Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.5
CVE-2024-47021

In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote info…

Mitigation only
Fix from $1,950 2024-10-25
Android HIGH 7.5
CVE-2024-47022

Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.

Fix: 2024-10-05+
Fix from $1,950 2024-10-25
Android HIGH 7.4
CVE-2024-44098

In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to local esc…

Mitigation only
Fix from $1,950 2024-10-25
Android MEDIUM 5.5
CVE-2024-44099

There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additi…

No fix yet
Fix from $1,600 2024-10-25
Android MEDIUM 5.5
CVE-2024-47015

In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. Thi…

Mitigation only
Fix from $1,600 2024-10-25
Android MEDIUM 5.5
CVE-2024-47018

In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a buffer overflow. This could lead to local informat…

Mitigation only
Fix from $1,600 2024-10-25
Android MEDIUM 5.5
CVE-2024-47019

In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could …

Mitigation only
Fix from $1,600 2024-10-25
Chrome HIGH 8.8
CVE-2024-10231

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 130.0.6723.69+
Fix from $1,950 2024-10-22
Chrome HIGH 8.8
CVE-2024-10230

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 130.0.6723.69+
Fix from $1,950 2024-10-22
Chrome HIGH 8.1
CVE-2024-10229

Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted C…

Fix: 130.0.6723.69+
Fix from $1,950 2024-10-22
Migrate To Containers HIGH 7.8
CVE-2024-9858

There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser…

Fix: 1.2.3+
Fix from $1,950 2024-10-16
Chrome HIGH 8.8
CVE-2024-9954

Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 130.0.6723.58+
Fix from $1,950 2024-10-15
Chrome HIGH 8.8
CVE-2024-9955

Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 130.0.6723.58+
Fix from $1,950 2024-10-15
Chrome HIGH 8.8
CVE-2024-9957

Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Fix: 130.0.6723.58+
Fix from $1,950 2024-10-15
Chrome HIGH 8.8
CVE-2024-9959

Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially …

Fix: 130.0.6723.58+
Fix from $1,950 2024-10-15
Chrome HIGH 8.8
CVE-2024-9961

Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific …

Fix: 130.0.6723.58+
Fix from $1,950 2024-10-15
Chrome HIGH 8.8
CVE-2024-9965

Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage …

Fix: 130.0.6723.58+
Fix from $1,950 2024-10-15
Chrome HIGH 7.8
CVE-2024-9956

Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege es…

Fix: 130.0.6723.58+
Fix from $1,950 2024-10-15
Chrome HIGH 7.5
CVE-2024-9960

Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 130.0.6723.58+
Fix from $1,950 2024-10-15
Chrome MEDIUM 5.3
CVE-2024-9966

Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass content security policy via a…

Fix: 130.0.6723.58+
Fix from $1,600 2024-10-15
Cloud Looker HIGH 7.5
CVE-2024-8912

An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users. There ar…

Fix: 23.12.123 / 23.18.117+
Fix from $1,950 2024-10-11
Chrome HIGH 8.8
CVE-2024-9859

Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (…

Fix: 126.0.6478.126+
Fix from $1,950 2024-10-11
Android MEDIUM 6.7
CVE-2024-39437

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,600 2024-10-09
Android MEDIUM 6.7
CVE-2024-39438

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,600 2024-10-09
Android MEDIUM 6.7
CVE-2024-39436

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,600 2024-10-09
Chrome HIGH 8.8
CVE-2024-9603

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 129.0.6668.100+
Fix from $1,950 2024-10-08
Chrome HIGH 8.8
CVE-2024-9602

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML p…

Fix: 129.0.6668.100+
Fix from $1,950 2024-10-08
Android MEDIUM 5.5
CVE-2024-34663

Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.

Mitigation only
Fix from $1,600 2024-10-08
Android HIGH 7.8
CVE-2024-20092

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executio…

Mitigation only
Fix from $1,950 2024-10-07
Android MEDIUM 6.7
CVE-2024-20090

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executio…

Mitigation only
Fix from $1,600 2024-10-07