Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2023-20919

In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error in the code. This could lead t…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2023-20920

In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2023-20925

In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalat…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2023-20928

In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no…

No fix yet
Fix from $1,950 2023-01-26
Android HIGH 7.3
CVE-2023-20921

In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility services due to a logic error in…

Mitigation only
Fix from $1,950 2023-01-26
Android MEDIUM 6.8
CVE-2023-20924

In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of privilege w…

Mitigation only
Fix from $1,600 2023-01-26
Android MEDIUM 5.5
CVE-2023-20908

In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of serv…

Mitigation only
Fix from $1,600 2023-01-26
Android MEDIUM 5.5
CVE-2023-20922

In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service …

Mitigation only
Fix from $1,600 2023-01-26
Android MEDIUM 5.5
CVE-2023-20923

In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to a permissions bypass. This c…

Mitigation only
Fix from $1,600 2023-01-26
Android HIGH 7.8
CVE-2023-20904

In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could l…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2022-20493

In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escal…

Mitigation only
Fix from $1,950 2023-01-26
Android MEDIUM 5.5
CVE-2022-20494

In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of servi…

Mitigation only
Fix from $1,600 2023-01-26
Android HIGH 7.8
CVE-2022-20461

In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to type confusion. This could lea…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2022-20489

In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead t…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2022-20490

In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could le…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2022-20492

In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead t…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2022-20456

In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead…

Mitigation only
Fix from $1,950 2023-01-26
Android MEDIUM 5.5
CVE-2022-20215

In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjacking/overlay attack. This could lead to local denial…

Mitigation only
Fix from $1,600 2023-01-26
Android MEDIUM 5.5
CVE-2022-20235

The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem. This page can only be written by the GPU driver itself, bu…

Mitigation only
Fix from $1,600 2023-01-26
Android MEDIUM 5.5
CVE-2022-20458

The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.ge…

Mitigation only
Fix from $1,600 2023-01-26
Android MEDIUM 5.5
CVE-2022-20213

In ApplicationsDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of…

Mitigation only
Fix from $1,600 2023-01-26
Chrome HIGH 8.8
CVE-2023-0134

Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potential…

Fix: 109.0.5414.74+
Fix from $1,950 2023-01-10
Chrome HIGH 8.8
CVE-2023-0135

Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potential…

Fix: 109.0.5414.74+
Fix from $1,950 2023-01-10
Chrome HIGH 8.8
CVE-2023-0136

Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to execute incorrect s…

Fix: 109.0.5414.74+
Fix from $1,950 2023-01-10
Chrome HIGH 8.8
CVE-2023-0137

Heap buffer overflow in Platform Apps in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed an attacker who convinced a user to install a mali…

Fix: 109.0.5414.74+
Fix from $1,950 2023-01-10
Chrome HIGH 8.8
CVE-2023-0138

Heap buffer overflow in libphonenumber in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 109.0.5414.74+
Fix from $1,950 2023-01-10
Chrome MEDIUM 6.5
CVE-2023-0139

Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass downlo…

Fix: 109.0.5414.74+
Fix from $1,600 2023-01-10
Chrome MEDIUM 6.5
CVE-2023-0140

Inappropriate implementation in in File System API in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass file system…

Fix: 109.0.5414.74+
Fix from $1,600 2023-01-10
Chrome HIGH 8.8
CVE-2023-0128

Use after free in Overview Mode in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed a remote attacker who convinced a user to engage in spec…

Fix: 109.0.5414.74+
Fix from $1,950 2023-01-10
Chrome HIGH 8.8
CVE-2023-0129

Heap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious exten…

Fix: 109.0.5414.74+
Fix from $1,950 2023-01-10