Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2018-11987

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, if there is an unlikely memory alloc failu…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11988

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Un-trusted pointer de-reference issue by a…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11960

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition can occur in th…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11961

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possibility of accessing out of bound vect…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11963

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null …

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11964

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Exposing the hashed content in /etc/passwd…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11965

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Anyone can execute proptrigger.sh which wi…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11983

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Error in kernel observed while accessing f…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11984

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition and an out-of-b…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11985

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, When allocating heap using user supplied s…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2017-9704

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, There is no synchronization between msm_vb…

Patch available
Fix from $1,950 2018-12-20
Rendertron HIGH 7.5
CVE-2017-18353

Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route…

Patch available
Fix from $1,950 2018-12-17
Rendertron HIGH 7.5
CVE-2017-18354

Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by…

Patch available
Fix from $1,950 2018-12-17
Rendertron HIGH 7.5
CVE-2017-18355

Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "…

Patch available
Fix from $1,950 2018-12-17
Rendertron MEDIUM 6.1
CVE-2017-18352

Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.

Patch available
Fix from $1,600 2018-12-17
Gvisor MEDIUM 5.5
CVE-2018-20168

Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a den…

Fix: 2018-08-22+
Fix from $1,600 2018-12-17
Chrome HIGH 8.8
CVE-2018-18359

Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory rea…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome MEDIUM 5.7
CVE-2018-18358

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy re…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
Chrome HIGH 8.8
CVE-2018-18340

Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption v…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18341

An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploi…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18342

Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds write in V8 in Google Chrome…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18343

Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploi…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18347

Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a …

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18354

Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launc…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18356

An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome MEDIUM 6.5
CVE-2018-18344

Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote at…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
Chrome MEDIUM 6.5
CVE-2018-18345

Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker who had compromised the renderer p…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
Chrome MEDIUM 6.5
CVE-2018-18346

Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to present confusing browser UI via…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
Chrome MEDIUM 6.5
CVE-2018-18349

Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinc…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
Chrome MEDIUM 6.5
CVE-2018-18350

Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content …

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11