Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.8
CVE-2021-30626

Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 93.0.4577.82+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-30627

Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 93.0.4577.82+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-30628

Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit stack corruption via a crafted…

Fix: 93.0.4577.82+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-30629

Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 93.0.4577.82+
Fix from $1,950 2021-10-08
Chrome HIGH 8.8
CVE-2021-30632 KEVEPSS 65%

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 93.0.4577.82+
Fix from $1,950 2021-10-08
Extensible Service Proxy MEDIUM 5.4
CVE-2021-41130

Extensible Service Proxy, a.k.a. ESP is a proxy which enables API management capabilities for JSON/REST or gRPC API services. ESPv1 can be configured…

Fix: 1.58.0+
Fix from $1,600 2021-10-07
Android HIGH 8.0
CVE-2021-25485

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote so…

Mitigation only
Fix from $1,950 2021-10-06
Android HIGH 7.5
CVE-2021-25480

A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote …

Mitigation only
Fix from $1,950 2021-10-06
Android HIGH 7.2
CVE-2021-25478

A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code exec…

Mitigation only
Fix from $1,950 2021-10-06
Android HIGH 7.2
CVE-2021-25479

A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execu…

Mitigation only
Fix from $1,950 2021-10-06
Android MEDIUM 6.7
CVE-2021-25481

An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of …

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 6.5
CVE-2021-25483

Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 6.0
CVE-2021-25490

A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-25488

Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.

Mitigation only
Fix from $1,600 2021-10-06
Android HIGH 7.9
CVE-2021-25470

An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

Mitigation only
Fix from $1,950 2021-10-06
Android HIGH 7.5
CVE-2021-25471

A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network c…

Mitigation only
Fix from $1,950 2021-10-06
Android MEDIUM 6.7
CVE-2021-25467

Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release 1 allows …

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 6.7
CVE-2021-25469

A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitrary code execution.

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 6.7
CVE-2021-25475

A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execu…

Mitigation only
Fix from $1,600 2021-10-06
Android HIGH 7.8
CVE-2021-0692

In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIntent. This could lead to loca…

Patch available
Fix from $1,950 2021-10-06
Android MEDIUM 6.7
CVE-2021-0691

In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-…

Patch available
Fix from $1,600 2021-10-06
Android MEDIUM 6.5
CVE-2021-0690

In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to rem…

Patch available
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0693

In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. T…

Patch available
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0695

In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure wit…

Patch available
Fix from $1,600 2021-10-06
Android HIGH 7.8
CVE-2021-0595

In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. Thi…

Patch available
Fix from $1,950 2021-10-06
Android HIGH 7.8
CVE-2021-0635

When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video cannot be played, and the log …

Mitigation only
Fix from $1,950 2021-10-06
Android HIGH 7.8
CVE-2021-0636

When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video cannot be played, and the log …

Mitigation only
Fix from $1,950 2021-10-06
Android HIGH 7.8
CVE-2021-0683

In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to loc…

Patch available
Fix from $1,950 2021-10-06
Android HIGH 7.8
CVE-2021-0684

In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalati…

Patch available
Fix from $1,950 2021-10-06
Android HIGH 7.8
CVE-2021-0685

In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This c…

Patch available
Fix from $1,950 2021-10-06