.70+
Fix from $1,950 2010-06-15
Chrome HIGH 9.3
CVE-2010-0647

WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malfo…

Fix: after 4.0.249.78
Fix from $1,950 2010-02-18
Android MEDIUM 6.9
CVE-2009-2348

Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_R…

Mitigation only
Fix from $1,600 2009-07-17
Chrome MEDIUM 6.8
CVE-2008-5749

Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --render…

No fix yet
Fix from $1,600 2008-12-29