Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2024-40655

In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use permission in the background d…

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-40657

In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This …

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-40658

In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local esc…

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-40662

In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation …

Patch available
Fix from $1,950 2024-09-11
Android MEDIUM 5.5
CVE-2024-40656

In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy. T…

Patch available
Fix from $1,600 2024-09-11
Android MEDIUM 5.5
CVE-2024-40659

In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by up…

Patch available
Fix from $1,600 2024-09-11
Android HIGH 7.0
CVE-2024-23716

In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privil…

Mitigation only
Fix from $1,950 2024-09-11
Chrome HIGH 8.8
CVE-2024-7970

Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 128.0.6613.119+
Fix from $1,950 2024-09-03
Chrome HIGH 8.8
CVE-2024-8362

Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 128.0.6613.119+
Fix from $1,950 2024-09-03
Android MEDIUM 6.7
CVE-2024-20086

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executio…

Mitigation only
Fix from $1,600 2024-09-02
Android MEDIUM 6.7
CVE-2024-20087

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executio…

Mitigation only
Fix from $1,600 2024-09-02
Chrome HIGH 8.8
CVE-2024-8194

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 128.0.6613.113+
Fix from $1,950 2024-08-28
Chrome HIGH 8.8
CVE-2024-8198

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 128.0.6613.113+
Fix from $1,950 2024-08-28
Chrome HIGH 8.8
CVE-2024-8193

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 128.0.6613.113+
Fix from $1,950 2024-08-28
Chrome CRITICAL 9.6
CVE-2024-7971 KEVEPSS 21%

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium …

Fix: 128.0.2739.42 / 128.0.6613.84+
Fix from $2,300 2024-08-21
Chrome HIGH 8.8
CVE-2024-7966

Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer process to per…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 8.8
CVE-2024-7967

Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 8.8
CVE-2024-7968

Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI inte…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 8.8
CVE-2024-7969

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 8.8
CVE-2024-7972

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory acce…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 8.8
CVE-2024-7973

Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read via a crafte…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 8.8
CVE-2024-7974

Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 7.8
CVE-2024-7977

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 7.8
CVE-2024-7979

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 7.8
CVE-2024-7980

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 8.8
CVE-2024-7964

Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 8.8
CVE-2024-7965 KEVEPSS 19%

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 128.0.2739.42 / 128.0.6613.84+
Fix from $1,950 2024-08-21
Android HIGH 7.8
CVE-2024-32927

In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,950 2024-08-19
Nest Mini Firmware MEDIUM 5.9
CVE-2024-32928

The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-m…

Mitigation only
Fix from $1,600 2024-08-19
Android HIGH 7.8
CVE-2024-31333

In _MMU_AllocLevel of mmu_common.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of p…

Mitigation only
Fix from $1,950 2024-08-15