Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.8
CVE-2018-16083EPSS 5%

An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out o…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-16085

A use after free in ResourceCoordinator in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-17457

An object lifecycle issue in Blink could lead to a use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to exe…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-17458

An improper update of the WebAssembly dispatch table in WebAssembly in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to execute arbit…

Fix: 69.0.3497.92+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-17461

An out of bounds read in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform an out of bounds memory read via a crafte…

Fix: 68.0.3440.75+
Fix from $1,950 2019-01-09
Chrome HIGH 7.4
CVE-2018-16081

Allowing the chrome.debugger API to run on file:// URLs in DevTools in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user t…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 7.4
CVE-2018-17470

A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 70.0.3538.67+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16078

Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive i…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16080

A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the conten…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16082

An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform out of bounds memory acc…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16088

A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files w…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-17459

Incorrect handling of clicks in the omnibox in Navigation in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to spoof the contents of t…

Fix: 69.0.3497.92+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.1
CVE-2018-16084

The default selected dialog button in CustomHandlers in Google Chrome prior to 69.0.3497.81 allowed a remote attacker who convinced the user to perfo…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 5.3
CVE-2018-16079

A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the …

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome CRITICAL 9.6
CVE-2018-16068

Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM…

Fix: 69.0.3497.81+
Fix from $2,300 2019-01-09
Chrome HIGH 8.8
CVE-2017-15428EPSS 18%

Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3…

Fix: 62.0.3202.94+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-16065

A Javascript reentrancy issues that caused a use-after-free in V8 in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitra…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-16071

A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted vide…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-16076

Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16066

A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16067

A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16072

A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin polic…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome CRITICAL 9.6
CVE-2017-15402

Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same proces…

Fix: 62.0.3202.74+
Fix from $2,300 2019-01-09
Chrome HIGH 8.8
CVE-2016-10403

Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed a remote attacker to perform an out of bounds mem…

Fix: 51.0.2704.63+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2016-9651EPSS 11%

A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute ar…

Fix: 55.0.2883.75+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2017-15401

A memory corruption bug in WebAssembly could lead to out of bounds read and write through V8 in WebAssembly in Google Chrome prior to 62.0.3202.62 al…

Fix: 62.0.3202.62+
Fix from $1,950 2019-01-09
Chrome HIGH 7.8
CVE-2017-15404

An ability to process crash dumps under root privileges and inappropriate symlinks handling could lead to a local privilege escalation in Crash Repor…

Fix: 61.0.3163.113+
Fix from $1,950 2019-01-09
Chrome HIGH 7.3
CVE-2017-15403

Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to…

Fix: 61.0.3163.113+
Fix from $1,950 2019-01-09
Chrome HIGH 7.0
CVE-2017-15405

Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a mali…

Fix: 61.0.3163.113+
Fix from $1,950 2019-01-09
Android HIGH 7.8
CVE-2018-11986

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buffer overflow in TX and RX FIFO…

Patch available
Fix from $1,950 2018-12-20