Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2020-0259

In android_verity_ctr of dm-android-verity.c, there is a possible way to modify a dm-verity protected filesystem due to improperly used crypto. This …

Mitigation only
Fix from $1,950 2020-08-11
Android HIGH 7.5
CVE-2020-0251

There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647626

Mitigation only
Fix from $1,950 2020-08-11
Android HIGH 7.5
CVE-2020-0254

There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751

Mitigation only
Fix from $1,950 2020-08-11
Android MEDIUM 5.5
CVE-2020-0239

In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to a permissions bypass. This c…

Mitigation only
Fix from $1,600 2020-08-11
Android MEDIUM 5.5
CVE-2020-0247

In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This could lead to local denial o…

Mitigation only
Fix from $1,600 2020-08-11
Android MEDIUM 5.5
CVE-2020-0248

In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local infor…

Mitigation only
Fix from $1,600 2020-08-11
Android MEDIUM 5.5
CVE-2020-0249

In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local infor…

Mitigation only
Fix from $1,600 2020-08-11
Android MEDIUM 5.5
CVE-2020-0250

In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure …

Mitigation only
Fix from $1,600 2020-08-11
Android MEDIUM 5.5
CVE-2020-0258

In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure in the application that is s…

No fix yet
Fix from $1,600 2020-08-11
Android HIGH 7.8
CVE-2020-0108

In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lea…

Mitigation only
Fix from $1,950 2020-08-11
Android HIGH 7.0
CVE-2020-0238

In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition. This could lead to loc…

Mitigation only
Fix from $1,950 2020-08-11
Go Tpm HIGH 7.1
CVE-2020-8918

An improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions prior to 0.3.0 can lead an eavesdropping attacker to disco…

Fix: 0.3.0+
Fix from $1,950 2020-08-11
Chrome HIGH 8.8
CVE-2020-6524

Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6525

Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6530

Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious…

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6533

Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6534

Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome MEDIUM 6.5
CVE-2020-6526

Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via…

Fix: 84.0.4147.89+
Fix from $1,600 2020-07-22
Chrome MEDIUM 6.1
CVE-2020-6535

Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to in…

Fix: 84.0.4147.89+
Fix from $1,600 2020-07-22
Chrome CRITICAL 9.6
CVE-2020-6509

Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to pot…

Fix: 83.0.4103.116+
Fix from $2,300 2020-07-22
Chrome CRITICAL 9.6
CVE-2020-6522

Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a …

Fix: 84.0.4147.89+
Fix from $2,300 2020-07-22
Chrome HIGH 8.8
CVE-2020-6507EPSS 19%

Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 83.0.4103.106+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6512

Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6513

Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6515

Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6517

Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6518

Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools …

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6520

Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6523

Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 7.8
CVE-2020-6510

Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via …

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22