Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2018-9401

In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This could lead to local escalatio…

Mitigation only
Fix from $1,950 2025-01-18
Android MEDIUM 6.7
CVE-2018-9405

In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation …

Mitigation only
Fix from $1,600 2025-01-18
Android MEDIUM 5.5
CVE-2018-9406

In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privi…

Mitigation only
Fix from $1,600 2025-01-18
Android HIGH 7.8
CVE-2018-9387

In multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This could lead to local escalation…

Mitigation only
Fix from $1,950 2025-01-18
Android HIGH 7.8
CVE-2018-9434

In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of pri…

Patch available
Fix from $1,950 2025-01-17
Android MEDIUM 5.5
CVE-2018-9447

In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This c…

Patch available
Fix from $1,600 2025-01-17
Android HIGH 7.8
CVE-2018-9375

In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy…

Mitigation only
Fix from $1,950 2025-01-17
Android HIGH 7.8
CVE-2018-9382

In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission…

Mitigation only
Fix from $1,950 2025-01-17
Android MEDIUM 5.5
CVE-2018-9379

In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. This could le…

Patch available
Fix from $1,600 2025-01-17
Android MEDIUM 5.5
CVE-2017-13322

In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the co…

Patch available
Fix from $1,600 2025-01-17
Chrome HIGH 8.8
CVE-2025-0443

Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specif…

Fix: 132.0.6834.83+
Fix from $1,950 2025-01-15
Chrome HIGH 8.8
CVE-2025-0447

Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform privilege escalation via a cr…

Fix: 132.0.6834.83+
Fix from $1,950 2025-01-15
Chrome MEDIUM 6.5
CVE-2025-0439

Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI…

Fix: 132.0.6834.83+
Fix from $1,600 2025-01-15
Chrome MEDIUM 6.5
CVE-2025-0440

Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a …

Fix: 132.0.6834.83+
Fix from $1,600 2025-01-15
Chrome MEDIUM 6.5
CVE-2025-0441

Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive infor…

Fix: 132.0.6834.83+
Fix from $1,600 2025-01-15
Chrome MEDIUM 6.5
CVE-2025-0442

Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific…

Fix: 132.0.6834.83+
Fix from $1,600 2025-01-15
Chrome HIGH 8.8
CVE-2025-0434EPSS 6%

Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 132.0.6834.83+
Fix from $1,950 2025-01-15
Chrome HIGH 8.8
CVE-2025-0436

Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 132.0.6834.83+
Fix from $1,950 2025-01-15
Chrome HIGH 8.8
CVE-2025-0437

Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 132.0.6834.83+
Fix from $1,950 2025-01-15
Chrome HIGH 8.8
CVE-2025-0438

Stack buffer overflow in Tracing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit stack corruption via a craf…

Fix: 132.0.6834.83+
Fix from $1,950 2025-01-15
Chrome MEDIUM 6.5
CVE-2025-0435

Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a …

Fix: 132.0.6834.83+
Fix from $1,600 2025-01-15
Chrome HIGH 8.8
CVE-2025-0291EPSS 8%

Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 131.0.6778.264+
Fix from $1,950 2025-01-08
Android HIGH 7.8
CVE-2023-35685

In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalati…

No fix yet
Fix from $1,950 2025-01-08
Android MEDIUM 6.7
CVE-2024-20105

In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor …

Mitigation only
Fix from $1,600 2025-01-06
Android CRITICAL 9.8
CVE-2024-53842

In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote c…

Mitigation only
Fix from $2,300 2025-01-03
Android HIGH 7.8
CVE-2024-11624

there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional exec…

Mitigation only
Fix from $1,950 2025-01-03
Android HIGH 7.8
CVE-2024-47032

In construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local es…

Mitigation only
Fix from $1,950 2025-01-03
Android HIGH 7.8
CVE-2024-53833

In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local…

Mitigation only
Fix from $1,950 2025-01-03
Android HIGH 7.8
CVE-2024-53835

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution priv…

No fix yet
Fix from $1,950 2025-01-03
Android HIGH 7.8
CVE-2024-53837

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2025-01-03