VYPR

Vendor CVEs

Google

All CVEs

16,116 total · sorted by risk
  • CVE-2014-9940HigMay 2, 2017
    risk 0.39cvss 7.0epss 0.02

    The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.

  • CVE-2016-10200HigMar 7, 2017
    risk 0.39cvss 7.0epss 0.00

    Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED…

  • CVE-2016-6689MedOct 10, 2016
    risk 0.39cvss 5.5epss 0.02

    Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30768347.

  • CVE-2012-6702MedJun 16, 2016
    risk 0.39cvss 5.9epss 0.02

    Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.

  • CVE-2026-87590MedSep 9, 2026
    risk 0.38cvss 5.9epss 0.00

    Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-87482MedSep 9, 2026
    risk 0.38cvss 5.9epss 0.00

    Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-79208MedAug 25, 2026
    risk 0.38cvss 5.9epss 0.00

    Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-79126MedAug 25, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially obtain sensitive information via crafted network traffic. (Chromium security severity: Low)

  • CVE-2026-79122MedAug 25, 2026
    risk 0.38cvss 5.9epss 0.00

    Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-79013MedAug 25, 2026
    risk 0.38cvss 5.9epss 0.00

    Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-17908MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17906MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17893MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17891MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17890MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17866MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17809MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17806MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17776MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17770MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17746MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17745MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17736MedJul 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-14062MedJun 30, 2026
    risk 0.38cvss 5.9epss 0.00

    Inappropriate implementation in Views in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security…

  • CVE-2026-13976MedJun 30, 2026
    risk 0.38cvss 5.8epss 0.00

    Insufficient data validation in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-11238MedJun 5, 2026
    risk 0.38cvss 5.9epss 0.00

    Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity:…

  • CVE-2026-11199MedJun 4, 2026
    risk 0.38cvss 5.9epss 0.00

    Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)

  • CVE-2026-0075MedJun 1, 2026
    risk 0.38cvss 5.9epss 0.00

    In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0061MedJun 1, 2026
    risk 0.38cvss 5.9epss 0.00

    In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-12436MedNov 10, 2025
    risk 0.38cvss 5.9epss 0.00

    Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2025-31710MedJun 3, 2025
    risk 0.38cvss 5.9epss 0.00

    In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.

  • CVE-2024-32928MedAug 19, 2024
    risk 0.38cvss 5.9epss 0.00

    The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.

  • CVE-2024-32916MedJun 13, 2024
    risk 0.38cvss 5.9epss 0.00

    In fvp_freq_histogram_init of fvp.c, there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32897MedJun 13, 2024
    risk 0.38cvss 5.9epss 0.00

    In ProtocolCdmaCallWaitingIndAdapter::GetCwInfo() of protocolsmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for…

  • CVE-2024-20060MedMay 6, 2024
    risk 0.38cvss 5.9epss 0.00

    In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.

  • CVE-2023-52534MedApr 8, 2024
    risk 0.38cvss 5.9epss 0.00

    In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2024-29747MedApr 5, 2024
    risk 0.38cvss 5.9epss 0.00

    In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27231MedApr 5, 2024
    risk 0.38cvss 5.9epss 0.00

    In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27234MedMar 11, 2024
    risk 0.38cvss 5.9epss 0.00

    In fvp_set_target of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-25989MedMar 11, 2024
    risk 0.38cvss 5.9epss 0.00

    In gpu_slc_liveness_update of pixel_gpu_slc.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2022-39886MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.

  • CVE-2022-39885MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.

  • CVE-2022-39879MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.

  • CVE-2022-36868MedOct 7, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth device.

  • CVE-2022-36861MedSep 9, 2022
    risk 0.38cvss 5.9epss 0.00

    Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.

  • CVE-2022-33729MedAug 5, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.

  • CVE-2022-27567MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.

  • CVE-2022-26099MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.

  • CVE-2022-26097MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_unknown_property function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

  • CVE-2022-26096MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

Page 203 of 323