Vulnerability index

Browse CVEs

4,645 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.8 CVE-2014-6041EPSS 18% The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 charac… Android Browser No fix yet Fix from $1,6002014-09-02 MEDIUM 5.1 CVE-2014-3100 Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arb… Android No fix yet Fix from $1,6002014-07-02 HIGH 7.5 CVE-2014-1909 Integer signedness error in system/core/adb/adb_client.c in Android Debug Bridge (ADB) for Android 4.4 in the Android SDK Platform Tools 18.0.1 allow… Android Debug Bridge No fix yet Fix from $1,9502014-05-14 HIGH 9.3 CVE-2013-4710EPSS 43% Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, whi… Android Mitigation only Fix from $1,9502014-03-03 HIGH 7.5 CVE-2013-5349 Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag … Picasa Mitigation only Fix from $1,9502014-01-09 HIGH 7.5 CVE-2013-5357 Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that… Picasa Mitigation only Fix from $1,9502014-01-09 HIGH 7.5 CVE-2013-5358 Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to trigger memory corruption via a crafted TIFF tag, as demonstrated u… Picasa Mitigation only Fix from $1,9502014-01-09 HIGH 7.5 CVE-2013-5359 Stack-based buffer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 might allow remote attackers to execute arbitrary code via a cr… Picasa Mitigation only Fix from $1,9502014-01-09 HIGH 8.8 CVE-2013-6271EPSS 8% Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the up… Android No fix yet Fix from $1,9502013-12-14 MEDIUM 6.9 CVE-2013-4777 A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that… Android No fix yet Fix from $1,6002013-09-25 MEDIUM 6.9 CVE-2013-5933 Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic W… Android Mitigation only Fix from $1,6002013-09-25 MEDIUM 6.9 CVE-2013-4872 Google Glass before XE6 does not properly restrict the processing of QR codes, which allows physically proximate attackers to modify the configuratio… Glass Mitigation only Fix from $1,6002013-07-18 HIGH 9.3 CVE-2013-4787EPSS 59% Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitra… Android Mitigation only Fix from $1,9502013-07-09 HIGH 7.2 CVE-2013-3666 The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attackers to execute arbitrary commands by entering USB… Android Mitigation only Fix from $1,9502013-05-29 HIGH 7.5 CVE-2013-0912 WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion." Chrome Mitigation only Fix from $1,9502013-03-11 HIGH 7.5 CVE-2013-0843 content/renderer/media/webrtc_audio_renderer.cc in Google Chrome before 24.0.1312.56 on Mac OS X does not use an appropriate buffer size for the 96 k… Chrome Mitigation only Fix from $1,9502013-01-24 MEDIUM 5.0 CVE-2012-6301EPSS 6% The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SR… Android No fix yet Fix from $1,6002012-12-10 MEDIUM 6.8 CVE-2012-4220 diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to ex… Android Mitigation only Fix from $1,6002012-11-30 MEDIUM 6.8 CVE-2012-4221 Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 al… Android Mitigation only Fix from $1,6002012-11-30 MEDIUM 5.0 CVE-2012-6051 Google CityHash computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent … Cityhash Mitigation only Fix from $1,6002012-11-28 MEDIUM 5.8 CVE-2012-5820 The developer-account sample code in Google AdMob does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or… Admob No fix yet Fix from $1,6002012-11-04 HIGH 10.0 CVE-2012-2864 Mesa, as used in Google Chrome before 21.0.1183.0 on the Acer AC700, Cr-48, and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chro… Chrome Os Mitigation only Fix from $1,9502012-08-22 HIGH 10.0 CVE-2011-3087 Google Chrome before 19.0.1084.46 does not properly perform window navigation, which has unspecified impact and remote attack vectors. Chrome Mitigation only Fix from $1,9502012-05-16 HIGH 9.3 CVE-2011-3874EPSS 12% Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute ar… Android Mitigation only Fix from $1,9502012-01-27 MEDIUM 5.0 CVE-2011-5037 Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attack… V8 Mitigation only Fix from $1,6002011-12-30 MEDIUM 5.0 CVE-2010-5073 The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyl… Chrome No fix yet Fix from $1,6002011-12-07 MEDIUM 6.8 CVE-2011-3886 Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impa… V8 Mitigation only Fix from $1,6002011-10-25 HIGH 10.0 CVE-2011-2344 Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which al… Android Mitigation only Fix from $1,9502011-07-08 HIGH 9.3 CVE-2011-2075 Unspecified vulnerability in Google Chrome 11.0.696.65 on Windows 7 SP1 allows remote attackers to execute arbitrary code via unknown vectors. NOTE:… Chrome Mitigation only Fix from $1,9502011-05-10 HIGH 9.3 CVE-2010-3134 Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to execute arbitrary code and co… Earth No fix yet Fix from $1,9502010-08-26