Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.1
CVE-2022-0114

Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory r…

Fix: 97.0.4692.71+
Fix from $1,950 2022-02-12
Chrome MEDIUM 6.5
CVE-2022-0108

Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted H…

Fix: 97.0.4692.71+
Fix from $1,600 2022-02-12
Chrome MEDIUM 6.5
CVE-2022-0109

Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information…

Fix: 97.0.4692.71+
Fix from $1,600 2022-02-12
Chrome MEDIUM 6.5
CVE-2022-0111

Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted H…

Fix: 97.0.4692.71+
Fix from $1,600 2022-02-12
Chrome MEDIUM 6.5
CVE-2022-0113

Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML p…

Fix: 97.0.4692.71+
Fix from $1,600 2022-02-12
Chrome HIGH 8.8
CVE-2021-4099

Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 96.0.4664.110+
Fix from $1,950 2022-02-11
Chrome HIGH 8.8
CVE-2021-4100

Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 96.0.4664.110+
Fix from $1,950 2022-02-11
Chrome HIGH 8.8
CVE-2021-4101

Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 96.0.4664.110+
Fix from $1,950 2022-02-11
Chrome HIGH 8.8
CVE-2021-4102 KEVEPSS 8%

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 96.0.4664.110+
Fix from $1,950 2022-02-11
Chrome HIGH 7.4
CVE-2021-4098

Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to po…

Fix: 96.0.4664.110+
Fix from $1,950 2022-02-11
Android MEDIUM 6.5
CVE-2022-24925

Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of servi…

Mitigation only
Fix from $1,600 2022-02-11
Android CRITICAL 9.8
CVE-2022-23425

Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base…

Mitigation only
Fix from $2,300 2022-02-11
Android HIGH 7.8
CVE-2022-22292

Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.

Mitigation only
Fix from $1,950 2022-02-11
Android HIGH 7.8
CVE-2022-23428

An improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

Mitigation only
Fix from $1,950 2022-02-11
Android HIGH 7.1
CVE-2022-23427

PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files witho…

Mitigation only
Fix from $1,950 2022-02-11
Android MEDIUM 6.7
CVE-2022-23431

An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

Mitigation only
Fix from $1,600 2022-02-11
Android MEDIUM 6.7
CVE-2022-23432

An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

Mitigation only
Fix from $1,600 2022-02-11
Android MEDIUM 6.0
CVE-2022-23426

A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.

Mitigation only
Fix from $1,600 2022-02-11
Android MEDIUM 5.5
CVE-2022-22291

Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information thr…

Mitigation only
Fix from $1,600 2022-02-11
Android CRITICAL 9.8
CVE-2021-39658

ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions o…

Mitigation only
Fix from $2,300 2022-02-11
Android CRITICAL 9.8
CVE-2021-39675EPSS 6%

In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privil…

Mitigation only
Fix from $2,300 2022-02-11
Android CRITICAL 9.1
CVE-2021-39635

ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No ph…

Mitigation only
Fix from $2,300 2022-02-11
Android HIGH 7.8
CVE-2021-39662

In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing pe…

Patch available
Fix from $1,950 2022-02-11
Android HIGH 7.8
CVE-2021-39663

In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This co…

Mitigation only
Fix from $1,950 2022-02-11
Android HIGH 7.8
CVE-2021-39668

In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead to local escalation of privi…

Patch available
Fix from $1,950 2022-02-11
Android HIGH 7.8
CVE-2021-39669

In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/o…

Patch available
Fix from $1,950 2022-02-11
Android HIGH 7.8
CVE-2021-39672

In fastboot, there is a possible secure boot bypass due to a configuration error. This could lead to local escalation of privilege with no additional…

Mitigation only
Fix from $1,950 2022-02-11
Android HIGH 7.8
CVE-2021-39674

In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privile…

Patch available
Fix from $1,950 2022-02-11
Android HIGH 7.8
CVE-2021-39676

In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This cou…

Mitigation only
Fix from $1,950 2022-02-11
Android HIGH 7.5
CVE-2021-39677

In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘zero’ in size.Product: AndroidVersions: Android-1…

Mitigation only
Fix from $1,950 2022-02-11