Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android MEDIUM 5.5
CVE-2021-0338

In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local de…

Patch available
Fix from $1,600 2021-02-10
Android HIGH 7.8
CVE-2021-0332

In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privileg…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.8
CVE-2021-0334

In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.3
CVE-2021-0331

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to l…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.3
CVE-2021-0333

In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permi…

Patch available
Fix from $1,950 2021-02-10
Android MEDIUM 6.5
CVE-2021-0335

In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to remote information disclosure wi…

Patch available
Fix from $1,600 2021-02-10
Android HIGH 7.8
CVE-2021-0327

In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lea…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.8
CVE-2021-0328

In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.8
CVE-2021-0329

In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bounds check. This could lead t…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.8
CVE-2021-0330

In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 8.8
CVE-2021-0325

In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote cod…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.3
CVE-2021-0314

In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. Thi…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.8
CVE-2021-0305

In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and per…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.8
CVE-2021-0302

In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and per…

Patch available
Fix from $1,950 2021-02-10
Chrome HIGH 8.8
CVE-2021-21148 KEVEPSS 20%

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 88.0.4324.150+
Fix from $1,950 2021-02-09
Chrome CRITICAL 9.6
CVE-2021-21142

Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a cra…

Fix: 88.0.4324.146+
Fix from $2,300 2021-02-09
Chrome CRITICAL 9.6
CVE-2021-21146

Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 88.0.4324.146+
Fix from $2,300 2021-02-09
Chrome HIGH 8.8
CVE-2021-21143

Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension …

Fix: 88.0.4324.146+
Fix from $1,950 2021-02-09
Chrome HIGH 8.8
CVE-2021-21144

Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension …

Fix: 88.0.4324.146+
Fix from $1,950 2021-02-09
Chrome HIGH 8.8
CVE-2021-21145

Use after free in Fonts in Google Chrome prior to 88.0.4324.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 88.0.4324.146+
Fix from $1,950 2021-02-09
Chrome CRITICAL 9.6
CVE-2021-21132EPSS 23%

Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $2,300 2021-02-09
Chrome HIGH 8.8
CVE-2021-21127EPSS 6%

Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via …

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,950 2021-02-09
Chrome HIGH 8.8
CVE-2021-21128EPSS 7%

Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,950 2021-02-09
Chrome HIGH 8.6
CVE-2021-21138

Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform a sandbox escape via a crafted file.

Fix: 88.0.4324.96+
Fix from $1,950 2021-02-09
Chrome MEDIUM 6.8
CVE-2021-21140

Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a…

Fix: 88.0.705.74 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Chrome MEDIUM 6.5
CVE-2021-21126EPSS 9%

Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Chrome MEDIUM 6.5
CVE-2021-21129EPSS 5%

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Chrome MEDIUM 6.5
CVE-2021-21130EPSS 5%

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Chrome MEDIUM 6.5
CVE-2021-21131EPSS 8%

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Chrome MEDIUM 6.5
CVE-2021-21133

Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to byp…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09