Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android MEDIUM 5.5
CVE-2021-0321

In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel…

Patch available
Fix from $1,600 2021-01-11
Android MEDIUM 5.0
CVE-2021-0322

In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to loc…

Patch available
Fix from $1,600 2021-01-11
Android CRITICAL 9.8
CVE-2020-0471

In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper …

Patch available
Fix from $2,300 2021-01-11
Android HIGH 7.0
CVE-2021-0303

In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a possible use after free due …

Mitigation only
Fix from $1,950 2021-01-11
Android MEDIUM 6.7
CVE-2021-0301

In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…

Mitigation only
Fix from $1,600 2021-01-11
Android HIGH 7.8
CVE-2020-27059

In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesting the user's fingerprint due to an overlaid wind…

Patch available
Fix from $1,950 2021-01-11
Android MEDIUM 6.7
CVE-2021-0342

In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System e…

Patch available
Fix from $1,600 2021-01-11
Chrome CRITICAL 9.6
CVE-2021-21109

Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially …

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome CRITICAL 9.6
CVE-2021-21110

Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a craft…

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome CRITICAL 9.6
CVE-2021-21111

Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious exte…

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome CRITICAL 9.6
CVE-2021-21115

User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potent…

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome HIGH 8.8
CVE-2021-21112

Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 87.0.4280.141+
Fix from $1,950 2021-01-08
Chrome HIGH 8.8
CVE-2021-21113

Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

Fix: 87.0.4280.141+
Fix from $1,950 2021-01-08
Chrome HIGH 8.8
CVE-2021-21114

Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 87.0.4280.141+
Fix from $1,950 2021-01-08
Chrome HIGH 8.8
CVE-2021-21116

Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 87.0.4280.141+
Fix from $1,950 2021-01-08
Chrome CRITICAL 9.6
CVE-2021-21106

Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially …

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome CRITICAL 9.6
CVE-2021-21107

Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process t…

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome CRITICAL 9.6
CVE-2021-21108

Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome HIGH 8.8
CVE-2020-16039

Use after free in extensions in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 87.0.4280.88+
Fix from $1,950 2021-01-08
Chrome HIGH 8.8
CVE-2020-16043

Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to bypass discretionary access control v…

Fix: 87.0.4280.141+
Fix from $1,950 2021-01-08
Chrome HIGH 8.1
CVE-2020-16041

Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker who had compromised the renderer process to obtain …

Fix: 87.0.4280.88+
Fix from $1,950 2021-01-08
Chrome MEDIUM 6.5
CVE-2020-16040EPSS 100%

Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 87.0.4280.88+
Fix from $1,600 2021-01-08
Chrome MEDIUM 6.5
CVE-2020-16042

Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process mem…

Fix: 87.0.4280.88+
Fix from $1,600 2021-01-08
Chrome CRITICAL 9.6
CVE-2020-16024

Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially p…

Fix: 87.0.4280.66+
Fix from $2,300 2021-01-08
Chrome CRITICAL 9.6
CVE-2020-16025

Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potent…

Fix: 87.0.4280.66+
Fix from $2,300 2021-01-08
Chrome HIGH 8.8
CVE-2020-16022

Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall control…

Fix: 87.0.4280.66+
Fix from $1,950 2021-01-08
Chrome HIGH 8.8
CVE-2020-16023

Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 87.0.4280.66+
Fix from $1,950 2021-01-08
Chrome HIGH 8.8
CVE-2020-16026

Use after free in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 87.0.4280.66+
Fix from $1,950 2021-01-08
Chrome HIGH 8.8
CVE-2020-16028

Heap buffer overflow in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 87.0.4280.66+
Fix from $1,950 2021-01-08
Chrome HIGH 8.8
CVE-2020-16029

Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a craft…

Fix: 87.0.4280.66+
Fix from $1,950 2021-01-08