Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android MEDIUM 5.5
CVE-2021-0411

In flv extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no addition…

Mitigation only
Fix from $1,600 2021-10-25
Android MEDIUM 5.5
CVE-2021-0412

In flv extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no addit…

Mitigation only
Fix from $1,600 2021-10-25
Android MEDIUM 5.5
CVE-2021-0413

In flv extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no addit…

Mitigation only
Fix from $1,600 2021-10-25
Android MEDIUM 5.5
CVE-2021-0414

In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no addit…

Mitigation only
Fix from $1,600 2021-10-25
Android HIGH 8.1
CVE-2021-0870EPSS 7%

In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to remote code execution with n…

Patch available
Fix from $1,950 2021-10-22
Android HIGH 7.8
CVE-2021-0652

In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe …

Patch available
Fix from $1,950 2021-10-22
Android HIGH 7.8
CVE-2021-0705

In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and keep granted permissions due to …

Patch available
Fix from $1,950 2021-10-22
Android HIGH 7.8
CVE-2021-0708

In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local e…

Patch available
Fix from $1,950 2021-10-22
Android MEDIUM 6.8
CVE-2021-0703

In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage. This could lead to local escalation of privileg…

Patch available
Fix from $1,600 2021-10-22
Android MEDIUM 5.5
CVE-2021-0702

In RevertActiveSessions of apexd.cpp, there is a possible way to share the wrong file due to an unintentional MediaStore downgrade. This could lead t…

Patch available
Fix from $1,600 2021-10-22
Android MEDIUM 5.5
CVE-2021-0706

In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This coul…

Mitigation only
Fix from $1,600 2021-10-22
Android HIGH 7.8
CVE-2021-0483

In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege wi…

Patch available
Fix from $1,950 2021-10-22
Android MEDIUM 5.5
CVE-2021-0643

In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due t…

Mitigation only
Fix from $1,600 2021-10-22
Android MEDIUM 5.5
CVE-2021-0651

In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to incorrect input validation. Thi…

Mitigation only
Fix from $1,600 2021-10-22
Android HIGH 7.3
CVE-2021-0583

In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user consent due to a tapjacking/overlay attack. This coul…

Mitigation only
Fix from $1,950 2021-10-11
Chrome CRITICAL 9.6
CVE-2021-37973 KEVEPSS 12%

Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially pe…

Fix: 94.0.4606.61+
Fix from $2,300 2021-10-08
Chrome HIGH 8.8
CVE-2021-37970

Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 94.0.4606.54+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-37972

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 94.0.4606.54+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-37974

Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 94.0.4606.71+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-37975 KEVEPSS 35%

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 94.0.4606.71+
Fix from $1,950 2021-10-08
Chrome HIGH 7.8
CVE-2021-37969

Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege…

Fix: 94.0.4606.54+
Fix from $1,950 2021-10-08
Chrome MEDIUM 6.5
CVE-2021-37976 KEVEPSS 20%

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 94.0.4606.71+
Fix from $1,600 2021-10-08
Chrome HIGH 8.8
CVE-2021-37956

Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to…

Fix: 94.0.4606.54+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-37957

Use after free in WebGPU in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 94.0.4606.54+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-37959

Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convinced a user to enage in a series of user gestures …

Fix: 94.0.4606.54+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-37961

Use after free in Tab Strip in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 94.0.4606.54+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-37962

Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to po…

Fix: 94.0.4606.54+
Fix from $1,950 2021-10-08
Chrome MEDIUM 5.4
CVE-2021-37958

Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into…

Fix: 94.0.4606.54+
Fix from $1,600 2021-10-08
Chrome CRITICAL 9.6
CVE-2021-30633 KEVEPSS 33%

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potenti…

Fix: 93.0.4577.82+
Fix from $2,300 2021-10-08
Chrome HIGH 8.8
CVE-2021-30625EPSS 10%

Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website…

Fix: 93.0.4577.82+
Fix from $1,950 2021-10-08