Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2022-0114 Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory r… Chrome 97.0.4692.71+ Fix from $1,9502022-02-12 MEDIUM 6.5 CVE-2022-0108 Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted H… Chrome 97.0.4692.71+ Fix from $1,6002022-02-12 MEDIUM 6.5 CVE-2022-0109 Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information… Chrome 97.0.4692.71+ Fix from $1,6002022-02-12 MEDIUM 6.5 CVE-2022-0111 Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted H… Chrome 97.0.4692.71+ Fix from $1,6002022-02-12 MEDIUM 6.5 CVE-2022-0113 Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML p… Chrome 97.0.4692.71+ Fix from $1,6002022-02-12 HIGH 8.8 CVE-2021-4099 Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted … Chrome 96.0.4664.110+ Fix from $1,9502022-02-11 HIGH 8.8 CVE-2021-4100 Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafte… Chrome 96.0.4664.110+ Fix from $1,9502022-02-11 HIGH 8.8 CVE-2021-4101 Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a cr… Chrome 96.0.4664.110+ Fix from $1,9502022-02-11 HIGH 8.8 CVE-2021-4102 KEVEPSS 8% Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Chrome 96.0.4664.110+ Fix from $1,9502022-02-11 HIGH 7.4 CVE-2021-4098 Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to po… Chrome 96.0.4664.110+ Fix from $1,9502022-02-11 MEDIUM 6.5 CVE-2022-24925 Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of servi… Android Mitigation only Fix from $1,6002022-02-11 CRITICAL 9.8 CVE-2022-23425 Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base… Android Mitigation only Fix from $2,3002022-02-11 HIGH 7.8 CVE-2022-22292 Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity. Android Mitigation only Fix from $1,9502022-02-11 HIGH 7.8 CVE-2022-23428 An improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution. Android Mitigation only Fix from $1,9502022-02-11 HIGH 7.1 CVE-2022-23427 PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files witho… Android Mitigation only Fix from $1,9502022-02-11 MEDIUM 6.7 CVE-2022-23431 An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution. Android Mitigation only Fix from $1,6002022-02-11 MEDIUM 6.7 CVE-2022-23432 An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution. Android Mitigation only Fix from $1,6002022-02-11 MEDIUM 6.0 CVE-2022-23426 A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege. Android Mitigation only Fix from $1,6002022-02-11 MEDIUM 5.5 CVE-2022-22291 Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information thr… Android Mitigation only Fix from $1,6002022-02-11 CRITICAL 9.8 CVE-2021-39658 ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions o… Android Mitigation only Fix from $2,3002022-02-11 CRITICAL 9.8 CVE-2021-39675EPSS 6% In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privil… Android Mitigation only Fix from $2,3002022-02-11 CRITICAL 9.1 CVE-2021-39635 ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No ph… Android Mitigation only Fix from $2,3002022-02-11 HIGH 7.8 CVE-2021-39662 In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing pe… Android Patch available Fix from $1,9502022-02-11 HIGH 7.8 CVE-2021-39663 In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This co… Android Mitigation only Fix from $1,9502022-02-11 HIGH 7.8 CVE-2021-39668 In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead to local escalation of privi… Android Patch available Fix from $1,9502022-02-11 HIGH 7.8 CVE-2021-39669 In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/o… Android Patch available Fix from $1,9502022-02-11 HIGH 7.8 CVE-2021-39672 In fastboot, there is a possible secure boot bypass due to a configuration error. This could lead to local escalation of privilege with no additional… Android Mitigation only Fix from $1,9502022-02-11 HIGH 7.8 CVE-2021-39674 In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privile… Android Patch available Fix from $1,9502022-02-11 HIGH 7.8 CVE-2021-39676 In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This cou… Android Mitigation only Fix from $1,9502022-02-11 HIGH 7.5 CVE-2021-39677 In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘zero’ in size.Product: AndroidVersions: Android-1… Android Mitigation only Fix from $1,9502022-02-11