VYPR

Vendor CVEs

Google

All CVEs

15,856 total · sorted by risk
  • CVE-2024-0519HigKEVJan 16, 2024
    risk 0.70cvss 8.8epss 0.04

    Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-7024HigKEVDec 21, 2023
    risk 0.70cvss 8.8epss 0.07

    Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4863HigKEVSep 12, 2023
    risk 0.70cvss 8.8epss 1.00

    Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2022-4262HigKEVDec 2, 2022
    risk 0.70cvss 8.8epss 0.16

    Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-4135CriKEVNov 25, 2022
    risk 0.70cvss 9.6epss 0.32

    Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-3723HigKEVNov 1, 2022
    risk 0.70cvss 8.8epss 0.08

    Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-1364HigKEVJul 26, 2022
    risk 0.70cvss 8.8epss 0.14

    Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4102HigKEVFeb 11, 2022
    risk 0.70cvss 8.8epss 0.08

    Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30563HigKEVAug 3, 2021
    risk 0.70cvss 8.8epss 0.09

    Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30554HigKEVJul 2, 2021
    risk 0.70cvss 8.8epss 0.07

    Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21206HigKEVApr 26, 2021
    risk 0.70cvss 8.8epss 0.09

    Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21193HigKEVMar 16, 2021
    risk 0.70cvss 8.8epss 0.10

    Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6572HigKEVJan 14, 2021
    risk 0.70cvss 8.8epss 0.11

    Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

  • CVE-2010-1205CriJun 30, 2010
    risk 0.70cvss 9.8epss 0.43

    Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

  • CVE-2026-11645HigKEVJun 9, 2026
    risk 0.69cvss 8.8epss 0.02

    Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-3910HigKEVMar 13, 2026
    risk 0.69cvss 8.8epss 0.02

    Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-3909HigKEVMar 13, 2026
    risk 0.69cvss 8.8epss 0.02

    Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-48543HigKEVSep 4, 2025
    risk 0.69cvss 8.8epss 0.01

    In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2020-16013HigKEVJan 8, 2021
    risk 0.69cvss 8.8epss 0.03

    Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2015-0565CriFeb 25, 2020
    risk 0.69cvss 10.0epss 0.14

    NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.

  • CVE-2017-0561CriApr 7, 2017
    risk 0.69cvss 9.8epss 0.24

    A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the context of the Wi-Fi SoC.…

  • CVE-2016-0801CriFeb 7, 2016
    risk 0.69cvss 9.8epss 0.15

    The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal…

  • CVE-2025-48595HigKEVJun 1, 2026
    risk 0.67cvss 8.4epss 0.02

    In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2013-6792CriJan 23, 2020
    risk 0.67cvss 9.8epss 0.03

    Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability

  • CVE-2016-2417CriApr 18, 2016
    risk 0.67cvss 9.8epss 0.04

    media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently…

  • CVE-2023-5217HigKEVSep 28, 2023
    risk 0.66cvss 8.8epss 0.49

    Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2020-16009HigKEVNov 3, 2020
    risk 0.66cvss 8.8epss 0.48

    Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2017-7376CriFeb 19, 2018
    risk 0.66cvss 9.8epss 0.23

    Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

  • CVE-2016-0705CriMar 3, 2016
    risk 0.66cvss 9.8epss 0.27

    Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA…

  • CVE-2011-1823HigKEVJun 9, 2011
    risk 0.66cvss 7.8epss 0.42

    The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in…

  • CVE-2026-13782CriJun 30, 2026
    risk 0.65cvss 10.0epss 0.00

    Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-0092CriJun 17, 2026
    risk 0.65cvss epss 0.00

    In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-2031CriMay 15, 2026
    risk 0.65cvss epss 0.01

    An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted…

  • CVE-2025-48611CriMar 10, 2026
    risk 0.65cvss 10.0epss 0.00

    In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-9118CriAug 25, 2025
    risk 0.65cvss epss 0.01

    A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.

  • CVE-2025-6554HigKEVJun 30, 2025
    risk 0.65cvss 8.1epss 0.13

    Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-0982CriFeb 6, 2025
    risk 0.65cvss 10.0epss 0.00

    Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by the Rhino engine. Effective January 24, 2025, Application Integration will no longer support Rhino…

  • CVE-2024-22004CriApr 5, 2024
    risk 0.65cvss 10.0epss 0.00

    Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application

  • CVE-2023-48426CriApr 5, 2024
    risk 0.65cvss 10.0epss 0.00

    u-boot bug that allows for u-boot shell and interrupt over UART

  • CVE-2023-48418CriJan 2, 2024
    risk 0.65cvss 10.0epss 0.00

    In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no additional     execution privileges needed. User…

  • CVE-2023-6339CriJan 2, 2024
    risk 0.65cvss 10.0epss 0.00

    Google Nest WiFi Pro root code-execution & user-data compromise

  • CVE-2023-48419CriJan 2, 2024
    risk 0.65cvss 10.0epss 0.00

    An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 

  • CVE-2021-39296CriSep 9, 2021
    risk 0.65cvss 10.0epss 0.03

    In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.

  • CVE-2026-84325CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

  • CVE-2026-79152CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low)

  • CVE-2026-79090CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-74478CriAug 15, 2026
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: um: vector: fix use-after-free in vector_mmsg_rx() When vector_mmsg_rx() discards a packet whose overlay header fails verify_header(), it frees the skb and continues the loop: if (header_check < 0) { …

  • CVE-2026-74350CriAug 15, 2026
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate fast symlink target during inode read ocfs2_validate_inode_block() already rejects several inconsistent self-contained dinodes before they are exposed to the rest of the filesystem. Fast…

  • CVE-2026-0163CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-14537CriJul 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints…

Page 2 of 318