Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.8
CVE-2018-6064EPSS 7%

Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially explo…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-6065 KEVEPSS 60%

Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 a…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-6067

Incorrect IPC serialization in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-6071

An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted H…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-6072

An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-6073

A heap buffer overflow in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a craf…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-6074

Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a cra…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome HIGH 7.5
CVE-2018-6061

A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit …

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6066

Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-orig…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6069

Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6075

Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin da…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6077

Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacke…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6079

Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to …

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6080

Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer p…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.1
CVE-2018-6070

Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a maliciou…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome MEDIUM 6.1
CVE-2018-6076

Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based X…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome CRITICAL 9.6
CVE-2018-17462

Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox escape via a crafted HTML pag…

Fix: 70.0.3538.67+
Fix from $2,300 2018-11-14
Chrome CRITICAL 9.6
CVE-2018-17472

Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the <if…

Fix: 70.0.3538.67+
Fix from $2,300 2018-11-14
Chrome HIGH 8.8
CVE-2018-17463 KEVEPSS 85%

Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox vi…

Fix: 70.0.3538.67+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-17465

Incorrect implementation of object trimming in V8 in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit object corr…

Fix: 70.0.3538.67+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-17466

Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a cr…

Fix: 70.0.3538.67+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-17469

Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory…

Fix: 70.0.3538.67+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-17474

Use after free in HTMLImportsController in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit heap corrupt…

Fix: 70.0.3538.67+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-6057

Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process t…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-17468

Incorrect handling of timer information during navigation in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obtain cross o…

Fix: 70.0.3538.67+
Fix from $1,600 2018-11-14
Cardboard MEDIUM 5.3
CVE-2018-19111

The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as d…

Mitigation only
Fix from $1,600 2018-11-08
Android CRITICAL 9.8
CVE-2018-9446

In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This could lead to remote code exe…

Patch available
Fix from $2,300 2018-11-06
Android HIGH 8.8
CVE-2018-9450

In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code exe…

Patch available
Fix from $1,950 2018-11-06
Android HIGH 8.8
CVE-2018-9459

In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privilege due to a path traversal er…

Mitigation only
Fix from $1,950 2018-11-06
Android HIGH 7.8
CVE-2018-9458

In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wr…

Mitigation only
Fix from $1,950 2018-11-06