VYPR

Skia

by Google

Source repositories

CVEs (39)

  • CVE-2024-43097HigJan 3, 2025
    risk 0.51cvss 7.8epss 0.00

    In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2016-2412HigApr 18, 2016
    risk 0.51cvss 7.8epss 0.00

    include/core/SkPostConfig.h in Skia, as used in System_server in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01, mishandles certain crashes, which allows attackers to gain privileges via a crafted application, as demonstrated by…

  • CVE-2026-19176HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2013-6648HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.01

    SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).

  • CVE-2026-17992MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-6364MedApr 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security severity: Medium)

  • CVE-2019-9282MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In skia, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113211371

  • CVE-2018-6069MedNov 14, 2018
    risk 0.42cvss 6.5epss 0.02

    Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2021-21147MedFeb 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2017-15418MedAug 28, 2018
    risk 0.28cvss 4.3epss 0.02

    Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2026-11675LowJun 9, 2026
    risk 0.20cvss 3.1epss 0.00

    Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-14429HigJul 1, 2026
    risk 0.00cvss 8.3epss 0.00

    Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-14414MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity:…

  • CVE-2026-14410MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-14387CriJul 1, 2026
    risk 0.00cvss 9.6epss 0.00

    Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2015-3877Oct 6, 2015
    risk 0.00cvss epss 0.02

    Skia, as used in Android before 5.1.1 LMY48T, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20723696.

  • CVE-2014-7909Nov 19, 2014
    risk 0.00cvss epss 0.02

    effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.

  • CVE-2011-3104May 24, 2012
    risk 0.00cvss epss 0.01

    Skia, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2009-1442May 7, 2009
    risk 0.00cvss epss 0.02

    Multiple integer overflows in Skia, as used in Google Chrome 1.x before 1.0.154.64 and 2.x, and possibly Android, might allow remote attackers to execute arbitrary code in the renderer process via a crafted (1) image or (2) canvas.

Page 2 of 2