Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2018-11987 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, if there is an unlikely memory alloc failu… Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-11988 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Un-trusted pointer de-reference issue by a… Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-11960 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition can occur in th… Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-11961 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possibility of accessing out of bound vect… Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-11963 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null … Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-11964 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Exposing the hashed content in /etc/passwd… Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-11965 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Anyone can execute proptrigger.sh which wi… Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-11983 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Error in kernel observed while accessing f… Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-11984 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition and an out-of-b… Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-11985 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, When allocating heap using user supplied s… Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2017-9704 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, There is no synchronization between msm_vb… Android Patch available Fix from $1,9502018-12-20 HIGH 7.5 CVE-2017-18353 Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route… Rendertron Patch available Fix from $1,9502018-12-17 HIGH 7.5 CVE-2017-18354 Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by… Rendertron Patch available Fix from $1,9502018-12-17 HIGH 7.5 CVE-2017-18355 Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "… Rendertron Patch available Fix from $1,9502018-12-17 MEDIUM 6.1 CVE-2017-18352 Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs. Rendertron Patch available Fix from $1,6002018-12-17 MEDIUM 5.5 CVE-2018-20168 Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a den… Gvisor 2018-08-22+ Fix from $1,6002018-12-17 HIGH 8.8 CVE-2018-18359 Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory rea… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 MEDIUM 5.7 CVE-2018-18358 Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy re… Chrome 71.0.3578.80+ Fix from $1,6002018-12-11 HIGH 8.8 CVE-2018-18340 Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption v… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 HIGH 8.8 CVE-2018-18341 An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploi… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 HIGH 8.8 CVE-2018-18342 Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds write in V8 in Google Chrome… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 HIGH 8.8 CVE-2018-18343 Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploi… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 HIGH 8.8 CVE-2018-18347 Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a … Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 HIGH 8.8 CVE-2018-18354 Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launc… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 HIGH 8.8 CVE-2018-18356 An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 MEDIUM 6.5 CVE-2018-18344 Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote at… Chrome 71.0.3578.80+ Fix from $1,6002018-12-11 MEDIUM 6.5 CVE-2018-18345 Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker who had compromised the renderer p… Chrome 71.0.3578.80+ Fix from $1,6002018-12-11 MEDIUM 6.5 CVE-2018-18346 Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to present confusing browser UI via… Chrome 71.0.3578.80+ Fix from $1,6002018-12-11 MEDIUM 6.5 CVE-2018-18349 Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinc… Chrome 71.0.3578.80+ Fix from $1,6002018-12-11 MEDIUM 6.5 CVE-2018-18350 Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content … Chrome 71.0.3578.80+ Fix from $1,6002018-12-11