Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android MEDIUM 6.7
CVE-2020-0010

In fpc_ta_get_build_info of fpc_ta_kpi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation …

Mitigation only
Fix from $1,600 2020-03-10
Android MEDIUM 6.7
CVE-2020-0011

In get_auth_result of fpc_ta_hw_auth.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of…

Mitigation only
Fix from $1,600 2020-03-10
Android MEDIUM 6.7
CVE-2020-0012

In fpc_ta_pn_get_unencrypted_image of fpc_ta_pn.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local es…

Mitigation only
Fix from $1,600 2020-03-10
Android MEDIUM 5.0
CVE-2020-0031

In triggerAugmentedAutofillLocked and related functions of Session.java, it is possible for Augmented Autofill to display sensitive information to th…

Mitigation only
Fix from $1,600 2020-03-10
Chrome HIGH 8.8
CVE-2020-6383EPSS 6%

Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 80.0.3987.116+
Fix from $1,950 2020-02-27
Chrome HIGH 8.8
CVE-2020-6384

Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 80.0.3987.116+
Fix from $1,950 2020-02-27
Chrome HIGH 8.8
CVE-2020-6386

Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 80.0.3987.116+
Fix from $1,950 2020-02-27
Chrome HIGH 8.8
CVE-2020-6407

Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 80.0.3987.122+
Fix from $1,950 2020-02-27
Chrome HIGH 8.8
CVE-2020-6418 KEVEPSS 79%

Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 80.0.3987.122+
Fix from $1,950 2020-02-27
Native Client CRITICAL 10.0
CVE-2015-0565EPSS 14%

NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.

Mitigation only
Fix from $2,300 2020-02-25
Android HIGH 8.0
CVE-2020-8860

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), …

Mitigation only
Fix from $1,950 2020-02-22
Android HIGH 8.1
CVE-2014-7914

btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote att…

Fix: 5.1+
Fix from $1,950 2020-02-21
Android HIGH 7.8
CVE-2020-0027

In HidRawSensor::batch of HidRawSensor.cpp, there is a possible out of bounds write due to an unexpected switch fallthrough. This could lead to local…

Patch available
Fix from $1,950 2020-02-13
Android HIGH 7.0
CVE-2020-0030

In binder_thread_release of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wi…

Patch available
Fix from $1,950 2020-02-13
Android MEDIUM 6.5
CVE-2020-0028

In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of private DNS settings. This could lead to remote in…

Patch available
Fix from $1,600 2020-02-13
Android HIGH 8.8
CVE-2020-0022EPSS 6%

In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to …

Fix: 9.1.0.193 / 10.0.0.162+
Fix from $1,950 2020-02-13
Android HIGH 7.8
CVE-2020-0015

In onCreate of CertInstaller.java, there is a possible way to overlay the Certificate Installation dialog by a malicious application. This could lead…

Patch available
Fix from $1,950 2020-02-13
Android HIGH 7.8
CVE-2020-0026

In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege…

Patch available
Fix from $1,950 2020-02-13
Android HIGH 7.3
CVE-2019-2200

In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a…

Patch available
Fix from $1,950 2020-02-13
Android MEDIUM 6.7
CVE-2020-0005

In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to loc…

Patch available
Fix from $1,600 2020-02-13
Android MEDIUM 6.5
CVE-2020-0021

In removeUnusedPackagesLPw of PackageManagerService.java, there is a possible permanent denial-of-service due to a missing package dependency test. T…

Patch available
Fix from $1,600 2020-02-13
Android MEDIUM 5.5
CVE-2020-0014

It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escal…

Mitigation only
Fix from $1,600 2020-02-13
Android MEDIUM 5.5
CVE-2020-0020

In getAttributeRange of ExifInterface.java, there is a possible failure to redact location information from media files due to an incorrect bounds ch…

Patch available
Fix from $1,600 2020-02-13
Android MEDIUM 5.5
CVE-2020-0023

In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission ch…

Patch available
Fix from $1,600 2020-02-13
Android HIGH 7.5
CVE-2011-3901

Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.

No fix yet
Fix from $1,950 2020-02-12
Gizmo5 HIGH 7.5
CVE-2009-5139

The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it …

No fix yet
Fix from $1,950 2020-02-12
Chrome HIGH 8.8
CVE-2020-6409

Inappropriate implementation in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker who convinced the user to enter a URI to byp…

Fix: 80.0.3987.87+
Fix from $1,950 2020-02-11
Chrome HIGH 8.8
CVE-2020-6410

Insufficient policy enforcement in navigation in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to confuse the user via a crafted doma…

Fix: 80.0.3987.87+
Fix from $1,950 2020-02-11
Chrome HIGH 8.8
CVE-2020-6413

Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML p…

Fix: 80.0.3987.87+
Fix from $1,950 2020-02-11
Chrome HIGH 8.8
CVE-2020-6414

Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions v…

Fix: 80.0.3987.87+
Fix from $1,950 2020-02-11