13,754 CVEs • 235 products
Products (235)
Click to collapseToggle
Products (235)
Click to collapse
CVEs (13,754)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Google Icu Project2Chrome International Components For UnicodeMay 13, 2026 Apr 24, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represe...Show more |
Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information. |
The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to execute arbitrary code in the context of the kernel. |
Android allows users to cause a denial of service. |
The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code. |
Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices. |
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies. |
Google Chrome caches TLS sessions before certificate validation occurs. |
SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash). |
mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7920. |
mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921. |
2Google Linux2Android Linux KernelMay 13, 2026 Apr 12, 2017 N/A· v4 7.0 HIGH· v3 7.6 HIGH· v2 Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857. |
A use-after-free in AnimationController::endAnimationUpdate in Google Chrome. |
An elevation of privilege vulnerability in the DTS sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires...Show more |
An elevation of privilege vulnerability in the MediaTek camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first re...Show more |
An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first r...Show more |
An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the...Show more |
An information disclosure vulnerability in the factory reset process could enable a local malicious attacker to access data from the previous owner. This issue is rated as Moderate due to the possibility of bypassing dev...Show more |
An information disclosure vulnerability in libskia could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data witho...Show more |
An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data w...Show more |