Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android MEDIUM 5.5
CVE-2017-15844

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the function for writing…

Patch available
Fix from $1,600 2018-09-18
Android HIGH 8.8
CVE-2018-11263

In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, radio_id is received from the FW and is u…

Patch available
Fix from $1,950 2018-09-06
Android HIGH 7.8
CVE-2018-11262

In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while trying to find out total numb…

Patch available
Fix from $1,950 2018-09-04
Gvisor MEDIUM 6.8
CVE-2018-16359

Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on th…

Fix: 2018-08-23+
Fix from $1,600 2018-09-02
Chrome CRITICAL 9.8
CVE-2017-15398

A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a ma…

Fix: 62.0.3202.89+
Fix from $2,300 2018-08-28
Chrome HIGH 8.8
CVE-2017-15399

A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 62.0.3202.89+
Fix from $1,950 2018-08-28
Chrome HIGH 8.8
CVE-2017-15406

A stack buffer overflow in V8 in Google Chrome prior to 62.0.3202.75 allowed a remote attacker to perform an out of bounds memory read via a crafted …

Fix: 62.0.3202.75+
Fix from $1,950 2018-08-28
Chrome MEDIUM 6.5
CVE-2017-15396

A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior …

Fix: 60.2 / 62.0.3202.75+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.1
CVE-2017-15429

Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scri…

Fix: 63.0.3239.108+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.5
CVE-2017-15426

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homogr…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.1
CVE-2017-15427

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging an…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.5
CVE-2017-15424

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homogr…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.5
CVE-2017-15425

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homogr…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 5.3
CVE-2017-15423

Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA51…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.5
CVE-2017-15422

Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome p…

Fix: 60.1 / 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.5
CVE-2017-15420

Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to spoof the con…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 5.3
CVE-2017-15417

Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak cross-origi…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome HIGH 8.8
CVE-2017-15411

Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF fi…

Fix: 63.0.3239.84+
Fix from $1,950 2018-08-28
Chrome HIGH 8.8
CVE-2017-15410

Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF fi…

Fix: 63.0.3239.84+
Fix from $1,950 2018-08-28
Chrome HIGH 8.8
CVE-2017-15409

Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 63.0.3239.84+
Fix from $1,950 2018-08-28
Chrome HIGH 8.8
CVE-2017-15408

Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 63.0.3239.84+
Fix from $1,950 2018-08-28
Chrome HIGH 8.8
CVE-2017-15407

Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malici…

Fix: 63.0.3239.84+
Fix from $1,950 2018-08-28
Fscrypt MEDIUM 6.5
CVE-2018-6558

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root use…

Fix: 0.2.4+
Fix from $1,600 2018-08-23
Android CRITICAL 9.8
CVE-2018-14981

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The LG ID is LVE-SMP-180005.

Mitigation only
Fix from $2,300 2018-08-17
Android CRITICAL 9.8
CVE-2018-14982

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is LVE-SMP-180004.

Mitigation only
Fix from $2,300 2018-08-17
Android CRITICAL 9.8
CVE-2018-15482

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.

Mitigation only
Fix from $2,300 2018-08-17
Android CRITICAL 9.8
CVE-2018-14066

The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One …

No fix yet
Fix from $2,300 2018-07-15
Android HIGH 7.8
CVE-2018-5907

Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all …

Fix: after 8.1
Fix from $1,950 2018-07-06
Android HIGH 7.5
CVE-2018-5886

A pointer in an ADSPRPC command is not properly validated in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MS…

Patch available
Fix from $1,950 2018-07-06
Android CRITICAL 9.8
CVE-2018-3586

An integer overflow to buffer overflow vulnerability exists in the ADSPRPC heap manager in all Android releases(Android for MSM, Firefox OS for MSM, …

Mitigation only
Fix from $2,300 2018-07-06