Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
MEDIUM 6.7
CVE-2020-0010
In fpc_ta_get_build_info of fpc_ta_kpi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation …
Android
Mitigation only
MEDIUM 6.7
CVE-2020-0011
In get_auth_result of fpc_ta_hw_auth.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of…
Android
Mitigation only
MEDIUM 6.7
CVE-2020-0012
In fpc_ta_pn_get_unencrypted_image of fpc_ta_pn.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local es…
Android
Mitigation only
MEDIUM 5.0
CVE-2020-0031
In triggerAugmentedAutofillLocked and related functions of Session.java, it is possible for Augmented Autofill to display sensitive information to th…
Android
Mitigation only
HIGH 8.8
CVE-2020-6383EPSS 6%
Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Chrome
80.0.3987.116+
HIGH 8.8
CVE-2020-6384
Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…
Chrome
80.0.3987.116+
HIGH 8.8
CVE-2020-6386
Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …
Chrome
80.0.3987.116+
HIGH 8.8
CVE-2020-6407
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a…
Chrome
80.0.3987.122+
HIGH 8.8
CVE-2020-6418 KEVEPSS 79%
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Chrome
80.0.3987.122+
CRITICAL 10.0
CVE-2015-0565EPSS 14%
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
Native Client
Mitigation only
HIGH 8.0
CVE-2020-8860
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), …
Android
Mitigation only
HIGH 8.1
CVE-2014-7914
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote att…
Android
5.1+
HIGH 7.8
CVE-2020-0027
In HidRawSensor::batch of HidRawSensor.cpp, there is a possible out of bounds write due to an unexpected switch fallthrough. This could lead to local…
Android
Patch available
HIGH 7.0
CVE-2020-0030
In binder_thread_release of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wi…
Android
Patch available
MEDIUM 6.5
CVE-2020-0028
In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of private DNS settings. This could lead to remote in…
Android
Patch available
HIGH 8.8
CVE-2020-0022EPSS 6%
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to …
Android
9.1.0.193 / 10.0.0.162+
HIGH 7.8
CVE-2020-0015
In onCreate of CertInstaller.java, there is a possible way to overlay the Certificate Installation dialog by a malicious application. This could lead…
Android
Patch available
HIGH 7.8
CVE-2020-0026
In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege…
Android
Patch available
HIGH 7.3
CVE-2019-2200
In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a…
Android
Patch available
MEDIUM 6.7
CVE-2020-0005
In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to loc…
Android
Patch available
MEDIUM 6.5
CVE-2020-0021
In removeUnusedPackagesLPw of PackageManagerService.java, there is a possible permanent denial-of-service due to a missing package dependency test. T…
Android
Patch available
MEDIUM 5.5
CVE-2020-0014
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escal…
Android
Mitigation only
MEDIUM 5.5
CVE-2020-0020
In getAttributeRange of ExifInterface.java, there is a possible failure to redact location information from media files due to an incorrect bounds ch…
Android
Patch available
MEDIUM 5.5
CVE-2020-0023
In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission ch…
Android
Patch available
HIGH 7.5
CVE-2011-3901
Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.
Android
No fix yet
HIGH 7.5
CVE-2009-5139
The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it …
Gizmo5
No fix yet
HIGH 8.8
CVE-2020-6409
Inappropriate implementation in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker who convinced the user to enter a URI to byp…
Chrome
80.0.3987.87+
HIGH 8.8
CVE-2020-6410
Insufficient policy enforcement in navigation in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to confuse the user via a crafted doma…
Chrome
80.0.3987.87+
HIGH 8.8
CVE-2020-6413
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML p…
Chrome
80.0.3987.87+
HIGH 8.8
CVE-2020-6414
Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions v…
Chrome
80.0.3987.87+