Vulnerability index

Browse CVEs

4,645 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Android Browser MEDIUM 5.8
CVE-2014-6041EPSS 18%

The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 charac…

No fix yet
Fix from $1,600 2014-09-02
Android MEDIUM 5.1
CVE-2014-3100

Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arb…

No fix yet
Fix from $1,600 2014-07-02
Android Debug Bridge HIGH 7.5
CVE-2014-1909

Integer signedness error in system/core/adb/adb_client.c in Android Debug Bridge (ADB) for Android 4.4 in the Android SDK Platform Tools 18.0.1 allow…

No fix yet
Fix from $1,950 2014-05-14
Android HIGH 9.3
CVE-2013-4710EPSS 43%

Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, whi…

Mitigation only
Fix from $1,950 2014-03-03
Picasa HIGH 7.5
CVE-2013-5349

Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag …

Mitigation only
Fix from $1,950 2014-01-09
Picasa HIGH 7.5
CVE-2013-5357

Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that…

Mitigation only
Fix from $1,950 2014-01-09
Picasa HIGH 7.5
CVE-2013-5358

Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to trigger memory corruption via a crafted TIFF tag, as demonstrated u…

Mitigation only
Fix from $1,950 2014-01-09
Picasa HIGH 7.5
CVE-2013-5359

Stack-based buffer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 might allow remote attackers to execute arbitrary code via a cr…

Mitigation only
Fix from $1,950 2014-01-09
Android HIGH 8.8
CVE-2013-6271EPSS 8%

Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the up…

No fix yet
Fix from $1,950 2013-12-14
Android MEDIUM 6.9
CVE-2013-4777

A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that…

No fix yet
Fix from $1,600 2013-09-25
Android MEDIUM 6.9
CVE-2013-5933

Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic W…

Mitigation only
Fix from $1,600 2013-09-25
Glass MEDIUM 6.9
CVE-2013-4872

Google Glass before XE6 does not properly restrict the processing of QR codes, which allows physically proximate attackers to modify the configuratio…

Mitigation only
Fix from $1,600 2013-07-18
Android HIGH 9.3
CVE-2013-4787EPSS 59%

Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitra…

Mitigation only
Fix from $1,950 2013-07-09
Android HIGH 7.2
CVE-2013-3666

The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attackers to execute arbitrary commands by entering USB…

Mitigation only
Fix from $1,950 2013-05-29
Chrome HIGH 7.5
CVE-2013-0912

WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion."

Mitigation only
Fix from $1,950 2013-03-11
Chrome HIGH 7.5
CVE-2013-0843

content/renderer/media/webrtc_audio_renderer.cc in Google Chrome before 24.0.1312.56 on Mac OS X does not use an appropriate buffer size for the 96 k…

Mitigation only
Fix from $1,950 2013-01-24
Android MEDIUM 5.0
CVE-2012-6301EPSS 6%

The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SR…

No fix yet
Fix from $1,600 2012-12-10
Android MEDIUM 6.8
CVE-2012-4220

diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to ex…

Mitigation only
Fix from $1,600 2012-11-30
Android MEDIUM 6.8
CVE-2012-4221

Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 al…

Mitigation only
Fix from $1,600 2012-11-30
Cityhash MEDIUM 5.0
CVE-2012-6051

Google CityHash computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent …

Mitigation only
Fix from $1,600 2012-11-28
Admob MEDIUM 5.8
CVE-2012-5820

The developer-account sample code in Google AdMob does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or…

No fix yet
Fix from $1,600 2012-11-04
Chrome Os HIGH 10.0
CVE-2012-2864

Mesa, as used in Google Chrome before 21.0.1183.0 on the Acer AC700, Cr-48, and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chro…

Mitigation only
Fix from $1,950 2012-08-22
Chrome HIGH 10.0
CVE-2011-3087

Google Chrome before 19.0.1084.46 does not properly perform window navigation, which has unspecified impact and remote attack vectors.

Mitigation only
Fix from $1,950 2012-05-16
Android HIGH 9.3
CVE-2011-3874EPSS 12%

Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute ar…

Mitigation only
Fix from $1,950 2012-01-27
V8 MEDIUM 5.0
CVE-2011-5037

Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attack…

Mitigation only
Fix from $1,600 2011-12-30
Chrome MEDIUM 5.0
CVE-2010-5073

The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyl…

No fix yet
Fix from $1,600 2011-12-07
V8 MEDIUM 6.8
CVE-2011-3886

Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impa…

Mitigation only
Fix from $1,600 2011-10-25
Android HIGH 10.0
CVE-2011-2344

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which al…

Mitigation only
Fix from $1,950 2011-07-08
Chrome HIGH 9.3
CVE-2011-2075

Unspecified vulnerability in Google Chrome 11.0.696.65 on Windows 7 SP1 allows remote attackers to execute arbitrary code via unknown vectors. NOTE:…

Mitigation only
Fix from $1,950 2011-05-10
Earth HIGH 9.3
CVE-2010-3134

Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to execute arbitrary code and co…

No fix yet
Fix from $1,950 2010-08-26