Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2018-9372

In cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a local escal…

Mitigation only
Fix from $1,950 2024-11-19
Android HIGH 7.8
CVE-2018-9409

In HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local e…

Mitigation only
Fix from $1,950 2024-11-19
Android HIGH 7.5
CVE-2018-9364

In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User i…

Mitigation only
Fix from $1,950 2024-11-19
Android HIGH 7.3
CVE-2018-9369

In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2024-11-19
Android HIGH 7.3
CVE-2018-9370

In download.c there is a special mode allowing user to download data into memory and causing possible memory corruptions due to missing bounds check.…

Mitigation only
Fix from $1,950 2024-11-19
Android MEDIUM 6.5
CVE-2018-9348

In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhaustion with…

Mitigation only
Fix from $1,600 2024-11-19
Android MEDIUM 6.4
CVE-2018-9371

In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with …

Mitigation only
Fix from $1,600 2024-11-19
Android MEDIUM 5.5
CVE-2018-9346

In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead …

Patch available
Fix from $1,600 2024-11-19
Android HIGH 7.8
CVE-2018-9339

In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to l…

Patch available
Fix from $1,950 2024-11-19
Android HIGH 7.8
CVE-2018-9341

In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary cod…

Patch available
Fix from $1,950 2024-11-19
Android HIGH 7.8
CVE-2018-9344

In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privi…

Patch available
Fix from $1,950 2024-11-19
Android MEDIUM 5.5
CVE-2018-9340

In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing info…

Patch available
Fix from $1,600 2024-11-19
Android MEDIUM 5.5
CVE-2018-9345

In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead …

Patch available
Fix from $1,600 2024-11-19
Android HIGH 7.8
CVE-2023-21270

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to …

Patch available
Fix from $1,950 2024-11-19
Android HIGH 7.8
CVE-2017-13315

In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevati…

Patch available
Fix from $1,950 2024-11-19
Android HIGH 7.8
CVE-2018-9338

In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalat…

Mitigation only
Fix from $1,950 2024-11-19
Firebase Javascript Sdk MEDIUM 6.1
CVE-2024-11023

Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session sy…

Fix: 10.9.0+
Fix from $1,600 2024-11-18
Android HIGH 7.8
CVE-2017-13310

In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local e…

Mitigation only
Fix from $1,950 2024-11-15
Android HIGH 7.8
CVE-2017-13312

In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escal…

Mitigation only
Fix from $1,950 2024-11-15
Android HIGH 7.8
CVE-2017-13314

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul…

Patch available
Fix from $1,950 2024-11-15
Android MEDIUM 6.7
CVE-2017-13311

In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to l…

Mitigation only
Fix from $1,600 2024-11-15
Android MEDIUM 6.5
CVE-2017-13313

In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an inco…

Patch available
Fix from $1,600 2024-11-15
Android MEDIUM 5.5
CVE-2017-13309

In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information …

Mitigation only
Fix from $1,600 2024-11-15
Android MEDIUM 5.5
CVE-2017-13227

In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could lead to information disclosure …

Patch available
Fix from $1,600 2024-11-14
Android CRITICAL 9.8
CVE-2024-43091

In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution…

Patch available
Fix from $2,300 2024-11-13
Android HIGH 7.8
CVE-2024-43085

In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic …

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43087

In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the access…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43088

In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due …

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43089

In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.3
CVE-2024-43093 KEV

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive direc…

Patch available
Fix from $1,950 2024-11-13