Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android MEDIUM 6.5
CVE-2017-13234

In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remote temporary denial of servic…

Mitigation only
Fix from $1,600 2018-02-12
Android MEDIUM 6.5
CVE-2017-13235

A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68342866.

No fix yet
Fix from $1,600 2018-02-12
Chrome HIGH 8.8
CVE-2017-5125

Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5126

A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF …

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5127

Use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF fi…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5128

Heap buffer overflow in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5129

A use after free in WebAudio in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a …

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5130

An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attac…

Fix: 2.9.5 / 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5131

An integer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5132

Inappropriate implementation in V8 in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5133

Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to corrupt memory and possibly leak infor…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-15387

Insufficient enforcement of Content Security Policy in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to open javascript: URL…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-15388

Iteration through non-finite points in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read …

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-15393

Insufficient Policy Enforcement in Devtools remote debugging in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to obtain access to rem…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome Os HIGH 7.8
CVE-2017-15400

Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the sam…

Fix: 62.0.3202.74+
Fix from $1,950 2018-02-07
Chrome Os HIGH 7.4
CVE-2017-15397

Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to obs…

Fix: 62.0.3202.74+
Fix from $1,950 2018-02-07
Chrome MEDIUM 6.5
CVE-2017-15386

Incorrect implementation in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Chrome MEDIUM 6.5
CVE-2017-15389

An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (U…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Chrome MEDIUM 6.5
CVE-2017-15390

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing via IDN homogr…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Chrome MEDIUM 6.5
CVE-2017-15391

Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to access Extension pages without auth…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Chrome MEDIUM 6.5
CVE-2017-15394

Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permissi…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Chrome MEDIUM 6.5
CVE-2017-15395

A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Chrome MEDIUM 6.1
CVE-2017-5124EPSS 5%

Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UX…

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Android HIGH 7.8
CVE-2017-6258

NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and …

Patch available
Fix from $1,950 2018-02-06
Android HIGH 7.8
CVE-2017-6279

NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and …

Patch available
Fix from $1,950 2018-02-06
Android HIGH 7.0
CVE-2016-5345

Buffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to gain privileges via a crafted …

Patch available
Fix from $1,950 2018-01-23
Android MEDIUM 5.7
CVE-2017-17860

In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user'…

No fix yet
Fix from $1,600 2018-01-18
Android HIGH 7.8
CVE-2017-11072

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while calculating CRC for GPT header …

Patch available
Fix from $1,950 2018-01-16
Android HIGH 7.8
CVE-2017-13220

An elevation of privilege vulnerability in the Upstream kernel bluez. Product: Android. Versions: Android kernel. Android ID: A-63527053.

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.8
CVE-2017-13221

An elevation of privilege vulnerability in the Upstream kernel wifi driver. Product: Android. Versions: Android kernel. Android ID: A-64709938.

Patch available
Fix from $1,950 2018-01-12