Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2019-2033

In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional executio…

Patch available
Fix from $1,950 2019-04-19
Android HIGH 7.8
CVE-2019-2034

In rw_i93_sm_read_ndef of rw_i93.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privi…

Patch available
Fix from $1,950 2019-04-19
Android HIGH 7.8
CVE-2019-2035

In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of p…

Patch available
Fix from $1,950 2019-04-19
Android HIGH 7.5
CVE-2019-2037

In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out-of-bound read due to an incorrect bounds check. This could lead to remote infor…

Patch available
Fix from $1,950 2019-04-19
Android MEDIUM 5.5
CVE-2019-2038

In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information di…

Patch available
Fix from $1,600 2019-04-19
Android HIGH 7.8
CVE-2019-2000

In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with …

No fix yet
Fix from $1,950 2019-02-28
Android MEDIUM 5.5
CVE-2019-2001

The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional execution privileges needed. U…

Mitigation only
Fix from $1,600 2019-02-28
Android HIGH 8.8
CVE-2019-1986

In SkSwizzler::onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escal…

Mitigation only
Fix from $1,950 2019-02-28
Android HIGH 8.8
CVE-2019-1988

In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in s…

Mitigation only
Fix from $1,950 2019-02-28
Android HIGH 8.8
CVE-2019-1991

In btif_dm_data_copy of btif_core.cc, there is a possible out of bounds write due to a buffer overflow. This could lead to remote code execution with…

Mitigation only
Fix from $1,950 2019-02-28
Android HIGH 8.8
CVE-2019-1994

In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could…

Mitigation only
Fix from $1,950 2019-02-28
Android HIGH 7.8
CVE-2019-1987

In onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution wi…

Patch available
Fix from $1,950 2019-02-28
Android HIGH 7.8
CVE-2019-1993

In register_app of btif_hd.cc, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,950 2019-02-28
Android HIGH 7.5
CVE-2019-1992

In bta_hl_sdp_query_results of bta_hl_main.cc, there is a possible use-after-free due to a race condition. This could lead to remote code execution w…

Mitigation only
Fix from $1,950 2019-02-28
Android HIGH 7.5
CVE-2019-1997

In random_get_bytes of random.c, there is a possible degradation of randomness due to an insecure default value. This could lead to local information…

Mitigation only
Fix from $1,950 2019-02-28
Android MEDIUM 6.5
CVE-2019-1996

In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informati…

Mitigation only
Fix from $1,600 2019-02-28
Android MEDIUM 5.5
CVE-2019-1995

In ComposeActivityEmail of ComposeActivityEmail.java, there is a possible way to silently attach files to an email due to a confused deputy. This cou…

Mitigation only
Fix from $1,600 2019-02-28
Android MEDIUM 5.5
CVE-2019-1998

In event_handler of keymaster_app.c, there is possible resource exhaustion due to a table being lost on reboot. This could lead to local denial of se…

Mitigation only
Fix from $1,600 2019-02-28
Chrome HIGH 8.8
CVE-2019-5782EPSS 13%

Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox …

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 8.8
CVE-2019-5783

Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Inj…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 7.8
CVE-2019-5780

Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute J…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome MEDIUM 6.5
CVE-2019-5781

Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the…

Fix: 72.0.3626.81+
Fix from $1,600 2019-02-19
Chrome HIGH 8.8
CVE-2019-5769

Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker t…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 8.8
CVE-2019-5770

Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 8.8
CVE-2019-5771

An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code via a craf…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 8.8
CVE-2019-5772

Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially explo…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 8.8
CVE-2019-5774

Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacke…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome MEDIUM 6.5
CVE-2019-5766

Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via …

Fix: 72.0.3626.81+
Fix from $1,600 2019-02-19
Chrome MEDIUM 6.5
CVE-2019-5767

Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to i…

Fix: 72.0.3626.81+
Fix from $1,600 2019-02-19
Chrome MEDIUM 6.5
CVE-2019-5768

DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user…

Fix: 72.0.3626.81+
Fix from $1,600 2019-02-19