Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Protobuf CRITICAL 9.8
CVE-2024-2410

The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken …

Fix: 4.25.0+
Fix from $2,300 2024-05-03
Chrome HIGH 8.8
CVE-2024-4058EPSS 9%

Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 124.0.6367.78+
Fix from $1,950 2024-05-01
Chrome HIGH 8.8
CVE-2024-4331

Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a …

Fix: 124.0.6367.118+
Fix from $1,950 2024-05-01
Chrome HIGH 8.8
CVE-2024-4368

Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 124.0.6367.118+
Fix from $1,950 2024-05-01
Chrome MEDIUM 6.5
CVE-2024-4059

Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chro…

Fix: 124.0.6367.78+
Fix from $1,600 2024-05-01
Chrome MEDIUM 6.5
CVE-2024-4060

Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 124.0.6367.78+
Fix from $1,600 2024-05-01
Chrome MEDIUM 6.5
CVE-2024-3914

Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 124.0.6367.60+
Fix from $1,600 2024-04-17
Chrome HIGH 8.8
CVE-2024-3832

Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML…

Fix: 124.0.6367.60+
Fix from $1,950 2024-04-17
Chrome HIGH 8.8
CVE-2024-3833EPSS 18%

Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a cra…

Fix: 124.0.6367.60+
Fix from $1,950 2024-04-17
Chrome HIGH 8.8
CVE-2024-3834

Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 124.0.6367.60+
Fix from $1,950 2024-04-17
Chrome HIGH 8.8
CVE-2024-3837

Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially expl…

Fix: 124.0.6367.60+
Fix from $1,950 2024-04-17
Chrome HIGH 7.5
CVE-2024-3840

Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions…

Fix: 124.0.6367.60+
Fix from $1,950 2024-04-17
Chrome MEDIUM 6.5
CVE-2024-3839

Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 124.0.6367.60+
Fix from $1,600 2024-04-17
Chrome MEDIUM 6.1
CVE-2024-3841

Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a p…

Fix: 124.0.6367.60+
Fix from $1,600 2024-04-17
Chrome MEDIUM 6.1
CVE-2024-3847

Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a cr…

Fix: 124.0.6367.60+
Fix from $1,600 2024-04-17
Chrome MEDIUM 5.5
CVE-2024-3838

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app …

Fix: 124.0.6367.60+
Fix from $1,600 2024-04-17
Chrome CRITICAL 9.6
CVE-2024-3157

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to …

Fix: 123.0.6312.122+
Fix from $2,300 2024-04-10
Chrome MEDIUM 6.5
CVE-2024-3515

Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 123.0.6312.122+
Fix from $1,600 2024-04-10
Chrome MEDIUM 6.5
CVE-2024-3516

Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 123.0.6312.122+
Fix from $1,600 2024-04-10
Android HIGH 7.8
CVE-2023-52351

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System executi…

Mitigation only
Fix from $1,950 2024-04-08
Android HIGH 7.5
CVE-2023-52341

In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote in…

Mitigation only
Fix from $1,950 2024-04-08
Android HIGH 7.5
CVE-2023-52342

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no add…

No fix yet
Fix from $1,950 2024-04-08
Android MEDIUM 6.0
CVE-2023-52345

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execu…

No fix yet
Fix from $1,600 2024-04-08
Android MEDIUM 5.9
CVE-2023-52534

In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execu…

No fix yet
Fix from $1,600 2024-04-08
Android MEDIUM 5.5
CVE-2023-52343

In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information …

No fix yet
Fix from $1,600 2024-04-08
Android MEDIUM 5.5
CVE-2023-52347

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System executi…

Mitigation only
Fix from $1,600 2024-04-08
Android MEDIUM 5.5
CVE-2023-52352

In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution pri…

Mitigation only
Fix from $1,600 2024-04-08
Android MEDIUM 5.3
CVE-2023-52344

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no add…

Mitigation only
Fix from $1,600 2024-04-08
Android MEDIUM 5.3
CVE-2023-52533

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no add…

No fix yet
Fix from $1,600 2024-04-08
Chrome HIGH 8.8
CVE-2024-3156EPSS 13%

Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory acc…

Fix: 123.0.6312.105+
Fix from $1,950 2024-04-06